The two CRA dates that matter: 11 September 2026 and 11 December 2027
One date is a reporting duty on a 24-hour clock. The other is your license to keep selling in the EU. Here is what each means.
The CRA has a long transition, but only two dates change what you have to do. Confusing them is the most common planning mistake, because they demand completely different work.
11 September 2026: the reporting clock starts
From this date, if an actively exploited vulnerability or a severe incident hits a product you have on the EU market, you must report it on a fixed timeline: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days or one month depending on the trigger. You file through the ENISA Single Reporting Platform. This duty is event-driven. A single exploited flaw puts you 24 hours from a filing whether or not you have a fix, and whether or not it is a weekend.
You cannot prepare for this in the moment. You need a reporting process, named owners, and a platform registration set up in advance. Our reporting playbook covers exactly this.
11 December 2027: full compliance to sell
From this date, the full regulation applies. A product with digital elements needs a compliant technical file and Declaration of Conformity to carry the CE mark, and without the CE mark it cannot be sold in the EU. This is the deadline behind the phrase no file, no CE mark, no EU sales.
This work is not event-driven; it is a project. A first assessment usually surfaces gaps, such as a missing disclosure policy or an undocumented support period, that take months to close. Teams that start in 2026 are the ones not paying rush rates in 2027.
Read the dates in the right order. September 2026 comes first and needs a process. December 2027 needs a documented product. Different work, different owners, both on the calendar now.