What is added from 11 December 2027
The reporting duty is the first step. Conformity, documentation and support period follow.
Two dates, not one
The Cyber Resilience Act applies in stages. The reporting obligations under Article 14 apply from 11 September 2026 — including for products already placed on the market. The remaining manufacturer obligations apply from 11 December 2027.
Treating the first date as an isolated event means building reporting capability and starting over a year later. It makes more sense to see the notification as the first building block of a product file that will be required anyway.
What is required then
Products with digital elements must meet the essential cybersecurity requirements of Annex I, undergo a conformity assessment procedure and carry an EU declaration of conformity. The technical documentation under Annex VII must evidence this.
This includes a software bill of materials covering at least the top-level dependencies. It also includes a defined support period during which vulnerabilities are remediated — generally at least five years, shorter only where the product's expected lifetime is shorter.
Throughout that period: vulnerabilities must be remediated without delay, security updates provided, and users informed about available updates.
What can already be prepared now
Three things pay off regardless of the date: a reliable list of your own products with versions and support period, a bill of materials per release, and a defined procedure for who is reachable within 24 hours in a real case and permitted to report.
The last point is where it fails in practice. A 24-hour deadline is not a task for the next sprint planning but for a named person with a deputy.
Deadline running? Work the case through step by step.
Open the reporting assistant