11 Sep 2026
Reporting is already mandatory
Actively exploited vulnerabilities and severe incidents must be reported through ENISA's Single Reporting Platform. It covers products already on the market.
EU Cyber Resilience Act · Regulation (EU) 2024/2847
If you make software or connected hardware sold in the EU, you are already inside the reporting regime, and you have until 11 December 2027 to be CE marked for cybersecurity. This briefing pack is the position as it stands, written for product and security leaders rather than lawyers.
Scope, the four risk tiers, the 24-hour reporting clock, penalties and the standards timeline. One page, no vendor pitch.
We will email you the pack. No sequence you cannot leave in one click.
The CRA entered into force in December 2024. Most of the transition is behind us, and the obligations are now arriving in sequence.
11 Sep 2026
Actively exploited vulnerabilities and severe incidents must be reported through ENISA's Single Reporting Platform. It covers products already on the market.
9 Dec 2026
Software becomes a product. A missing security update can be argued as a defect, so CRA non-compliance stops being only a fine and starts being a claim.
11 Dec 2027
Essential requirements, conformity assessment, technical documentation and the EU declaration of conformity all apply in full.
Triggered by an actively exploited vulnerability in your product or a severe incident affecting its security. The clock starts the moment you become aware with a reasonable degree of certainty.
24h
Early warning
Member States affected, whether malicious action is suspected.
72h
Notification
Product details, nature of the exploit, corrective measures taken.
14d
Final report
Within 14 days of a fix or mitigation being available.
1mo
Incident close-out
Root cause and mitigation, within a month of the 72h notification.
ENISA's reporting platform does not record when you became aware. You evidence that timestamp from your own records, and there is no API yet, so nothing submits automatically from your tooling.
Classification turns on core functionality. No CRA harmonised standard has been cited in the Official Journal yet, so Class I products cannot currently count on self-assessment.
Default
Self-assessment
Apps, games, most IoT, business software installed locally.
Important · Class I
Self-assess only if a harmonised standard is fully applied, otherwise a notified body
Identity and PAM, browsers, password managers, anti-malware, VPNs, SIEM, operating systems, routers and switches, smart home devices.
Important · Class II
Notified body or EU certification scheme
Hypervisors and container runtimes, firewalls, intrusion detection and prevention, tamper-resistant microprocessors.
Critical · Annex IV
European cybersecurity certification where required
Hardware devices with security boxes, smart meter gateways, smartcards and secure elements.
Astragar classifies your products against the CRA tiers, maps the gap to Annex I, and puts a euro figure on the exposure that remains. The number a board can act on and an underwriter will recognise.
Book a 20-minute scoping callThis pack is a business briefing, not legal advice. Confirm product classification and your conformity route with EU regulatory counsel. Regulatory position as of 11 September 2026.
