Skip to content

Cyber Resilience Act: Vulnerability and incident reporting obligations apply

Tech · Compliance deadlines · Fri, September 11, 2026 · European Union

Source

Art 14: manufacturers must report actively exploited vulnerabilities and severe incidents (24-hour early warning, 72-hour notification) via the single reporting platform. Also covers products placed on the market before Not legal advice.

Every year

DateEventWhen
Dec 10, 2024Cyber Resilience Act: CRA enters into force2 yr ago
Jun 11, 2026Cyber Resilience Act: Conformity assessment body provisions apply3 mo ago
Sep 11, 2026Cyber Resilience Act: Vulnerability and incident reporting obligations apply14 days ago
Dec 11, 2027Cyber Resilience Act: CRA fully appliesin 15 mo
Jun 11, 2028Cyber Resilience Act: Legacy type-examination certificates expirein 2 yr
Sep 11, 2028Cyber Resilience Act: Report on single reporting platformin 2 yr
Dec 11, 2030Cyber Resilience Act: First CRA evaluationin 4 yr

Also on Sep 11, 2026

DateEventWhen
Sep 11, 20262026 Solheim Cup14 days ago
Sep 11, 20262026 World Athletics Ultimate Championship14 days ago
Sep 11, 2026NFL Melbourne game 2026: 49ers vs Rams14 days ago
Sep 11, 2026250th anniversary: British and American leaders held a peace conference on Staten Island, New...14 days ago
Sep 11, 2026CPI release for August 202614 days ago
Sep 11, 2026South Korea PIPA: 2026 PIPA amendments take effect14 days ago
Source, method and history
Source
Regulations
How we know
From the Regulations API (regulations.fru.dev), which cites the official text.
Recurs
one-off
More on fru.dev
regulations.fru.dev
Feed
Subscribe to Compliance deadlines
Changes
  • 2026-09-25: added to 2026-09-11

Calendar by email

Sunday mornings: a look ahead at the week’s major dates, only when there are some.

Double opt-in. Unsubscribe any time.