Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
New rule set
New rule set
Label (English)
Label (German)
Effective from
Effective until
Country scope
Position
Applies from milestone
The Regulation enters into force on the twentieth day following its publication in the Official Journal of 20 November 2024. Entry into force does not yet create obligations for companies; the application dates govern.
Deadline for the Commission to adopt the implementing act describing the important and critical product categories in technical terms.
Deadline for the delegated act in which the Commission lays down the terms and conditions for applying the cybersecurity grounds for delaying the dissemination of a notification under Article 16(2). The act was adopted as Delegated Regulation (EU) 2026/881 and has been in force since 10 May 2026.
Start of application of Chapter IV on the notification of conformity assessment bodies, so that notified bodies can be designated in time.
Early start of application of the manufacturer's reporting obligations for actively exploited vulnerabilities and severe incidents, more than a year before the general start of application.
Deadline for Member States to ensure a sufficient number of notified bodies.
General start of application: from this date the product requirements, conformity assessment, CE marking and the obligations of importers and distributors apply.
Grandfathering: products placed on the market before this date are subject to the requirements only if they are substantially modified thereafter; the Article 14 reporting obligations apply to them regardless.
EU type-examination certificates and approvals issued under other Union harmonisation legislation for cybersecurity requirements cease to be valid on this date at the latest.
Deadline for the Commission report on the reporting obligations and the single reporting platform.
First evaluation and review of the Regulation by the Commission, and every four years thereafter.
Expires at milestone
The Regulation enters into force on the twentieth day following its publication in the Official Journal of 20 November 2024. Entry into force does not yet create obligations for companies; the application dates govern.
Deadline for the Commission to adopt the implementing act describing the important and critical product categories in technical terms.
Deadline for the delegated act in which the Commission lays down the terms and conditions for applying the cybersecurity grounds for delaying the dissemination of a notification under Article 16(2). The act was adopted as Delegated Regulation (EU) 2026/881 and has been in force since 10 May 2026.
Start of application of Chapter IV on the notification of conformity assessment bodies, so that notified bodies can be designated in time.
Early start of application of the manufacturer's reporting obligations for actively exploited vulnerabilities and severe incidents, more than a year before the general start of application.
Deadline for Member States to ensure a sufficient number of notified bodies.
General start of application: from this date the product requirements, conformity assessment, CE marking and the obligations of importers and distributors apply.
Grandfathering: products placed on the market before this date are subject to the requirements only if they are substantially modified thereafter; the Article 14 reporting obligations apply to them regardless.
EU type-examination certificates and approvals issued under other Union harmonisation legislation for cybersecurity requirements cease to be valid on this date at the latest.
Deadline for the Commission report on the reporting obligations and the single reporting platform.
First evaluation and review of the Regulation by the Commission, and every four years thereafter.
Withdrawn at
Cancel