Independent information resource Product security · EU CRA
CRA fundamentals / 04

What Changed on 11 June 2026 Under the Cyber Resilience Act?

Learn what the 11 June 2026 Cyber Resilience Act milestone changed, why Chapter IV began applying, what it means for conformity assessment bodies and what it did not yet require from manufacturers.

IN BRIEF

The 11 June 2026 CRA milestone concerns the conformity assessment infrastructure. Chapter IV, Articles 35 to 51, began applying on that date. It did not move the main CRA manufacturer and product requirements forward from their general 11 December 2027 application date.

01 / 07

11 June 2026 Was the First Early CRA Application Date

Article 71 creates a phased application schedule for the Cyber Resilience Act. Although the Regulation entered into force in December 2024 and generally applies from 11 December 2027, Chapter IV was given an earlier date of 11 June 2026. That makes June 2026 the first major statutory application milestone within the CRA transition period. The reason is practical: the conformity assessment system needs authorities and qualified bodies before manufacturers reach the main product-compliance deadline. A functioning third-party assessment ecosystem cannot be created on the same day that thousands of products potentially need to use it. The early application of Chapter IV therefore supports institutional preparation while manufacturers, standards bodies, market participants and regulators continue preparing for the broader 2027 regime.

  • The CRA entered into force on 10 December 2024.
  • Chapter IV began applying on 11 June 2026.
  • Article 14 followed on 11 September 2026.
  • The Regulation generally applies from 11 December 2027.
02 / 07

What Chapter IV Covers

Chapter IV consists of Articles 35 to 51. Its focus is the notification of conformity assessment bodies and the institutional rules that support notified-body activity. The chapter addresses notifying authorities, their responsibilities, requirements for conformity assessment bodies, subsidiaries and subcontracting, applications for notification, the notification procedure, identification numbers and lists of notified bodies, changes to notification, challenges to competence, operational obligations, information duties and coordination. These provisions create the framework through which bodies can be recognised to perform CRA conformity assessment activities where the Regulation requires or permits their involvement. The chapter is therefore important to the future product-compliance system, but its legal subjects and purpose are different from the main cybersecurity duties imposed on manufacturers.

03 / 07

Member States Needed Notifying Authorities

The Commission's CRA implementation material identifies 11 June 2026 as the point at which provisions on the notification of conformity assessment bodies entered into application and Member States were to designate notifying authorities. A notifying authority performs a regulatory function rather than the product testing or assessment function of a notified body. Its role includes the assessment and notification framework for conformity assessment bodies and related monitoring responsibilities under the Regulation. Separating these roles is useful when planning CRA work because the organisation that supervises notification is not automatically the organisation that performs a manufacturer's conformity assessment. Businesses evaluating external assessment options should therefore distinguish national notifying authorities, conformity assessment bodies and bodies that have actually achieved notified status for the relevant CRA work.

  • A notifying authority manages the notification framework.
  • A conformity assessment body performs conformity assessment activities.
  • A notified body is a conformity assessment body notified under the applicable framework.
  • The roles should not be treated as interchangeable.
04 / 07

What the Date Did Not Mean for Manufacturers

The June milestone did not make the entire manufacturer compliance framework applicable. Article 71 continues to state that the Regulation generally applies from 11 December 2027. The early Chapter IV date therefore should not be converted into a claim that every manufacturer needed CRA technical documentation, an EU declaration of conformity, completed assessment and CRA-compliant product controls by June 2026. Manufacturer preparation is still important because conformity planning can require long lead times, but preparation and legal application are not the same thing. Product teams should use the transition period to determine likely scope, identify the product category, understand the relevant conformity route and collect evidence without misdescribing 11 June 2026 as the universal product-compliance deadline.

  • June 2026 was not the general manufacturer deadline.
  • Annex I product obligations generally wait for the main CRA application date.
  • Conformity planning can still need to begin well before 2027.
  • Product classification can influence the available assessment route.
05 / 07

Why the Conformity Assessment Infrastructure Matters Before 2027

For some products, manufacturers will be able to use conformity procedures that rely principally on their own assessment, while other circumstances can require third-party involvement. Product classification, applicable standards, certification and the conformity modules available under the CRA can influence the route. That means the availability of capable notified bodies can become a scheduling issue for manufacturers even before the main Regulation applies. A company that waits until late 2027 to determine whether external assessment is necessary could face capacity, evidence or remediation delays. The June 2026 framework is therefore not merely an institutional detail. It is part of the infrastructure that manufacturers may depend on when moving from cybersecurity design evidence to a legally defensible conformity process.

  • Determine the likely CRA product category early.
  • Identify whether third-party assessment may be required.
  • Track relevant notified-body availability.
  • Prepare technical evidence before seeking assessment.
  • Do not assume a conformity route solely from a product marketing label.
06 / 07

The Next Major CRA Date Was 11 September 2026

The next statutory milestone after Chapter IV was 11 September 2026. On that date Article 14 began applying, introducing mandatory reporting for manufacturers that become aware of specified actively exploited vulnerabilities or severe incidents affecting the security of products with digital elements. This September change is different in character from the June milestone. Chapter IV primarily establishes conformity assessment infrastructure, while Article 14 creates an operational reporting obligation directly relevant to manufacturers. Keeping the two dates separate helps organisations build the right workstream for each one: conformity planning and external-assessment readiness around the June framework, and rapid vulnerability and incident escalation around the September reporting regime.

  • 11 June 2026 concerns Chapter IV.
  • 11 September 2026 concerns Article 14 reporting.
  • 11 December 2027 remains the general CRA application date.
07 / 07

How Manufacturers Should Use the June 2026 Milestone

Manufacturers do not need to turn the June milestone into a fictional product deadline, but they should use it as a prompt to mature conformity planning. Build a product inventory, document likely CRA scope and classification, identify the manufacturer for each product and determine which products may require a conformity route involving a notified body. Map the technical evidence that such an assessment could rely on, including cybersecurity risk assessment, design decisions, testing, vulnerability-handling processes and product documentation. Track Commission guidance, harmonised standards activity and the notified-body environment as they develop. This approach keeps conformity work aligned with the actual CRA timetable while reducing the risk that external assessment becomes a late blocker close to December 2027.

  • Map products and classifications.
  • Identify likely conformity routes.
  • Track notified-body capacity and competence.
  • Build technical evidence progressively.
  • Keep the legal application dates attached to every readiness workstream.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.