The EU CRA timeline: (EU) 2024/2847 dates and the reporting clock

The dates that matter — including the vulnerability-reporting obligation that starts 11 September 2026

7 Aug 20265 min readAutoSifu

The CRA is two clocks, not one

The EU Cyber Resilience Act — Regulation (EU) 2024/2847 — entered into force in December 2024, but almost none of its duties bit on that day. The regulation phases in, and the single most important thing to understand about its timeline is that the reporting obligations start earlier than the main body of obligations. Plan against both dates or you will be caught by the earlier one.

For the regulation on its own terms, read the EU CRA for automotive; this piece is about the dates.

The dated table

Date What happens
December 2024 CRA (EU) 2024/2847 enters into force
11 September 2026 Vulnerability and incident reporting obligations apply
11 December 2027 The main body of obligations applies

Two dates carry the weight: 11 September 2026 for reporting, and 11 December 2027 for everything else. Everything a programme does between now and then should be sequenced against those two milestones.

Why 11 September 2026 is the one to watch

The reporting duty is the earliest operational obligation, and it is operational in a way the rest of the CRA is not. From 11 September 2026 a manufacturer must notify authorities of actively exploited vulnerabilities and severe incidents within defined windows. That is not a document you write once; it is a capability you must be able to exercise on demand — detect, triage, decide, notify — under time pressure.

This is why the reporting clock, not the 2027 deadline, is the harder near-term target. A manufacturer can draft policies and prepare technical documentation ahead of December 2027 at a measured pace. But the reporting path has to be live, staffed and rehearsed before September 2026, because the first exploited vulnerability will not wait for the process to mature. The substance of that duty is covered in vulnerability handling and disclosure under the CRA.

Why 11 December 2027 is the headline deadline

The main body of obligations — secure-by-design, the SBOM, the full vulnerability-handling process, conformity assessment before placing a product on the market — applies from 11 December 2027. This is the date most teams treat as the compliance deadline, and rightly so: from that point a product with digital elements placed on the EU market must meet the CRA's essential requirements and carry the conformity evidence to prove it.

The gap between the two dates is deliberate breathing room, but it is easy to misread. The reporting duty landing fifteen months before the main obligations means you must be able to report on vulnerabilities in products that are not yet fully CRA-conformant. In practice that pulls the SBOM and vulnerability-handling work forward, because you cannot report on components you have not inventoried.

How this sits against the vehicle timeline

Automotive teams already live with a set of dates from the UN regime. Under UN R155, applied in the EU through the General Safety Regulation (EU) 2019/2144, cybersecurity requirements hit new vehicle types on 6 July 2022 and all new vehicles on 7 July 2024 — dates that have already passed. The CRA dates come after those and run on a different logic: product placement and market surveillance rather than vehicle type approval. A team that has already cleared the R155 milestones still has the CRA clocks ahead of it. The two regimes and their dates are compared directly in CRA vs UN R155.

Sequencing the work

Working back from the two dates, a sensible order is:

  1. Now to mid-2026. Build the SBOM per product and stand up the vulnerability-handling and disclosure process. Rehearse the notification path end to end.
  2. By 11 September 2026. Reporting capability live: detection, triage, decision and notification working under a realistic clock.
  3. 2026 to late 2027. Complete secure-by-design evidence, technical documentation and conformity assessment readiness for products placed on the market.
  4. By 11 December 2027. Products placed on the EU market meet the essential requirements with conformity evidence in hand.

The reporting capability is the long pole, because it is a running operation rather than a deliverable. Start it first.

Common misreadings of the timeline

Three misreadings recur, and each is expensive.

The first is treating December 2027 as the only date. A programme that plans everything for the headline deadline will be unprepared when the reporting duty lands fifteen months earlier, on an exploited vulnerability it has to notify but has no live process to handle.

The second is assuming the December 2024 entry into force meant nothing applied. It is true that the substantive duties phase in, but the regulation was legally in force from that point, and the phase-in dates are fixed from it. Entry into force is the anchor, not a delay.

The third is reading the reporting duty as a documentation task that can be prepared on paper and filed away. It cannot. A notification within a staged window measured in hours and days requires people, tooling and rehearsal — a capability exercised under pressure, not a template retrieved from a folder. The teams that struggle are the ones that discover this on the day of the first incident rather than in a tabletop a year earlier.

What does not have a fixed date

One honest caveat: much of the operational detail beneath these headline dates — the precise notification mechanics, the guidance and any implementing acts — continues to develop. The two statutory dates, 11 September 2026 and 11 December 2027, are firm and should anchor planning. The finer procedural detail around them should be tracked as it settles rather than assumed. Build the capability to the firm dates and adjust the mechanics as guidance matures.

The AutoSifu view

We plan CRA readiness against both clocks at once, not just the 2027 headline. Through CIRT we run a single route — compliance, solutioning and CoC/VTA support — so the SBOM and the reporting path built for September 2026 also feed the December 2027 obligations and the existing R155 CSMS, with the approval body in the room while the sequence is set. That keeps one team working to two dates instead of scrambling at each.

Questions

When does the EU CRA apply?
The CRA (Regulation (EU) 2024/2847) entered into force in December 2024, but its obligations phase in rather than applying all at once. The vulnerability and incident reporting obligations apply from 11 September 2026, and the main body of obligations applies from 11 December 2027. Programmes should plan against those two dates rather than treating the whole regulation as immediately binding.
When do CRA reporting obligations start?
The reporting obligations — notification of actively exploited vulnerabilities and severe incidents — apply from 11 September 2026. This is the earliest operational duty under the CRA and the one that demands a rehearsed detection-to-notification path. It commences well before the main body of product obligations.
What is the CRA compliance deadline?
The main body of CRA obligations applies from 11 December 2027, which is the date most manufacturers treat as the headline compliance deadline for placing compliant products on the EU market. The reporting duties, however, bite earlier, from 11 September 2026. Treat the CRA as two clocks, not one.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required