Regulation (EU) 2024/2847
CRA deadlines — every date in Regulation (EU) 2024/2847 that applies to you
“The reporting obligations concerning actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements … should apply from 11 September 2026.”
The CRA does not arrive all at once. It phases in across three dates, and the one most organisations miss is that reporting bites more than a year before the rest.
Article 14 reporting obligations have applied since 11 September 2026. The bulk of the Regulation, including the Annex I SBOM requirement, applies from 11 December 2027.
A derogation matters for products already on the market: Article 14 reporting applies to products with digital elements that fall within scope and were placed on the market before the general date of application.
What it actually requires
- 10 December 2024
- Regulation (EU) 2024/2847 entered into force.
- 11 September 2026
- Article 14 reporting obligations apply: 24-hour early warning, 72-hour vulnerability notification, 14-day final report. Already in force.
- 11 December 2027
- The Regulation applies in full, including the Annex I SBOM obligation, CE marking, technical documentation and conformity assessment.
- Products already on the market
- By derogation, the Article 14 reporting duty reaches in-scope products placed on the market before the general date of application.
Dates that apply
| Date | What applies |
|---|---|
| 10 December 2024 | Entry into force. |
| 11 September 2026 | Article 14 reporting obligations apply. |
| 11 December 2027 | Full application, including the Annex I SBOM requirement. |
The rest of the CRA
- CRA Annex I: the SBOM Requirement in Full
- CRA Article 14: the 24-Hour Reporting Clock
- CRA Article 13: Manufacturer Obligations Explained
- EU Cyber Resilience Act — full compliance overview
Producing the Annex I SBOM and tracking which listed vulnerabilities actually affect your product is what O3 generates automatically, in CycloneDX or SPDX. Book a demo.