Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is a CRA readiness checklist before 11 December 2027?

Updated

A CRA readiness checklist groups Regulation (EU) 2024/2847 duties by area: scope, essential requirements, vulnerability handling, reporting, documentation, and conformity assessment, against Article 71 dates. Article 14 applies from 11 September 2026; full application is 11 December 2027. This page is not legal advice and does not start a clock.

CRA readiness checklist, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 1–3, 7–8, 13, 14, 16, 28, 30–32, 64, 69 and 71, Annexes I, II, III, IV, V, VII and VIII, the European Commission's CRA policy page (last updated 7 September 2026) and 27 July 2026 guidance (guidance, not the regulation), and ENISA product-security / Single Reporting Platform materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination that the CRA applies, not CE marking, not a product checklist UI, and not a substitute for counsel.

This is a readiness checklist, not YOUR determination

Audience: a CTO, founder, product, or compliance lead at an organisation that might make products with digital elements available on the Union market. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Checking a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that a reporting clock has started, that essential requirements are met, or that a conformity-assessment route is complete.

The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. It is a regulation, directly applicable. A checked box on this page is not CRA conformity, not CE marking, and not a market-surveillance determination. Last verified 9 September 2026. Not legal advice.

  • Statute versus guidance: Articles 1–3, 7–8, 13, 14, 16, 28, 30–32, 64, 69 and 71, and Annexes I–V, VII and VIII, are legal requirements only if they apply. Commission CRA pages and the 27 July 2026 Commission guidance are Commission materials — guidance, not the regulation. ENISA product-security and Single Reporting Platform materials are agency guidance, not the regulation. This page quotes which kind of text it is relying on.
  • The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is the cluster reporting page. The statute-clock Article 14 guide on this site is the ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page.
  • The evidence-retention guide on this site is the technical-documentation keep page. A dedicated products-in-scope, vulnerability-management, security-updates, penalties, and how-ShipReadyMetrics-supports-CRA guide is not on this site yet. Naming them is not a link.
  • This page is not a product checklist UI. The signed-in app does not present this table as a click-to-complete CRA readiness board.

Master checklist by obligation area — not a determination

The table groups CRA duties the regulation states, by area. It is an aid for tracking work with counsel. It is not YOUR file, not a finding that any row applies, and not a product checklist UI. Checking a row here does not mean the organisation is CRA-conformant. Last verified 9 September 2026. Not legal advice.

Master CRA readiness checklist grouped by obligation area (not a determination; not legal advice; not a product checklist UI)
AreaItemKind of textWhat this page / product does not do
ScopeWhether a product with digital elements is made available on the Union market, with a direct or indirect logical or physical data connection to a device or network — Articles 2 and 3(1), 3(21) and 3(22).Legal requirement — Articles 2 and 3. Only if the CRA applies.Does not run that test for YOU. Marking cra in-scope on the obligation map is not that determination.
ScopeWhether YOU are a manufacturer, authorised representative, importer, distributor, or open-source software steward — Articles 3(13)–(17), 13, 18–21 and 24.Legal requirement — Chapter II. Only if the role applies.Does not classify YOUR role. The who-is-covered guide on this site is the economic-operator roles page.
ScopeWhether a cloud path is remote data processing of a product (Article 3(2)) or a service outside the CRA. Recital 12 discusses cloud services designed and developed outside the manufacturer's responsibility and points to NIS2 for in-scope cloud computing services.Article 3(2) is a legal requirement. Recital 12 is a recital, not an operative article. Commission 27 July 2026 guidance on remote data processing is guidance, not the regulation.Does not decide that standalone browser-only SaaS is in or out. The SaaS-scope guide on this site is the remote-processing versus service page. A dedicated products-in-scope guide is not on this site yet. Naming it is not a link.
Essential requirementsArticle 13(1): when placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I. Annex I Part I: products shall be designed, developed and produced so they ensure an appropriate level of cybersecurity based on the risks.Legal requirement — Article 13(1) and Annex I Part I. Applies from 11 December 2027 (Article 71(2), first subparagraph).Does not find that YOUR product meets Annex I Part I. Readiness tracking in this product is not CE marking.
Essential requirementsArticle 13 also covers a cybersecurity risk assessment that informs the essential requirements, due diligence so third-party components do not compromise the product, and taking that assessment into account during planning, design, development, production, delivery and maintenance.Legal requirement — Article 13. Only if the manufacturer duty applies.Does not perform YOUR risk assessment. The CRA starter control-set is an illustrative readiness mapping, not that assessment.
Vulnerability handlingArticle 13(8) and Annex I Part II: vulnerability handling for the support period, including handling vulnerabilities without delay and providing security updates. Annex I Part II also covers a component inventory (SBOM), a coordinated vulnerability disclosure policy, and a contact address for reporters.Legal requirement — Article 13(8) and Annex I Part II. Applies from 11 December 2027 (Article 71(2), first subparagraph). Distinct from Article 14, which applies from 11 September 2026.Does not run YOUR vulnerability-handling process. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. A dedicated vulnerability-management and security-updates guide is not on this site yet. Naming them is not a link.
Vulnerability handlingENISA product-security pages, Technical Advisories, and SBOM materials describe secure-by-design practice and CRA implementation support.Agency guidance, not the regulation.Does not treat an ENISA playbook as Annex I. Does not treat this product's findings intake as YOUR public reporter mailbox.
Reporting readinessArticle 14: 24-hour early warning, 72-hour notification, and 14-day final report on the actively-exploited track, to the CSIRT designated as coordinator and to ENISA via the single reporting platform. Severe-incident final report within one month. Article 14 applies from 11 September 2026 (Article 71(2)). Article 69(3) applies those duties to in-scope products placed on the market before 11 December 2027.Legal requirement — Articles 14, 69(3) and 71(2). Only if the CRA applies. This page does not start that clock.Does not start an Article 14 clock and does not file with a CSIRT or ENISA. The statute-clock Article 14 guide on this site is the ladder. The CRA-cluster Article 14 overview on this site is the cluster page. Those two pages agree on the marks.
Reporting readinessArticle 16: ENISA establishes and maintains the single reporting platform. ENISA SRP pages and the FAQ updated 8 September 2026 describe Assigned Representatives, EU Login, and the intended portal.Article 16 is a legal requirement. ENISA SRP pages are agency guidance, not the regulation.Does not submit on the platform. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. A dedicated 24-hour early-warning, 72-hour notification, final-report, and actively-exploited guide is not on this site yet. Naming them is not a link.
DocumentationArticle 31 and Annex VII: technical documentation drawn up before placing on the market and kept at the disposal of market surveillance authorities. Article 13(12) and Article 28: EU declaration of conformity. Annex II: information and instructions to the user, including the support-period end date and where the CVD policy can be found.Legal requirement — Articles 13(12), 28 and 31; Annexes II, V and VII. Applies from 11 December 2027 except where Article 14 already applies.Does not keep YOUR technical documentation file. Hosting a policy in the signed-in library is not Annex II user information. The evidence-retention guide on this site is the keep-period page.
Conformity assessment routeArticle 32 and Annex VIII: default products may use internal control (module A), EU-type examination, full quality assurance, or, where available and applicable, a European cybersecurity certification scheme. Important class I (Annex III) tightens the path when harmonised standards, common specifications, or a certification scheme at assurance level at least 'substantial' have not been applied. Important class II (Annex III) uses EU-type examination, full quality assurance, or such a scheme. Critical products (Annex IV) use a European cybersecurity certification scheme in accordance with Article 8(1), or the class II procedures where those conditions are not met.Legal requirement — Articles 7–8, 32 and Annexes III, IV and VIII. Only if the CRA applies. Commission Implementing Regulation (EU) 2025/2392 specifies technical descriptions of important and critical categories — an implementing act, not this checklist.Does not classify YOUR product and does not pick YOUR conformity-assessment module. A dedicated products-in-scope guide is not on this site yet. Naming it is not a link. This product does not affix a CE mark and is not a notified body.
Conformity assessment routeArticle 30: the CE marking shall be affixed before the product with digital elements is placed on the market. Article 28(4): by drawing up the EU declaration of conformity, the manufacturer assumes responsibility for compliance of the product.Legal requirement — Articles 28 and 30. Applies from 11 December 2027 (Article 71(2), first subparagraph).Readiness in this product is not CE marking, not an EU declaration of conformity, and not a market-surveillance determination.

Phased timeline — Article 71, not YOUR dates

Last verified 9 September 2026 against Article 71 on EUR-Lex. Article 71(1): this Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. Publication was 20 November 2024, so entry into force is 10 December 2024. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Those four dates are not one number. This page does not move them.

Article 69(3): by way of derogation from Article 69(2), the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027. Article 14 reporting is not delayed until full application in December 2027.

As of last verification on 9 September 2026, Article 14's application date is in two days (11 September 2026). Chapter IV notifying-bodies provisions have applied since 11 June 2026. Full essential-requirements / CE / market-surveillance application remains 11 December 2027. This table is not YOUR dates. Not legal advice.

Article 71 application dates as the regulation states them (not YOUR dates; not a determination; not legal advice)
Date in the regulationWhat appliesKind of textLast verified
10 December 2024Entry into force — twentieth day following publication in the Official Journal (OJ L 2024/2847, 20.11.2024).Article 71(1). Legal requirement.9 September 2026
11 June 2026Chapter IV — notification of conformity assessment bodies (Articles 35 to 51).Article 71(2), second subparagraph. Not the Article 14 reporting ladder.9 September 2026
11 September 2026Article 14 reporting obligations of manufacturers.Article 71(2), second subparagraph. Legal requirement. This page does not start that clock.9 September 2026
11 December 2027The rest of the Regulation, including essential cybersecurity requirements, CE marking, and market surveillance.Article 71(2), first subparagraph.9 September 2026

Must-do (law) versus should-do (guidance)

Do not treat guidance as the article, and do not treat the article as optional because a FAQ exists. Last verified 9 September 2026. Not legal advice.

Statute versus guidance (not a ranking; not legal advice; last verified 9 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/2847 Articles 1–3, 7–8, 13, 14, 16, 28, 30–32, 64, 69, 71 and Annexes I–V, VII and VIIILegal requirement — the regulation, only if it applies.Does not apply those articles to YOU. Checking a row is not conformity.
European Commission CRA policy page (updated 7 September 2026) and CRA summary pageCommission materials. Guidance, not the regulation.Does not treat a Commission summary as a substitute for Article 71.
Commission guidance of 27 July 2026 (C(2026) 5252) on CRA applicationCommission guidance, not the regulation. The Commission page itself calls it non-binding. It addresses remote data processing, substantial modification, support periods, and reporting.Does not treat that guidance as rewriting 11 September 2026 or 11 December 2027.
ENISA product-security pages and Single Reporting Platform materialsAgency guidance on product security and the Article 16 platform. Not the regulation.Does not treat an ENISA FAQ as starting YOUR clock or completing readiness.

What to do now

As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. Full essential-requirements application remains 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.

  • Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. Marking CRA in an obligation map is not that determination.
  • Ask counsel which class, if any, YOUR product has under Annex III or Annex IV, and which Article 32 route follows. This page does not classify it. A dedicated products-in-scope guide is not on this site yet. Naming it is not a link.
  • If counsel says Article 14 may apply, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder, or the CRA-cluster Article 14 overview. This checklist does not start that clock. A named human still submits via the single reporting platform.
  • If counsel says Annex I Part II may apply, walk the coordinated-vulnerability-disclosure guide on this site for the CVD policy and contact address. A dedicated vulnerability-management and security-updates guide is not on this site yet. Naming them is not a link.
  • Do not treat Commission or ENISA guidance as the regulation. Do not treat this product's CRA control-set as a conformity-assessment file. Do not treat a checked box on this page as CRA conformity.
  • Document the assessment, including a not-in-scope decision. This page does not keep YOUR file. The evidence-retention guide on this site is the keep-period page. A dedicated how-ShipReadyMetrics-supports-CRA guide is not on this site yet. Naming it is not a link.

Where this shows up in ShipReady Metrics

The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative readiness mapping, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not compliance, not CE marking, and not a market-surveillance determination. A CRA-to-canonical-control crosswalk exists in the signed-in compliance layer. That crosswalk is an illustrative mapping, not a determination, not a count of CRA-conformant controls, and not CE marking.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.

The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. Marking cra in-scope is not a determination that you are a manufacturer or that a product with digital elements has been made available on the Union market, and it does not complete readiness. The cyber risk register lives under Security. It is not an Article 14 file. This page is not a product checklist UI; checking a row here does not tick a control in the app.

A dedicated how-ShipReadyMetrics-supports-CRA guide is not on this site yet. Naming it is not a link. This page does not document a public demo URL. There is no public CRA demo path.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 1–3, 7–8, 13, 14, 16, 28, 30–32, 64, 69 and 71 and Annexes I, II, III, IV, V, VII and VIII, is a legal requirement only if it applies. Entry into force 10 December 2024 (Article 71(1)). Article 14 applies from 11 September 2026; Chapter IV from 11 June 2026; the rest from 11 December 2027 (Article 71(2)). The European Commission's CRA policy page (updated 7 September 2026), CRA summary page, and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. ENISA's product-security pages and Single Reporting Platform materials are agency guidance, not the regulation. Directive (EU) 2022/2555 Article 23 is a different instrument; the NIS2 incident-reporting guide is on this site. Regulation (EU) 2022/2554 Articles 18–19 are a different instrument; the DORA incident-reporting guide is on this site. These are not a complete world list. Not legal advice.

The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The coordinated-vulnerability-disclosure guide on this site is the Annex I Part II CVD page. The evidence-retention guide on this site is the technical-documentation keep page. A dedicated products-in-scope, vulnerability-management, security-updates, penalties, and how-ShipReadyMetrics-supports-CRA guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a readiness checklist distilled from Regulation (EU) 2024/2847, with Commission and ENISA materials labelled as guidance, not the regulation. Whether the CRA applies to YOUR product, which class it has, and whether a reporting clock has started are legal questions for counsel on your facts. This page does not start a clock.

Does a checked box here mean we are CRA-conformant?

No. Checking a row on this page is not CRA conformity, not CE marking, not an EU declaration of conformity, and not a market-surveillance determination. This page is not a product checklist UI. Counsel applies the regulation to YOUR facts. Last verified 9 September 2026.

Does ShipReady file Article 14 reports?

No. The signed-in app does not file with a CSIRT or ENISA, does not start an Article 14 clock, and does not decide that the CRA applies or that you are a manufacturer. Compliance → CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. A named human still submits.

Does marking cra in-scope complete readiness?

No. Marking the bundled framework key cra in-scope on the obligation map is not a determination that you are a manufacturer, that a product with digital elements has been made available on the Union market, or that readiness is complete. The control-set is a starter subset, illustrative readiness mapping, not conformity assessment. Counsel applies Articles 2 and 3 to YOUR facts.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.