If you sell internet-connected hardware, software, or combined hardware-software products to the EU, you have most likely heard of the “CRA”. What confuses many people most is not the specific compliance requirements, but “when exactly do I need to comply?” — after all, regulatory documents are often hundreds of pages long, and terms like “entry into force”, “application”, and “transition period” can easily be confusing. This article clarifies the CRA implementation milestones from three dimensions: official timeline, role responsibilities, and special scenarios.
Must-Know for Beginners: Core Conclusions and Basic Concepts
First memorize the three core timeline milestones, and you can fill in the rest of the details later:
First, the CRA officially becomes EU law on December 10, 2024, but full compliance is not required immediately at this time; this is only the legal baseline for all scheduling.
Second, the first mandatory corporate obligation will come into effect on September 11, 2026: reporting of vulnerabilities and serious security incidents, but only for actively exploited critical vulnerabilities and incidents that have a significant impact on product security.
Third, starting from December 11, 2027, all products within the scope of compliance that are newly placed on the EU market must meet all market placement requirements; existing products that were legally placed on the market before this date will follow the old rules and do not need to undergo new market placement compliance.
What is the CRA (Plain Language Version)
Some people may still not be clear about what the CRA is. Here is a plain language explanation: it is a mandatory cybersecurity regulation issued by the EU for products with digital elements sold to the EU, with the full name Cyber Resilience Act (CRA for short), and the official regulation number is Regulation (EU) 2024/2847.
Unlike many EU directives that require transposition by each member state, the CRA is a regulation directly applicable in the EU, implemented uniformly by all member states without the need for each country to separately adapt it into local law. The statutory maximum fine for serious violations can reach 15 million euros or 2.5% of global annual turnover, whichever is higher; there are lower fine caps for general violations and provision of false information. The actual penalty will be determined based on the local rules of the member state and the circumstances of the individual case. Products with serious violations may also be restricted from being sold in the EU, and violations do not automatically result in the maximum penalty.
Why Timeline Milestones Are the Core Basis for Preparation
The reason we need to clarify the timeline milestones first is that the CRA’s obligations are implemented in phases, not all required as soon as the regulation enters into force; moreover, the trigger time for obligations varies for different roles and different types of products. If you get the timing wrong, you will either waste a lot of unnecessary costs by preparing too early, or miss the milestone and face penalties or market restrictions, which is not worth the loss.
Clarification of Easily Confused Time Concepts
Many people cannot distinguish between the terms “adoption”, “publication”, “entry into force”, and “application”, which is the root cause of all timeline confusion. Let’s use the familiar analogy of school rules to clarify them all at once, and we will use these terms directly later:
- Adoption: It is like the school board voting to approve the text of new school rules, which is a key step in the legislative process, but it is not the starting point for everyone to start complying with specific requirements; all statutory times are subject to the officially published version.
- Publication: It means posting the final version of the school rules on the school’s official bulletin board. All times related to the school rules are calculated from the date of publication; the CRA was published on November 20, 2024, in the Official Journal of the European Union (OJEU), which is the starting point for all statutory times.
- Entry into force: It means that after a specified number of days following publication, the school rules officially become rules that must be followed, and the framework clauses take effect immediately; the CRA enters into force on the 20th day after publication, which is December 10, 2024.
- Application: It means that a specific requirement in the school rules begins to be enforced. For example, requirements that require preparation time, such as “new access control must be installed in dormitories”, will have a transition period of several months, and will officially apply after the transition period ends; most of the CRA’s obligations related to enterprise products have their own application times, and are not required immediately upon entry into force.
Core Logic of Timeline Division
The entire CRA timeline can be understood from two dimensions:
By phase, it is “legislative implementation → phased activation of obligations → full-lifecycle normalized compliance”; long-term obligations include security support, record retention, etc.
By product differences, the higher the product classification, the more complex the compliance requirements, but the deadline for full market placement compliance is unified for all product categories, and compliance will not be required earlier due to higher risk — this is different from the early draft, which will be specifically discussed later.
Core Statutory Timeline
The following are all statutory timeline milestones officially confirmed by the EU. All dates are subject to the final regulation published in the Official Journal of the European Union, and there are no so-called “early implementation” or “special channels” circulating online:
| Phase Name | Official Date | Legal Basis | Applicable Objects | Directly Generates Corporate Obligations | Key Exceptions |
|---|---|---|---|---|---|
| Publication in Official Journal | 2024.11.20 | OJEU published version / Release information of Regulation (EU) 2024/2847 | All relevant parties | No | The final regulation text is subject to this version |
| Official Entry into Force of the Regulation | 2024.12.10 | Article 71 | All relevant parties | No (only framework clauses enter into force) | No substantive product compliance requirements |
| Application of Conformity Assessment and Notified Body System | 2026.06.11 | Chapter IV | Member state regulatory authorities, third-party notified bodies | Indirect impact | Certification feasibility depends on the progress of notified body designation, the release of harmonized standards/common specifications, and product categories |
| Application of Vulnerability and Security Incident Reporting Obligation | 2026.09.11 | Article 14 | Manufacturers of products within the scope of jurisdiction | Yes | Only two specific types of situations need to be reported, covering all products on sale |
| Full Application of Product Compliance Requirements | 2027.12.11 | Article 71 | New products within the scope of jurisdiction, all economic operators | Yes | Only applicable to products first placed on the EU market after this date |
| Implementation of Penalty Rules and Market Surveillance Mechanism | Before 2027.12.11 | Chapter VI | EU member states | Indirect impact | Member states must establish local enforcement rules before this date |
| Security Support Period | From the date of first placement of the product | Article 10 | Manufacturers | Yes | Triggered by the first placement of products within the scope of jurisdiction and the application of corresponding obligations; it is not required that all historical products be retroactively compliant upon entry into force of the regulation; products with an expected service life shorter than 5 years can be set according to actual conditions |
| Record Retention Period | Varies by data type | Article 13, etc. | Manufacturers, importers, etc. | Yes | Triggered by the first placement of products within the scope of jurisdiction and the application of corresponding obligations; it is not required that all historical products be retroactively compliant upon entry into force of the regulation; if the support period is longer than 10 years, technical documents shall be retained for the same length as the support period |

Starting Point of Legislative Implementation: Publication in the Official Journal (2024.11.20)
This is the starting point for all statutory times. The final official text of the CRA is subject to the version published in the Official Journal of the European Union, and any previous drafts or discussion papers are not valid. For enterprises, there are no mandatory obligations at this milestone; they can only obtain the official regulation text and start preliminary preparation and investigation.
Official Entry into Force of the Regulation (2024.12.10)
According to Article 71 of the CRA, the regulation officially enters into force on the 20th day after publication and is incorporated into the EU legal system.
The clauses that take effect immediately after entry into force are framework clauses, such as the definition of the scope of application, the requirements for the establishment of competent authorities in each member state, and the basic principles of penalties. For enterprises, there are still no substantive mandatory product compliance requirements at this stage. There is no need to rush to modify products or conduct certifications; you can first conduct a gap assessment: see which of your products are within the scope of jurisdiction, and how far your current security level is from the requirements.
Application of Conformity Assessment and Notified Body System (2026.06.11)
Many people have not noticed this milestone, which mainly sets rules for regulators and third-party conformity assessment bodies (commonly referred to as “notified bodies”). According to the requirements of Chapter IV of the CRA, from this date onwards, the qualification accreditation rules for notified bodies and the process framework for conformity assessment officially enter into force.
The impact on enterprises is: you can start contacting notified bodies to understand the specific certification requirements and processes, but you cannot confirm that all products can immediately obtain final certification conclusions solely based on the milestone of June 11, 2026 — because notified bodies need time to complete qualification accreditation, and the supporting harmonized standards and common specifications may still be under development. There is no need to spend money too early to rush for the so-called “first batch of certifications”.
Application of Vulnerability and Security Incident Reporting Obligation (2026.09.11)
This is the first mandatory obligation directly imposed on enterprises, based on Article 14 of the CRA.
Special attention should be paid to its application premise: as long as the product is within the scope of CRA jurisdiction and the manufacturer is aware of the relevant situation, the reporting obligation must be fulfilled, and it covers all products sold in the EU — whether they are existing products launched before December 11, 2027, or new products launched after that date, they must comply.
But there is no need to be overly nervous. There are only two types of conditions that trigger reporting, not all vulnerabilities need to be reported:
The first type is actively exploited critical vulnerabilities;
The second type is incidents that have a serious impact on product security.
Reporting is tiered, and you do not need to submit a complete investigation report at the beginning:
- Within 24 hours: submit an early warning, only need to clarify the core facts, no need to wait for the complete investigation results;
- Within 72 hours: submit a formal notification, including a preliminary impact assessment and measures already taken;
- Follow-up: follow up on the remediation progress as required by the regulator, and finally submit a closure report.
The submission time, field requirements, and platform operation details of the final closure report are subject to the implementation rules and platform specifications subsequently issued by ENISA and the EU; at this stage, enterprises can first build an internal process framework for vulnerability discovery, classification, escalation, evidence retention, and external reporting. The submission channel is the unified reporting platform of the European Union Agency for Cybersecurity (ENISA). The specific operation processes, templates, etc. will be issued by ENISA in subsequent implementation rules. Enterprises can build internal vulnerability response processes in advance, and do not need to wait for the platform to go live before preparing.

Full Application of Product Compliance Requirements (2027.12.11)
This is the core milestone that everyone is most concerned about, based on Article 71 of the CRA.
There are two prerequisites for its application, both of which are indispensable: first, the product is within the scope of CRA jurisdiction; second, the product is first placed on the EU market after this date.
Here, we must thoroughly understand the concept of “first placement on the EU market”: it refers to the first time a product is made available for sale or use on the EU market, and has nothing to do with production time, inventory time, or the production time of subsequent batches of the same model. For example, a batch of smart routers produced in 2025 but first made available for sale or use on the EU market on or after December 11, 2027 must meet the CRA market placement compliance requirements; if the specific product was legally first placed on the EU market before December 11, 2027, it is an existing product and does not need to undergo new market placement compliance, except for the reporting obligation under Article 14 and the material modification rules.

The judgment object must be specific products or clear product versions/batches that have completed first placement before December 11, 2027: only specific products that have been legally first placed on the EU market can continue to be sold under the existing product rules; subsequent production of the same model does not in itself change the compliance deadline, but inventory, new batches or new versions that first enter the EU market after December 11, 2027, if they cannot prove that they were legally placed before, need to meet the CRA market placement compliance requirements; if a product undergoes material modification, it is regarded as a new product and the timeline milestones need to be recalculated.
At this milestone, the core obligations that manufacturers need to complete include: meeting basic cybersecurity design requirements, completing conformity assessment, issuing an EU declaration of conformity, affixing the CE mark, retaining technical documentation, and clearly informing users of the security support period and update policy.
Different economic operators have different responsibilities, so don’t confuse them:
- Importers: need to verify the CE mark, declaration of conformity and other materials of the product, and cannot place non-compliant new products on the EU market;
- Distributors: need to ensure that the product’s labeling meets the requirements, and cannot sell new products that they know are non-compliant;
- Authorized representatives: only undertake designated responsibilities in accordance with the manufacturer’s entrustment, and will not automatically assume all technical compliance responsibilities of the manufacturer.
It is also necessary to emphasize a point that many people are misled by old information: the market placement compliance deadline is unified for all product categories, and the difference between different categories is only in the complexity of conformity assessment requirements, not in time. The “2-year transition period for high-risk products” mentioned in the early draft has been deleted, so don’t believe outdated information.
Implementation of Penalty Rules and Market Surveillance Mechanism (Before 2027.12.11)
According to the requirements of Chapter VI of the CRA, each member state needs to establish local penalty enforcement rules and market surveillance processes before December 11, 2027.
The EU sets the minimum standard for the maximum fine, and the maximum set by member states cannot be lower than this level. The actual penalty amount will be determined based on factors such as the severity of the case, the duration of the violation, and the cooperation of the enterprise, and violations do not automatically result in the maximum penalty. The specific three tiers of caps are:
- Serious violations (such as failure to meet core security requirements, failure to fulfill vulnerability reporting obligations, etc.): up to 15 million euros or 2.5% of global annual turnover, whichever is higher;
- General violations (such as failure to retain documents as required, failure to provide necessary information to users, etc.): up to 10 million euros or 2% of global annual turnover, whichever is higher;
- Provision of false information: up to 5 million euros or 1% of global annual turnover, whichever is higher.
Regulatory measures include requiring correction, product recall, supply restriction, etc. Sales ban is only a possible result of serious violations, not automatically triggered.
Long-Term Compliance: Security Support Period Rules
The security support period is an important part of the CRA’s full-lifecycle requirements, based on Article 10.
The statutory requirement is: the security support period shall reflect the expected service life of the product, and in principle shall not be less than 5 years; if the expected service life of the product is originally shorter than 5 years (such as some low-cost disposable smart devices), it can be set according to the actual expected service life, but must be clearly informed to users.
The starting point of the support period is the day the product is first placed on the EU market, not the day the user purchases it. During the support period, manufacturers need to provide free security updates, disclose vulnerability handling policies and contact channels, and cooperate with the official coordinated disclosure mechanism. It should be noted that only security-related updates are mandatory, and ordinary function updates are not within the scope of mandatory provision.
Long-Term Compliance: Record Retention Period Rules
The second long-term obligation is record retention, based on Article 13 and other relevant clauses of the CRA. Different data have different retention requirements and cannot be generalized:
- Technical documentation, EU declaration of conformity: retained for at least 10 years from the date of first placement of the product on the EU market; if the security support period of the product is longer than 10 years, the retention period shall be the same as the security support period;
- Vulnerability report records, security update records: need to be retained for at least 2 years after the end of the security support period.
These records must be submitted within the specified time limit when required by the market surveillance authority. Enterprises can set shorter internal response targets by themselves, but they cannot be slower than the statutory requirements.
Key Timeline Focus for Different Economic Operators
After clarifying the general timeline, readers in different roles can directly correspond to the key points they need to pay attention to, without having to focus on all milestones.
Manufacturers (Core Responsible Parties)
Manufacturers are the first responsible parties for CRA compliance, including own-brand parties, OEM producers, and entities that make material modifications to products.
Statutory timeline milestones you need to remember (see Chapter 2 for specific rules):
- From 2026.09.11: Fulfill the Article 14 vulnerability and security incident reporting obligation for products within the scope of jurisdiction that are on sale;
- From 2027.12.11: Products within the scope of jurisdiction newly placed on the EU market must meet all market placement compliance requirements;
- Long-term: Provide security updates according to the promised security support period, and retain compliance records.
If you want to prepare, you can refer to this practical rhythm (not statutory mandatory, just empirical advice): - Before the end of 2025: Complete product scope identification, classification determination, and compliance gap assessment, figure out how many products need to be compliant, which category they belong to, and how far they are from the requirements;
- After June 2026: Contact notified bodies to confirm which type of conformity assessment your products need, and schedule in advance;
- Before mid-2027: Complete conformity assessment, CE mark preparation, and technical documentation archiving, leaving sufficient time for rectification and buffering.
Other Roles in the Economic Operator Responsibility Chain
Many people cannot clarify the responsibilities of authorized representatives, importers, distributors, and logistics service providers. The general principle is: each role only assumes responsibilities within the statutory or entrusted scope, and will not automatically undertake all technical compliance obligations of the manufacturer.
- Authorized representative: Voluntarily designated by a non-EU manufacturer (not a mandatory requirement), it is one of the responsible entities within the EU. The specific responsibilities are subject to the entrustment agreement, usually including retaining technical documentation, liaising with regulators, etc., and the time requirements are synchronized with the corresponding obligations of the manufacturer.
- Importers: From 2027.12.11, they shall not place non-compliant new products on the market, and need to verify upstream CE marks, declarations of conformity and other materials. Importers are one of the responsible entities within the EU, and bear the obligation to assist in market surveillance liaison, but do not automatically assume the technical compliance responsibility of the manufacturer; if an importer uses its own brand or makes material modifications to the product, it is regarded as a manufacturer and shall bear full responsibility.
- Distributors: From 2027.12.11, they shall not sell new products that they know are non-compliant, and need to ensure that the product’s labeling meets the requirements. The main responsibility of distributors is to retain supply chain traceability information and cooperate with regulatory spot checks.
- Fulfillment service providers: For example, e-commerce warehousing and distribution, drop-shipping service providers, need to cooperate with regulators to provide relevant information on the product supply chain from 2027.12.11. The CRA obligations of such service providers are centered on supply chain information cooperation, and they do not automatically become the responsible entity for product compliance just because they provide warehousing, packaging or distribution services; but if they sell products under their own brand or make material modifications to products, they need to bear corresponding responsibilities in accordance with the manufacturer rules.
Non-EU Enterprises / Cross-Border Sellers
Many cross-border sellers will ask “My company is not in the EU, are the requirements looser?” The answer is: the statutory time requirements are exactly the same as those for local EU manufacturers, and will not be relaxed just because the registered address is outside the EU.
You can choose the compliance path by yourself: you can designate an EU authorized representative as the domestic responsible entity, or you can not designate one — if you do not designate one, the importer within the EU will bear the relevant obligations for market surveillance liaison. There is no mandatory requirement to designate an authorized representative, just choose according to your own supply chain model.
Ordinary Consumers / Enterprise Procurers
If you are only the party buying products, you do not need to bear compliance responsibilities, just know:
For new connected products purchased after the full market placement compliance milestone, you can check the CE mark and the manufacturer’s security update commitment to choose products with more guarantees;
If it is enterprise procurement, you can write the CRA compliance requirements into the supplier contract in advance to avoid purchasing non-compliant products later;
You don’t need to report vulnerabilities to the regulator by yourself, just pay attention to the manufacturer’s security announcements.
Timeline Determination Rules for Special Scenarios
Now that the general timeline is clear, how to determine the time when encountering some special situations, such as existing products, product modifications, and open source software? You can follow this five-step decision logic:
Step 1: First confirm whether the product is within the scope of CRA jurisdiction;
Step 2: Confirm the time when the product is first placed on the EU market, and determine whether it is necessary to comply with the full market placement compliance requirements;
Step 3: If the product is produced before the full compliance milestone, determine whether it is an existing product already on the market or unsold inventory — if the inventory is first placed after the compliance milestone, it also needs to be compliant;
Step 4: Determine whether the product has undergone material modification. If material modification is triggered, it is regarded as a new product and the time is recalculated;
Step 5: Determine whether the software/firmware update will affect the original conformity, and decide whether to re-conduct the conformity assessment.
The following are the specific determination rules for several of the most common special scenarios:
Boundary Between Existing Products and Inventory
The core distinguishing standard between the two types of products is “whether the legal first placement on the EU market has been completed before December 11, 2027”:
- Existing products: Specific products that have completed first placement can continue to be sold without re-doing market placement compliance;
- Unplaced inventory: Products that have been produced but have not completed first placement, and are placed after December 11, 2027, need to meet the CRA requirements.
Both types of products are required to fulfill the Article 14 vulnerability and security incident reporting obligation starting from September 11, 2026, and are regarded as new products after material modification.
Determination Rules for Material Modification
If a product already on the market is modified, when will it be regarded as a “new product” that needs to be re-compliant?
The core of the determination is: whether the modification changes the intended use, core security attributes or risk level of the product, and affects the original conformity assessment conclusion. If so, it is regarded as a new product and needs to re-meet the CRA market placement compliance requirements, with the time calculated from the date when the modified product is first placed on the EU market.
Common situations that do not trigger material modification: regular security patches, ordinary bug fixes, these do not count, but you need to keep good assessment records to prove that the modification will not affect the original conformity.
Not all function updates trigger material modification; it should be judged based on the actual impact of the modification on security compliance, and there is no need to be nervous as soon as there is an update.
Timeline and Responsibility Determination for Open Source Software
The responsibility and timeline determination for open source software is another high-frequency question. The core is the three-part method, and it cannot be generalized:
- Purely non-commercial open source projects that are not sold in the EU market (including the maintenance of public open source components): generally do not bear market placement compliance obligations as manufacturers under the CRA; but if the component is integrated into a commercial product and sold to the EU, the final product manufacturer still needs to bear the corresponding compliance responsibility.
- Open source components integrated into commercial products sold to the EU: the compliance responsibility is borne by the manufacturer of the final product, and the time is calculated based on the launch time of the final product, which has nothing to do with the release time of the open source component;
- For those who provide open source products commercially, or provide open source components as part of commercial products and sell them to the EU, the provider may be regarded as a manufacturer; if it is only a pure cloud service or commercial support service, it is necessary to first determine whether it constitutes a product under the CRA or a remote data processing solution related to product functions, and then determine whether it applies.
3-Step Self-Test: Calculate Your Exclusive Compliance Timeline
After reading the general rules and special scenarios, you can use these three steps to quickly calculate your exclusive compliance timeline and preparation rhythm:
Step 1: Check Scope of Application and Exclusions
First confirm whether your product is under the jurisdiction of the CRA. The core determination conditions must be met at the same time:
- The product has digital elements;
- It is planned to be sold to or targeted at the EU market.
Having digital elements does not mean that it must be connected to the internet. Standalone software, hardware with embedded software, combined hardware-software products, and scenarios where the remote data processing solution is related to product functions should all be included in the initial screening.
If the core conditions are met, then check whether it falls within the statutory exclusion scope (based on Article 2 of the CRA, which needs to be verified in combination with specific clauses, and cannot be judged solely by industry):
- Products for military, defense or national security purposes;
- Prototype products used only for R&D and not placed on the market;
- Specific non-commercial, non-market-placed scenarios need to be judged in combination with Article 2 and relevant definitions; connected products sold to EU consumers, even if ultimately used for private purposes, usually cannot claim exclusion solely on the basis of “private use”;
- Products whose cybersecurity requirements have been fully covered by other EU special regulations (such as medical devices compliant with MDR, automobiles compliant with UN R155, etc., shall be subject to the specific clauses of the special regulations, and cannot be automatically excluded just because you are in the medical industry).
Here is a boundary to remind: whether SaaS, pure cloud services, and remote services belong to “products” as defined by the CRA needs to be judged according to specific scenarios, and you can refer to the guidelines subsequently issued by the EU official.
Step 2: Determine Conformity Assessment Path Based on Annex III Classification
After confirming that the product is within the scope of jurisdiction, you should compare it with the product list in Annex III of the CRA to determine the product classification. Different classifications have different conformity assessment requirements and different preparation cycles.
Statutory product classification does not use popular terms such as “high/low risk”, and is officially divided into four categories:
- Ordinary products: products with digital elements not listed in Annex III;
- Important products Class I: categories with lower risk in Annex III;
- Important products Class II: categories with higher risk in Annex III;
- Critical products: specific products that have a significant impact on critical infrastructure.
The differences between different classifications are not only the difference between “self-declaration” and “third-party certification”, but also include technical documentation requirements, applicable standards, regulatory intensity, etc., which should be prepared in combination with specific requirements.
When determining, note that the industry is only a reference clue. Ultimately, it needs to be confirmed against the product list in Annex III, harmonized standards and common specifications, and cannot be directly classified by industry.
Step 3: Back-Calculate the Preparation Cycle
The last step is to back-calculate your preparation time based on the statutory milestones. What is given here is practical advice, not statutory mandatory requirements, and you can adjust it according to your product complexity:
Statutory milestones are still implemented in accordance with Chapter 2: the Article 14 reporting obligation is activated on 2026.09.11, and the market placement compliance requirements for newly placed products are fully applied on 2027.12.11.
Reference for preparation time:
- Products that may require stricter conformity assessment or third-party institution participation (common in some important products Class II and critical products, specific requirements are subject to Annex III, harmonized standards/common specifications and applicable assessment modules): start preparation at least 12 months in advance, including time for institution liaison, testing, and rectification;
- Ordinary self-declaration products: start at least 6 months in advance.
Be sure to reserve extra buffer time: the scheduling of notified bodies and the rectification time for failed tests will vary depending on the product and institution. Do not prepare just in time to avoid missing the deadline.
Avoiding Common Misconceptions
Finally, we have sorted out 10 of the most common misconceptions about the CRA timeline, which many people have fallen into. Avoiding them in advance can save a lot of wasted money and time:
Timeline Milestone Misconceptions
- Misconception: The CRA entry into force date is the full compliance date
Clarification: Entry into force only means that the regulation is officially incorporated into the EU legal system. Core product compliance obligations have a transition period, and full compliance is not required as soon as it enters into force. - Misconception: The compliance deadline for high-risk products is earlier
Clarification: The final version of the CRA uniformly stipulates that the full market placement compliance date is the same for all product categories, and the differentiated transition period in the early draft has been invalidated; different categories only have different compliance requirements, and the time is exactly the same. - Misconception: There are no time requirements after the transition period ends
Clarification: The CRA is a full-lifecycle compliance requirement. After the transition period ends, there are still long-term obligations such as security support period, record retention period, and tiered vulnerability notification. - Misconception: “Placing on the market” means production or sale
Clarification: “First placement on the EU market” specifically refers to the first time a product is made available for sale or use on the EU market. Production, inventory, and production of subsequent batches of the same model will not individually trigger new market placement compliance obligations.
Obligation and Responsibility Misconceptions
- Misconception: After the vulnerability reporting obligation is activated, all vulnerabilities of all products on sale must be reported
Clarification: Only known, actively exploited critical vulnerabilities or serious security incidents need to be reported, and the product must be within the scope of CRA jurisdiction; not all vulnerabilities need to be reported. - Misconception: A complete technical investigation report must be submitted within 24 hours
Clarification: Only an early warning explaining the core facts needs to be submitted within 24 hours; a formal notification including a preliminary impact assessment and measures already taken shall be submitted within 72 hours; the complete investigation report can be supplemented later as required. - Misconception: Old products are completely unaffected by the CRA
Clarification: Existing products only do not need to re-do market placement compliance, but still need to fulfill the vulnerability reporting obligation; they are regarded as new products after material modification. For specific rules, see Chapter 4 Special Scenario Determination. - Misconception: Importers/authorized representatives must bear all the responsibilities of manufacturers
Clarification: Importers only bear statutory obligations such as verification and assisting regulators, and the responsibilities of authorized representatives are subject to the entrustment agreement. Neither will automatically undertake all technical compliance responsibilities of the manufacturer.
Compliance Certification Misconceptions
- Misconception: Having a CE mark means meeting the CRA requirements
Clarification: Old CE marks may be obtained in accordance with other EU regulations and do not cover the CRA cybersecurity requirements; it is necessary to verify the scope of regulations corresponding to the CE mark, and the CE mark is not the only evidence of compliance. - Misconception: Open source software/non-EU enterprises do not need to comply with the CRA
Clarification: Commercialized open source products/components sold to the EU need to be compliant, and non-EU enterprises selling products to the EU are also under the jurisdiction of the CRA; only purely non-commercial open source products that have not entered the EU market are not bound.
Quick Reference, Evidence List and Action Summary
Finally, we have sorted out the quick reference tools that can be saved, the list of evidence that needs to be retained, and the action priorities for your convenience to check at any time later.
CRA Core Timeline Milestone Quick Reference Table
If you don’t want to read the long article, you can directly save this simplified table, which contains all the key information:
| Phase Name | Official Date | Core Obligation Reminder |
|---|---|---|
| Publication in Official Journal | 2024.11.20 | Starting point for statutory time calculation, final regulation text is subject to this version |
| Official Entry into Force of the Regulation | 2024.12.10 | Framework clauses enter into force, compliance gap assessment can be initiated |
| Application of Conformity Assessment System | 2026.06.11 | Can contact notified bodies to understand certification requirements |
| Application of Vulnerability Reporting Obligation | 2026.09.11 | Two types of serious situations require 24/72-hour tiered reporting, covering all products on sale |
| Full Market Placement Compliance | 2027.12.11 | New products first placed in the EU after this date need full compliance |
| Security Support Period | From the date of first placement | In principle no less than 5 years, free security updates must be provided |
| Record Retention Period | Varies by data type | Technical documents for at least 10 years, vulnerability records for 2 years after the end of the support period |
List of Evidence Related to Compliance Timeline
If you want to achieve systematic compliance management, these time-related evidences must be properly retained, as they will be used during regulatory spot checks:
- Evidence of the time when the product is first placed on the EU market (such as sales records, customs declarations, first release announcements, etc.);
- Product version and material modification assessment records (including conformity assessment conclusions for each update);
- Software Bill of Materials (SBOM) and open source component usage records;
- Vulnerability response process and report records;
- Security support period statement and user notification records;
- EU declaration of conformity, technical documentation and conformity assessment records;
- Responsibility information of supply chain economic operators (contact information of manufacturers, importers, authorized representatives).
Action Priorities for Beginner Users
If you are new to the CRA, you can proceed according to the following priorities. After completing them, you will be able to independently judge core timeline issues:
First priority: First confirm whether your products and roles are under the jurisdiction of the CRA. If they are not within the scope, there is no need to waste effort;
Second priority: Compare with the core timeline milestones to clarify the obligations you need to fulfill and the corresponding time requirements;
Third priority: Back-calculate the preparation work according to the time, first build a vulnerability reporting mechanism (because the activation time is earlier), and then advance the preparation for market placement compliance.
Official Information Query Channels
If you want to check the most authoritative and latest information, you must go to official channels:
- Official Journal of the European Union (OJEU): You can check the final regulation text and official entry into force date;
- European Commission official website: Will release CRA implementation guidelines and policy updates;
- ENISA (European Union Agency for Cybersecurity): Responsible for the operation rules and platform construction related to vulnerability reporting.
Overall, although the CRA timeline has many milestones and detailed rules, the core logic is clear: obligations are implemented in phases, core milestones are unified, and special scenarios are determined based on “first placement + material modification”. Enterprises only need to first clarify their own product scope and role, and back-calculate the preparation rhythm against the official milestones, to effectively avoid compliance risks.