Independent information resource Product security · EU CRA
CRA fundamentals / 06

What Changes on 11 December 2027 Under the Cyber Resilience Act?

Understand what changes when the main Cyber Resilience Act provisions become applicable on 11 December 2027, including manufacturer duties, essential cybersecurity requirements, conformity assessment, documentation and supply-chain responsibilities.

IN BRIEF

11 December 2027 is the CRA's main application date. From then, covered products entering the relevant EU market framework generally need to meet the CRA's product-security, vulnerability-handling, documentation, conformity and economic-operator requirements. Earlier Article 14 reporting remains in effect, while Article 69 provides an important transition for products placed on the market before the deadline.

01 / 08

11 December 2027 Is the Main CRA Application Date

The Cyber Resilience Act entered into force in December 2024, but Article 71 deliberately separates entry into force from application. Chapter IV began applying in June 2026 and Article 14 reporting began applying in September 2026. The wider regulatory framework generally applies from 11 December 2027. This is the date on which CRA readiness moves from a transition programme into the normal product-compliance environment for covered products. A manufacturer should therefore not treat December 2027 as the point at which compliance work starts. Product architecture, security controls, documentation, support planning, component management and conformity assessment can require substantial lead time. The deadline is better understood as the date by which relevant product and economic-operator processes need to operate under the applicable CRA framework.

  • 10 December 2024: Regulation entered into force.
  • 11 June 2026: Chapter IV began applying.
  • 11 September 2026: Article 14 began applying.
  • 11 December 2027: the Regulation generally becomes applicable.
02 / 08

Manufacturer Product-Security Duties Become Central

Article 13 places the central CRA responsibilities on manufacturers. When the main provisions apply, manufacturers of covered products need to ensure that products are designed, developed and produced in accordance with the applicable essential cybersecurity requirements. The manufacturer must perform a cybersecurity risk assessment and take its results into account throughout planning, design, development, production, delivery and maintenance. CRA compliance therefore cannot be reduced to a final penetration test or a declaration signed shortly before release. The product record needs to connect the identified cybersecurity risks with design controls, testing, known dependencies, vulnerability-handling arrangements and evidence that the applicable requirements have been considered. For organisations with large portfolios, this makes product ownership and repeatable evidence collection particularly important.

03 / 08

Annex I Becomes a Core Product Engineering Reference

Annex I contains the CRA's essential cybersecurity requirements. Part I addresses cybersecurity properties of products with digital elements, while Part II addresses vulnerability handling. Manufacturers need to translate the legal requirements into product-specific controls and evidence rather than use the Annex as a generic policy checklist. Depending on the product and its risk assessment, this can involve secure-by-default configuration, protection against unauthorised access, confidentiality and integrity controls, attack-surface reduction, resilience, logging, security updates and systematic vulnerability handling. The exact control set must be tied to the product's intended purpose and cybersecurity risks. A manufacturer that has mapped Annex I only at company-policy level may therefore still lack the product-level evidence necessary for CRA conformity.

  • Map Annex I requirements to specific product controls.
  • Connect controls to the cybersecurity risk assessment.
  • Retain verification and testing evidence.
  • Keep vulnerability handling connected to supported product versions.
04 / 08

Documentation and User Information Become Part of Compliance

CRA compliance also requires evidence and product information. Manufacturers need technical documentation capable of demonstrating conformity with the Regulation, and the product must be accompanied by the applicable information and instructions for users. The technical file should reflect the actual product version, design and security decisions rather than exist as a separate generic compliance library. Product teams should know where the cybersecurity risk assessment, architecture evidence, dependency information, test results, vulnerability process and conformity evidence are maintained. User-facing information also matters because secure installation, operation, maintenance and support depend partly on communicating the correct assumptions and instructions. Documentation therefore becomes part of the product lifecycle instead of a task left solely to legal or certification teams.

  • Maintain technical documentation for the actual product.
  • Keep the risk assessment aligned with product changes.
  • Provide required user information and security instructions.
  • Preserve evidence needed for conformity assessment and market surveillance.
05 / 08

Conformity Assessment and CE Marking Matter at Market Placement

Before a covered product is placed on the market under the applicable CRA regime, the manufacturer needs to follow the appropriate conformity assessment procedure. The available route depends on matters including the product category and the conditions set by the Regulation. Some products can use a manufacturer-led conformity route in specified circumstances, while important or critical products can face stricter assessment requirements. Once conformity has been demonstrated through the applicable procedure, the manufacturer completes the required declaration and CE marking process. Classification should therefore happen early. A company that discovers late in development that a product needs notified-body involvement may face evidence gaps or scheduling delays that cannot be solved simply by preparing more documentation during the final weeks before release.

  • Classify the product before selecting the conformity route.
  • Determine whether third-party assessment may be necessary.
  • Build technical evidence before the assessment stage.
  • Treat CE marking as the result of conformity work, not as the compliance process itself.
06 / 08

Importers and Distributors Also Enter the Main CRA Framework

The December 2027 application date is not only a manufacturer milestone. Importers and distributors have role-specific obligations under the CRA. Their responsibilities include checks and actions connected to the products they place or make available on the Union market. The exact duty depends on the economic-operator role, which is why supply-chain mapping should be completed before the deadline. A company can also acquire manufacturer responsibilities in certain situations, including own-brand arrangements or substantial product modifications. Commercial contracts can allocate operational work, but they do not automatically replace the legal role assigned by the Regulation. Businesses that distribute large product portfolios should therefore know the manufacturer, market route, conformity evidence and escalation contact for each relevant product rather than relying only on supplier warranties.

  • Map manufacturer, importer and distributor roles.
  • Review own-brand and modification arrangements.
  • Maintain access to required product and conformity information.
  • Create escalation routes for suspected non-conformity and cybersecurity issues.
07 / 08

Article 14 Reporting Does Not Start Again in 2027

Article 14 reporting is already applicable before the main CRA deadline. Manufacturers have been subject to the specified reporting regime since 11 September 2026. December 2027 therefore does not create the first reporting obligation. Instead, it brings the broader product and economic-operator framework into application while the reporting process continues. This distinction matters when building compliance ownership. Product-security teams should already have escalation and Single Reporting Platform procedures in 2026, while the wider product engineering, technical documentation, conformity and supply-chain controls mature for 2027. Keeping these workstreams connected helps prevent reporting from becoming an isolated emergency process with no link to the product inventory, support record or vulnerability-handling system.

  • Article 14 reporting is already active before December 2027.
  • The main 2027 deadline expands the applicable CRA framework.
  • Reporting and product-compliance evidence should use the same product records.
08 / 08

Article 69 Creates an Important Legacy-Product Transition

Not every product already on the EU market automatically becomes subject to every CRA requirement on 11 December 2027. Article 69 contains transitional provisions for products with digital elements placed on the market before that date. In general, those products become subject to the CRA requirements if they undergo a substantial modification from the main application date. Article 14 is an express exception and applies to in-scope products placed on the market before December 2027 as well. This means portfolio planning should separate new products, legacy products, products expected to receive major feature changes and products receiving only ordinary maintenance or security updates. The transition can materially affect which compliance workstream applies to a particular product version.

  • Identify products placed on the market before the main application date.
  • Track post-2027 changes that could be substantial modifications.
  • Do not overlook the Article 14 reporting exception.
  • Document the reasoning behind transitional treatment.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.