Result · E2

Manufacturer — important, class II.

What this means for you

Conformity assessment by a notified body (Module B+C or H).

Your first 5 steps

  1. Define the support period and list your products.
  2. Generate an SBOM from your current build.
  3. Set up a vulnerability-reporting channel and a CVD policy.
  4. Decide who monitors vulnerabilities and who files reports (EU Login + registration on ENISA's Single Reporting Platform).
  5. Start the technical documentation per Annex VII.

Deadlines

Reporting obligation · Art. 1411 Sep 2026
Full conformity + CE11 Dec 2027

Article 14 reporting applies to you from 11 September 2026. The full Annex I requirements apply only if the product is substantially modified after 11 December 2027 (Article 69). Recommendation: sort out your SBOM and reporting channel now — you will need them for your first report.

Key facts

  • The Cyber Resilience Act is Regulation (EU) 2024/2847; obligations phase in over time.
  • From 11 September 2026: report actively exploited vulnerabilities and severe incidents (24 h / 72 h / 14 days) via ENISA's Single Reporting Platform.
  • From 11 December 2027: no product with digital elements on the EU market without CE marking and the Annex I security requirements.
  • Penalties up to €15 million or 2.5 % of worldwide annual turnover.

Source: EUR-Lex (Regulation (EU) 2024/2847); European Commission guidance of 27 July 2026.

Disclaimer

Informational tool based on Regulation (EU) 2024/2847 and the European Commission's guidance as of 27 July 2026. Not legal advice and not a conformity assessment; borderline cases (especially SaaS, open source and custom development) should be reviewed with a professional.