EU Cyber Resilience Act Becomes Fully Applicable: Essential Requirements and CE Marking
The EU Cyber Resilience Act, Regulation (EU) 2024/2847, becomes fully applicable on December 11, 2027, three years after it entered into force on December 10, 2024. From this date every product with digital elements placed on the Union market must meet the Annex I essential cybersecurity requirements, be covered by a conformity assessment appropriate to its risk class, carry CE marking, ship with technical documentation and an EU declaration of conformity, and be supported with security updates for a declared support period. The Act phased in ahead of this date: Chapter IV, covering notification of conformity assessment bodies, applied from June 11, 2026, and the Article 14 vulnerability and incident reporting duties from September 11, 2026.
Key Analytics
Impact Analysis
This is the date the CRA stops being a reporting obligation and becomes a market access condition. A product with digital elements that cannot demonstrate conformity cannot lawfully be placed on the EU market, and that reaches hardware, embedded software, and standalone software alike, including products from vendors with no EU establishment. The work is front-loaded and long: secure-by-design engineering evidence, a vulnerability handling process with a coordinated disclosure policy, an SBOM covering at least the top-level dependencies, and a support period that has to be declared and then honoured. Important and critical product classes face heavier conformity routes that may require a notified body, which is why Chapter IV opened eighteen months early. Products already placed on the market before December 11, 2027 are pulled into the essential requirements and the conformity route only where they undergo a substantial modification after that date, so the substantial-modification analysis becomes a live product-management question rather than a legal footnote. The reporting duties are the exception and are not limited that way: the Commission states that they apply to all products with digital elements made available on the Union market, including those already placed on it before December 11, 2027, so a legacy product still generates actively-exploited-vulnerability and severe-incident reports from September 11, 2026 onward.
Recommended Actions
- Classify every product with digital elements you place on the EU market against the CRA risk classes, since the class determines whether self-assessment is available or a notified body is required.
- Stand up the Annex I Part II vulnerability handling process now, including a coordinated disclosure policy and the ability to distribute security updates for the declared support period.
- Decide and document the support period for each product, because it is a declared commitment enforced against you rather than a marketing statement.
- Produce the technical documentation and EU declaration of conformity ahead of the date, and confirm your CE marking process covers cybersecurity conformity and not only existing product directives.
- Define what counts as a substantial modification for your existing portfolio, since that test decides whether products already on the market are pulled into full CRA conformity.
- Keep the Article 14 reporting track that started on September 11, 2026 running, because full application adds to those duties rather than replacing them.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Readiness assessment
- ›Remediation sprint to date
- ›Attestation or filing preparation
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 55 to 240 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.