The CRA dates, and the standards timeline
Short answer. Only two dates bind you.
- 11 September 2026 — the Article 14 reporting duties. Already live.
- 11 December 2027 — everything else: the essential requirements, the technical documentation, the declaration of conformity, CE marking.
The harmonised standards are a separate schedule, and the dates published for them are delivery deadlines, not the date a standard becomes usable. None had been cited in the Official Journal when this page was written, and citation is what confers the presumption of conformity.
Most CRA timelines you will find are a list of eight or ten dates with no indication of which ones create obligations. Three do. The rest are either administrative milestones that have already passed or projections about other people's work — useful for planning, and not deadlines you can miss.
The dates that bind
| Date | What happens | Does it create a duty for you? |
|---|---|---|
| 10 December 2024 | The Regulation entered into force | No — entry into force starts the clocks, it does not impose the duties |
| 11 June 2026 | The provisions on notified bodies applied; conformity assessment bodies could begin being designated | No, but it is the date the queue you may need to join opened |
| 11 September 2026 | Article 14 reporting. Actively exploited vulnerabilities and severe incidents must be reported, on 24-hour and 72-hour clocks | Yes. This is live now |
| 11 December 2027 | Full application. The essential requirements in Annex I, the manufacturer's obligations in Article 13, the technical documentation, the declaration of conformity, CE marking, the retention duties | Yes, for anything placed on the market from that date |
That is the whole of it. If a timeline shows you more dates than this with the word "deadline" attached, check what each one is a deadline for — most are deadlines on the Commission or the standardisation bodies, not on you.
The standards schedule, and what the dates mean
Standardisation request M/606 was accepted by CEN, CENELEC and ETSI in April 2025. It asks for two kinds of standard:
- Horizontal standards, which apply across products — the ones on secure development and vulnerability handling do the heavy lifting for most manufacturers.
- Vertical, product-specific standards for particular categories.
The delivery dates, as they stood when this page was written:
| Tranche | Deliver by | Status |
|---|---|---|
| Core horizontal — secure development and vulnerability management | 31 October 2026 | In drafting. Not cited in the Official Journal |
| Vertical, product-specific | 31 December 2026 | A substantial set of ETSI drafts went out to public enquiry during 2026, with comment periods running into late 2026. Not cited |
| Remaining horizontal | 30 October 2027 | Not delivered. Six weeks before full application |
Nothing in that table is a deadline on you. They are deadlines on the standardisation bodies, and the last one lands six weeks before the Regulation applies in full.
Delivery is not citation, and the gap matters
This is the part that changes how you should plan, and it is almost always left out.
A harmonised standard does not do anything for you by existing. Article 27 confers a presumption of conformity only once the standard's reference has been published in the Official Journal of the European Union. Two separate events:
- Delivery. The standardisation bodies finish the standard and hand it to the Commission by the date in the request. The dates in the table above are these.
- Citation. The Commission assesses it and publishes its reference in the Official Journal. Only now can you cite it and rely on the presumption.
The gap between the two is an assessment process, and across EU harmonisation legislation generally it has historically run to months rather than weeks — sometimes considerably longer where the Commission asks for revisions.
Plan on that basis. A standard delivered on 31 October 2026 may not be citable for some time afterwards. And a standard delivered on 30 October 2027 has six weeks before full application to be assessed and cited, which on any historical rate is unlikely.
It has already slipped once
In mid-2026 a draft amendment to the standardisation request moved two of the tranches back by two months:
| Tranche | Was | Now |
|---|---|---|
| Horizontal — secure development and vulnerability management | 30 August 2026 | 31 October 2026 |
| Vertical — product-specific | 30 October 2026 | 31 December 2026 |
Two months is not dramatic in itself. What it tells you is that this schedule moves, and that any compliance plan whose critical path runs through a standard being citable by a particular date is resting on someone else's slipping deadline.
It is also a reason not to wait. A manufacturer who decided in 2025 to start once the standards landed has now been waiting a year, and the December 2027 date has not moved.
What to do while there is nothing to cite
The Regulation anticipated this, and the answer is in the annexes rather than in a workaround.
Annex VII point 5 asks for a list of the harmonised standards applied in full or in part, common specifications or cybersecurity certifications — and, where none were applied, a description of the solutions adopted to meet the essential requirements. So an empty standards list is a contemplated state, not a gap, provided the description is there.
Which means, concretely:
- Your declaration of conformity's standards section says that none is cited, plainly, and does not invent one. What point 6 asks for.
- Your risk assessment carries the argument instead, requirement by requirement across Annex I Part I. This is why it matters more under the CRA today than the equivalent document does under a mature regime. The thirteen requirements.
- Technical references you did follow get cited as what they are. If you work to IEC 62443-4-1, say so as part of the description of the solutions adopted — not as a harmonised standard, because it is not one and is not expected to be cited as one.
- Never cite a draft as though it were cited. A reference to a prEN in a signed declaration is a misleading statement in the first document an authority reads.
The Class I problem
For most manufacturers the missing standards make the paperwork slightly more effortful. For Annex III Class I products they do something worse.
Article 32(2) requires a notified-body route where the manufacturer has not applied, or has applied only in part, the relevant harmonised standards, common specifications or an equivalent certification scheme at substantial assurance level — and also where such standards, specifications or schemes do not exist.
On the plain reading, that is where Class I manufacturers are today: there is no standard to apply in full, so the condition for self-assessment cannot be met. Plan for EU-type examination or full quality assurance, and treat a notified body's lead time as a release dependency rather than assuming the standards will arrive in time to rescue the self-assessment route. The routes, and which list you are on.
What to watch, and how often
Four things, and monthly is enough for all of them:
- The Official Journal, for citations of harmonised standards under the CRA. This is the one that changes your Annex VII point 5 answer and, for Class I, your conformity route.
- The implementing act specifying the SBOM format and elements under Article 13. Not adopted at the time of writing. When it lands, every SBOM you hold may need re-examining. Why.
- Further classification acts. An implementing regulation already gives technical descriptions of the Annex III and Annex IV categories, and the Commission can amend Annex III by delegated act. Your classification is not a permanent answer.
- Corrigenda to the Regulation itself. It has already been corrected twice, once substantively — a change to Article 64(10) that widened a penalty derogation. The text moves.
An honest note on confidence, because this page is more perishable than most. The two binding dates are corroborated across several independent sources. The standards tranches, their delivery dates and the two-month slip come from trackers and industry sources rather than from CEN, CENELEC, ETSI or the Commission directly, and they are a snapshot: if you are reading this some months after the date at the top, check them. The claim that none had been cited in the Official Journal is an accurate statement of what those sources reported at the time of writing, and it is the single statement here most likely to have changed — the Official Journal is the place to confirm it, and it takes minutes. The observation that citation historically lags delivery by months is drawn from how EU harmonisation legislation has worked generally and is not a prediction about these particular standards. Nothing here is legal advice.
When a standard is finally cited, your file has to change
Conformance House keeps the standards list central and pushes it into your documents when a tranche is published — and keeps the previous version, dated, because it is the one that governed the units you had already placed on the market.
Not sure which of these dates apply to you at all? Take the two-minute check.