Public datasetUpdated 2026-07-29CC BY 4.0

CRA Enforcement Tracker

Every announced enforcement action under the EU Cyber Resilience Act, every ENISA guidance update, every Member State authority designation, every harmonised standard published in support of the regulation. Filterable by country, type, and year. Updated weekly. Free to republish with attribution.

15
Entries
2
Member states covered
3
Entry categories
2026-07-29
Last updated

Anchor dates

The EU Cyber Resilience Act timeline runs in two steps. Article 14 reporting applies from 11 September 2026 and the full regulation from 11 December 2027. Every tracker entry below sits against these dates from Article 71 of Regulation (EU) 2024/2847. For what each obligation means, see the EU Cyber Resilience Act guide.

EU Cyber Resilience Act key dates under Regulation (EU) 2024/2847
MilestoneDateLegal basis
Regulation entered into force10 December 2024Article 71(1)
Notified body provisions apply (Chapter IV)11 June 2026Article 71(2)
Article 14 vulnerability and incident reporting applies11 September 2026Article 71(2)
Full regulation applies, including CE marking11 December 2027Article 71(2)
Showing 15 of 15 entries
DateCountryTypeEventArticle
Anchor date
EU
EU-wide
Anchor dateCRA becomes fully applicable to all products with digital elements

All remaining obligations apply, including essential cybersecurity requirements in Annex I, conformity assessment under Article 32, and CE marking of products with digital elements. Manufacturers must have completed conformity assessment before placing products on the market.

Source: EUR-Lex (Article 71(2))

Article 71(2)
Anchor date
EU
EU-wide
Anchor dateArticles 13 (CVD) and 14 (incident and vulnerability reporting) become applicable

Manufacturers of products with digital elements placed on the EU market must operate a coordinated vulnerability disclosure policy and a single point of contact (Article 13), and must report actively exploited vulnerabilities and significant incidents to ENISA and the relevant national CSIRT on the 24h / 72h / final-report cadence (Article 14).

Source: EUR-Lex (Article 71(2))

Articles 13, 14
EU
EU-wide
GuidanceCommission adopts guidance on the application of the Cyber Resilience Act (C(2026) 5252)

The Commission adopts the Article 26(1) guidance, running to 84 pages and 67 worked examples. It defines when a manufacturer 'becomes aware' for the purposes of the Article 14 reporting deadlines, sets out a four-factor test for whether a software update is a substantial modification, confirms that the five-year support period in Article 13(8) is a minimum rather than a default, reduces the remote data processing definition to two cumulative questions, and states that a web application accessed exclusively through a browser is not a product with digital elements. The guidance is non-binding and follows a public consultation held between 3 March and 13 April 2026.

Source: European Commission, CRA implementation

Article 26(1) (guidance)
EU
EU-wide
StandardFirst ETSI CRA vertical standards reach enquiry and final draft stage

Several EN 304 6xx deliverables reach enquiry or final draft during June and July 2026, including anti-malware software, firewalls and intrusion detection or prevention systems, routers and switches, hypervisors and container runtimes, internet-connected toys and personal wearables. None is cited in the Official Journal, so none confers presumption of conformity.

Source: ETSI CYBER-EUSR open consultation area

Article 27 (presumption of conformity)
EU
EU-wide
StandardETSI opens public consultation on the EN 304 vertical CRA standards

ETSI TC CYBER publishes drafts of its EN 304 6xx series in an open consultation area, together with commenting instructions. The series covers the vertical standards under standardisation request M/606, one per Annex III product category, with the deliverable number set to 304 600 plus the mandate line item.

Source: ETSI CYBER-EUSR open consultation area

Article 27 (presumption of conformity)
EU
EU-wide
StandardCEN-CENELEC JTC 13 publishes work programme for harmonised CRA standards

JTC 13 publishes its work programme detailing the harmonised standards under development for CRA Annex I essential requirements, with target publication dates ahead of full applicability in December 2027.

Source: CEN-CENELEC cybersecurity sector page

n/a
EU
EU-wide
GuidanceENISA launches the European Union Vulnerability Database (EUVD)

ENISA launches the EUVD as required under NIS2 Article 12, providing a public catalogue of vulnerabilities with European context. The EUVD will integrate with the CRA Single Reporting Platform once Article 14 reporting becomes applicable in September 2026.

Source: EUVD (ENISA)

Article 16 (EUVD interaction)
FR
France
GuidanceANSSI publishes CRA implementation guidance for French manufacturers

L'Agence nationale de la sécurité des systèmes d'information (ANSSI) publishes guidance for French manufacturers on CRA scope, the Article 13 SPOC requirement, and the upcoming Article 14 reporting workflow. ANSSI is the expected national CSIRT recipient under Article 14.

Source: ANSSI CRA page

n/a
DE
Germany
GuidanceBSI signals lead role for CRA market surveillance and conformity assessment in Germany

The Bundesamt für Sicherheit in der Informationstechnik (BSI) publishes guidance positioning itself as the expected lead authority for CRA market surveillance and conformity assessment in Germany, pending formal national legislation transposing supervisory powers.

Source: BSI CRA page

n/a
EU
EU-wide
GuidanceENISA publishes CRA overview and FAQ on its dedicated topic page

ENISA opens a dedicated Cyber Resilience Act topic page summarising the regulation, the application timetable, and the agency's role in the Single Reporting Platform and the European vulnerability database (EUVD).

Source: ENISA topic page

n/a
Anchor date
EU
EU-wide
Anchor dateRegulation (EU) 2024/2847 enters into force

The Cyber Resilience Act enters into force across the European Union. Most substantive obligations apply later (see September 2026 and December 2027 anchors), but the legal framework is now binding on Member States for transposition and on the Commission for delegated and implementing acts.

Source: EUR-Lex (Official Journal)

Article 71 (entry into force)
EU
EU-wide
StandardCommission issues standardisation request M/606 to CEN-CENELEC for harmonised CRA standards

The European Commission issues a formal standardisation request to CEN-CENELEC (JTC 13) to develop harmonised European standards supporting the essential cybersecurity requirements in Annex I of the CRA. Compliance with these standards will provide a presumption of conformity under Article 27.

Source: Commission standardisation request M/606

Article 27 (presumption of conformity)
EU
EU-wide
GuidanceCRA text published in the Official Journal of the European Union

Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements is published in the OJ, locking in the 20-day countdown to entry into force.

Source: EUR-Lex OJ L 2024/2847

n/a
EU
EU-wide
GuidanceCouncil of the EU formally adopts the Cyber Resilience Act

The Council adopts the CRA after the European Parliament's plenary vote in March 2024, completing the ordinary legislative procedure. Final text proceeds to OJ publication and signature.

Source: Council of the EU press release

n/a
EU
EU-wide
GuidanceEuropean Parliament adopts CRA at first reading

MEPs approve the trilogue-agreed text by a wide margin, clearing the final political hurdle before Council adoption. Key amendments included the carve-out for open-source software stewards and the staged application timetable.

Source: European Parliament press release

n/a

Methodology

An entry is included when one of the following has occurred: a formal enforcement action by an EU or Member State authority under the CRA, an ENISA or Commission guidance or FAQ publication, a Member State designation of an NCA or CSIRT with CRA scope, a harmonised standard published or referenced under Article 27, a delegated or implementing act adopted under the CRA, or a court decision touching CRA scope.

Each entry cites an official source as the primary reference (Official Journal, ENISA, the European Commission, a national authority, or a national publication). Reputable trade press is accepted only as a secondary corroborating source.

Anchor dates (entry into force, Article 13 and 14 applicability, full applicability) are included as a navigation aid and are visually flagged so they are not confused with actual events. All dates are the date of the underlying event, not the date the entry was added.

To suggest an entry or flag an error, email [email protected] with a working source URL. Corrections are made in place and the dataset's last-updated date is bumped.

Run Article 13 and 14 in CVD Portal

CVD Portal runs the Article 13 coordinated disclosure intake and the Article 14 reporting cascade for EU manufacturers. Free tier covers Article 13. Reporting and Enterprise add the 24h / 72h / final report workflow for Article 14.

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.