Live timer11 September 2026 CESTFree to embed

EU Cyber Resilience Act timeline and Article 14 countdown

The EU Cyber Resilience Act applies in two steps. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking, applies from 11 December 2027. From September 2026, every manufacturer placing a product with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT on fixed deadlines. This counter ticks down to that first deadline in real time. Embed it on your compliance dashboard.

39
Days
01
Hours
29
Minutes
27
Seconds

Drop this on your compliance dashboard

Paste the snippet below into any page that supports HTML. The widget loads in an iframe, weighs under 20 KB, sets no cookies, and updates every second.

<iframe src="https://cvdportal.com/embed/countdown" width="600" height="200" style="border:0;max-width:100%" loading="lazy" title="EU CRA Article 14 countdown"></iframe>

Default size is 600 by 200 pixels. The widget is responsive and scales to its container.

CRA key dates

All application dates come from Article 71 of Regulation (EU) 2024/2847. The full timeline of enforcement actions and guidance lives in the CRA enforcement tracker.

EU Cyber Resilience Act key dates under Regulation (EU) 2024/2847
MilestoneDateLegal basis
Regulation entered into force10 December 2024Article 71(1)
Notified body provisions apply (Chapter IV)11 June 2026Article 71(2)
Article 14 vulnerability and incident reporting applies11 September 2026Article 71(2)
Full regulation applies, including CE marking11 December 2027Article 71(2)

What changes on 11 September 2026

Article 14 obliges every manufacturer of products with digital elements to notify ENISA and the relevant CSIRT of any actively exploited vulnerability or severe incident affecting the security of the product. The cascade is an early warning within 24 hours, an intermediate notification within 72 hours, and a final report within 14 days for an actively exploited vulnerability or one month for a severe incident.

Article 14 is the only substantive obligation that moves this early. Under Article 71(2) the Regulation applies from 11 December 2027, and the sole derogations are Article 14 from 11 September 2026 and Chapter IV on notified bodies from 11 June 2026. So Article 14 comes 15 months ahead of the rest.

Everything else arrives on 11 December 2027, including placing on the market, CE marking, conformity assessment, and the Article 13 manufacturer obligations such as the coordinated vulnerability disclosure policy and the security contact. In practice the CVD process needs to be running before September 2026 anyway, because Article 14 reporting depends on it. For the full picture of every obligation, read the EU Cyber Resilience Act guide.

Timeline questions, answered

When does the EU Cyber Resilience Act take effect?

The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking and conformity assessment, applies from 11 December 2027.

What is the CRA deadline in September 2026?

From 11 September 2026, every manufacturer of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, with an early warning within 24 hours, a notification within 72 hours, and a final report after 14 days or one month.

What happens on 11 December 2027?

On 11 December 2027 the Cyber Resilience Act applies in full. Products with digital elements placed on the EU market must meet the Annex I essential requirements, carry CE marking, have technical documentation and an EU Declaration of Conformity, and manufacturers must run a coordinated vulnerability disclosure process under Article 13.

Which CRA obligations apply before 2027?

Two parts move early under Article 71(2). Chapter IV on notified bodies applies from 11 June 2026, and Article 14 reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026. Everything else applies from 11 December 2027.

Get Article 13 ready in an afternoon

CVD Portal runs the Article 13 intake and the Article 14 cascade for EU manufacturers. The free tier covers Article 13. Reporting and Enterprise add the 24h / 72h / final report workflow.

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.