How Long Does EU CRA Conformity Take?
Counting from August 2026, the Cyber Resilience Act's main obligations apply from 11 December 2027, which is about fifteen months away, and the reporting obligations apply from 11 September 2026, which is weeks away. Those two dates are the only parts of the answer that are fixed. The part buyers actually want, how long the conformity assessment itself takes, cannot be honestly quoted yet, for two reasons the European Commission's own pages make plain: the product-specific harmonised standards that important products would be assessed against are still in approval, and the Commission's conformity assessment page describes the NANDO listing of CRA notified bodies as available "once available". A firm that quotes you a conformity assessment duration today is quoting a process whose two external inputs do not yet exist in final form. The contrarian consequence is that the calendar you control is the technical documentation, and the calendar you do not control is everything after it.
Below: the three clocks outside your control and where each stands, how the duration driver differs by product tier, why the reporting duty arrives first, the sequence that is right under any outcome of the standards process, and when this is a memo rather than a programme.
Key takeaways
- Two dates are fixed: reporting obligations from 11 September 2026 and the main obligations from 11 December 2027. The conformity route's own duration is not yet quotable by anyone.
- The product-specific standards are still in approval, not adopted. ETSI's 17 vertical final drafts were under public enquiry as of August 2026; ETSI calls the enquiry the first phase of the approval procedure, which runs until mid-September to mid-November 2026 depending on the vertical.
- Chapter IV on notified bodies applies from 11 June 2026, and the Commission's conformity page still describes the NANDO listing for the CRA as available "once available".
- In every tier the technical documentation is the part of the timeline you control; the rest of the calendar belongs to a standards body, a notifying authority or a notified body, so the technical file is the critical path under every scenario.
- The reporting obligations arrive fifteen months before the main ones, so the reporting runbook and the component inventory behind it come before any conformity artifact on the calendar.
The three clocks you do not control
The duration of a CRA conformity project depends on three things happening outside your building, and as of August 2026 each is at a different stage.
The harmonised standards. The Commission's standardisation page records that the Commission adopted standardisation request M/606 "containing a set of 41 standards in support of the CRA", split into horizontal standards providing a common framework including vulnerability handling, and vertical, product-specific standards intended to provide presumption of conformity for particular product types. The request "prioritises the development of standards covering the important and critical product categories". CEN-CENELEC's announcement of the request's acceptance in April 2025 records a commitment by the three European standardisation organisations to deliver harmonised standards "at least one year before the CRA enters into application". On the vertical side, ETSI announced in August 2026 that its 17 vertical final draft standards are "currently under Public Enquiry", that the approval procedure "will run until mid-September to mid-November 2026, depending on the vertical", and that the enquiry is "the first phase of the approval procedure". A final draft under enquiry is not yet a harmonised standard, and the Commission's own harmonised-standards page states that publication of the reference in the Official Journal is foreseen as a precondition for presumption of conformity.
The notified bodies. Chapter IV of the regulation, which governs how conformity assessment bodies are notified, has applied since 11 June 2026. The Commission's conformity page explains what has to happen next: bodies "have to be assessed, designated, notified and monitored by the Member State where they are established", and "once a conformity assessment body has become a notified body it will be published on the NANDO website". The same page, read in August 2026, lists NANDO as the place that lists notified bodies "including (once available) for the CRA", and offers ENISA's Technical Competence Requirements for CRA Notified Bodies as the reference for what those bodies have to demonstrate. A route that requires a notified body cannot be scheduled until there is one to book, and nothing on the Commission's own pages says how many there will be or when.
The guidance. The Commission published practical guidance in July 2026, Communication C(2026) 5252 and its annex, described as non-binding and as addressing "the questions stakeholders have been asking most". Non-binding guidance does not move a date, but it does change how much interpretive work sits inside your own project, which is a duration input in its own right.
Which tier, which duration driver
The conformity routes article sets out the four tiers, the Annex III class lists and when a notified body is required. This page does not restate them. What it adds is the question a schedule needs answered: for each tier, what actually sets the duration.
| Tier | What sets the duration | What you control |
|---|---|---|
| Default products | Your own technical documentation and internal control procedure. The Commission's conformity page: self-assessment "irrespective of the technical specification used by the manufacturer" | All of it |
| Important products, class I | Whether a harmonised standard covering your product is cited in time. Whether the self-assessment condition the routes article sets out is met depends on that citation landing before your assessment does | The technical file; not the standard's timing, not notified body capacity |
| Important products, class II | Notified body availability, since the routes article's answer for this class is a third-party route | The technical file and the readiness of the vulnerability-handling process the body will assess |
| Critical products | Notified body availability, for the same reason; the routes article has the conditions | The technical file |
Read down the right-hand column and the pattern is the whole planning argument. In every tier, the technical documentation is the part you control, and in three of the four the rest of the calendar belongs to a standards body, a Member State's notifying authority, or a notified body that may not yet be listed. The Commission's manufacturers page states the sequence the same way: the first step "is to carry out a risk assessment", on which the manufacturer defines how to implement the essential requirements, explains that in the technical documentation, carries out a conformity assessment procedure, and only then affixes the CE marking, draws up the declaration of conformity and indicates the support period. The order is not negotiable and the first three steps are yours.
For a class I manufacturer the timeline has a fork in it, and what decides the branch is timing: whether a harmonised standard covering the product has its reference cited in the Official Journal before the product's conformity assessment. Which branch leads where, and the planning posture to hold while the standards are unsettled, are the routes article's subject, in its sections "Why the class I self-assessment route is not a plan yet" and "The technical documentation is the actual deliverable". What this page adds is where that timing stood in August 2026: the vertical drafts under ETSI enquiry, with the approval procedure running until mid-September to mid-November 2026; Chapter IV live since 11 June 2026; the NANDO listing for the CRA still described as available "once available"; and the Commission's July 2026 guidance published. Every one of those is a date to re-check monthly, and none of them is a date you can move.
Reporting arrives first
Which products the reporting duties reach, and how the transitional rules treat products already on the market, is the subject of does the CRA apply to your product; this page takes only the scheduling consequence. The reporting obligations apply from 11 September 2026, fifteen months before the main obligations, so the reporting capability and the component inventory behind it have to exist for the whole product inventory before the conformity work on any single product has finished. EU CRA vulnerability reporting obligations covers what has to be reported, to whom and on what clocks, and the SBOM article explains why the component inventory belongs on the 2026 side of the calendar rather than the 2027 side.
One more transitional detail belongs on the calendar. The Commission's summary notes that EU type-examination certificates "remain valid until 11 June 2028, unless they expire before that date", which is the outer edge of the transition for anyone holding an existing certificate on a product that the CRA will now govern.
The sequence that is right under every outcome
Because the standards and notified body timing are unknowable from here, the useful plan is one that does not depend on them. In order:
- Inventory every shipped and deployed product, with its cloud dependencies and its Annex III class call written down with reasoning. This gates the reporting duty in September 2026 and the tier determination for everything else.
- Stand up the vulnerability-handling process and the reporting runbook for the whole inventory before 11 September 2026.
- Carry out the cybersecurity risk assessment for each product still in development or still being modified, because the Commission's manufacturers page puts it first and everything in the technical file hangs from it.
- Build the technical documentation to the standard a notified body would read, in every tier, starting now rather than when the standards land.
- Put a monthly check on the standards approvals and the NANDO listing. A citation or a listing changes the last phase of the schedule, never the first ones.
Nothing in that list depends on how the standards process ends, and every item is dated by a clock you can read today.
When this is a memo, not a programme
Against our own interest, three cases.
If everything you place on the EU market is a default-tier product, the conformity route is internal control and the "conformity assessment duration" is however long it takes your team to write a technical file it would be comfortable handing to a market surveillance authority. That is a documentation project with a known owner, and it does not need a consultancy to run it.
If your only EU-bound product is already on the market and will not change, which obligations reach it is the scoping article's question. If the answer there is reporting only, the right deliverable is a reporting runbook plus a maintained component inventory rather than a conformity plan, and the December 2027 clock is not yours.
If you are not sure whether your product is in scope at all, stop. The scoping analysis is a memo, and the duration of everything above is zero if the answer is no.
Where Top Floor fits
Our EU Cyber Resilience Act practice does the parts of the timeline you control: the product inventory with the class call reasoned in writing, the risk assessment, the gap assessment against the essential requirements, the vulnerability-handling process, and the technical documentation built to be read by a notified body whether or not one ever reads it. Where the technical file needs testing evidence behind it, penetration testing supplies it. Where the CRA is one of several regimes you are answering at once, it belongs inside a broader international compliance scope.
We are not a notified body, we do not perform conformity assessments or issue CE marks, and we will not quote you a conformity assessment duration that depends on a standard that has not been cited or a body that has not been listed.
How to decide this week
Date the technical-file start for each product against the December 2027 clock. For every product that will ship or change before 11 December 2027, take its next planned release, count back the time your team needs to write a file a notified body could read, and write that start date down. If the start date is already behind you, the file is late today, not in 2027, and that is the finding to take to whoever owns the roadmap.
Then mark each product's tier using the lists in the conformity routes article, and for each class I product write down which vertical standard, if any, you are hoping will be cited, so that the hope is a tracked dependency rather than an assumption.
Then start the technical file for whichever product ships or changes next, and put a named owner on watching the NANDO listing and the standards approvals, with a monthly check. Those two pages are your schedule's external inputs, and someone should be reading them.
Frequently asked questions
When does the EU Cyber Resilience Act start to apply?
The Commission's policy page states that the CRA entered into force on 10 December 2024, that the reporting obligations apply from 11 September 2026, and that the main obligations apply from 11 December 2027. Separately, Chapter IV, which governs the notification of conformity assessment bodies, applies from 11 June 2026, so that notified bodies can exist before the main deadline. As of August 2026 that gives roughly fifteen months to the main obligations and weeks to the reporting duties.
How long does a CRA conformity assessment by a notified body take?
Nobody can honestly say yet. The Commission's conformity assessment page, read in August 2026, describes the NANDO listing of CRA notified bodies as available "once available", and conformity assessment bodies have to be assessed, designated, notified and monitored by their Member State before they can act. Until bodies are listed and running assessments, any duration quoted for a third-party route is a guess. What a manufacturer can control is having a technical file a notified body can read on the day one becomes bookable.
Can we wait for the harmonised standards before starting?
Not safely. The standards are still in approval: as of August 2026 ETSI's 17 vertical final drafts were under public enquiry, which ETSI calls the first phase of an approval procedure that runs until mid-September to mid-November 2026 depending on the vertical, and CEN-CENELEC's stated commitment is delivery at least one year before the CRA enters into application. Whether a standard covering your product is cited in time is a dependency to track, not a plan. Waiting moves nothing forward on the calendar you control, and the reporting duties arrive in September 2026 regardless.
Do products we already sold need a conformity assessment?
Not unless they are substantially modified, but the reporting obligations do apply to them; the transitional rules are covered in does the CRA apply to your product.
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.