Timeline and what to plan for
Product teams should treat 2026 to 2027 as the window to stand up component inventory, SBOM generation, vulnerability processes, and (separately) license disclosure workflows. Waiting until conformity assessment to discover you have no reviewed third-party license record creates dual fire drills.
Timelines vary by product class and implementing acts, and documentation must stay current through the support period. Confirm all dates with counsel; this page is not legal advice.
December 2024
CRA in force
The planning phase for manufacturers begins.
Milestone 1September 2026
Incident reporting applies
Early reporting obligations for actively exploited vulnerabilities and severe incidents.
Milestone 2December 2027
Broader requirements
Most other requirements apply for many products; confirm your classification.
Milestone 3
