For most manufacturers, Cyber Resilience Act compliance takes 12 to 24 months from a standing start. The range is wide because the CRA does not ask you to file a document by a date. It asks you to change how you build, ship, and support a product, and then prove it. Firms that already run a secure development lifecycle and a working vulnerability disclosure process land near the 12 month end. Firms starting from an undocumented build pipeline, with a portfolio they have never formally classified, should plan for 24 months or more.
The date that should drive your plan is not 11 December 2027, when the CRA applies in full. It is 11 September 2026, when the Article 14 reporting duties start, because those duties apply to products already on the market and cannot be met by a project that is still in its scoping phase.
| Phase | Typical duration | What gates it |
|---|---|---|
| Scope and classify | 4 to 8 weeks | Knowing every product with digital elements you place on the EU market, and which Annex III class each falls into. |
| Annex I gap assessment | 6 to 12 weeks | Access to the people who actually know the build. Gaps in Part II vulnerability handling are usually wider than Part I. |
| Secure development and vulnerability handling | 6 to 12 months | Engineering capacity. This is the phase that determines whether you land at 12 or 24 months. |
| Technical documentation | 2 to 4 months | It runs partly in parallel, but cannot finish before the build changes do. |
| Conformity assessment and CE marking | 1 to 6 months | Product class. Self assessment closes fast, a notified body queue does not. |
How long does Cyber Resilience Act compliance take?
Twelve to twenty four months is the honest planning range, and the distribution inside it is not even. The scoping, documentation and assessment phases are fairly predictable. The engineering phase is not, and it dominates the total.
A useful way to estimate your own position is to ask what you would have to build if a regulator asked for it tomorrow. If you can produce a software bill of materials for a shipped product, name the person who triages inbound vulnerability reports, and show the security tests that ran on the last release, you are closer to 12 months than 24. If any of those three is a shrug, the engineering phase is where your time will go.
What decides whether it takes 12 months or 24?
Four things, in descending order of impact.
1. Whether a secure development lifecycle already exists
Annex I Part I asks for products delivered without known exploitable vulnerabilities, with a secure by default configuration, and with security update capability. Annex I Part II asks for vulnerability handling: an SBOM, coordinated disclosure, and timely security updates. Part II is where most manufacturers discover the real work. Producing an SBOM once for an audit is a week of effort. Producing one automatically for every release, and keeping it accurate, is a pipeline change.
2. Product classification
Default products self assess. Annex III important products can use harmonised standards or a third party. Class II important products need a third party. Annex IV critical products may require a European cybersecurity certification scheme. Each step up adds both cost and calendar time, and the calendar time is the part people underestimate, because notified body capacity is finite and the queue lengthens as 2027 approaches.
3. Portfolio size and shared components
Compliance effort does not scale linearly with product count. Ten products on one shared platform is closer to one programme than to ten. Ten products on ten stacks acquired over a decade is genuinely ten programmes. Map the shared components early, because that map is what tells you whether your number is 12 or 24 months.
4. What you already did for other regulations
If you have been through NIS2 or hold ISO 27001, some of the CRA is already paid for. Secure development, asset inventory and incident processes overlap. The CRA specific parts, which are the product level essential requirements, the SBOM, the CE marking and the technical file, do not.
Which deadline should you actually plan against?
Plan against 11 September 2026. That is when Article 14 reporting starts: actively exploited vulnerabilities and severe incidents must be reported, with an early warning inside 24 hours and a fuller notification inside 72 hours. Those duties attach to products you have already placed on the market, so there is no grace period earned by shipping early.
Full application follows on 11 December 2027, covering the essential requirements, conformity assessment, CE marking and the EU declaration of conformity. A separate milestone on 11 June 2026 lets Member States designate the conformity assessment bodies, which matters mainly because it is the point from which notified body capacity starts to exist at all. The full set is laid out in our guide to Cyber Resilience Act deadlines for 2026 and 2027.
Counted from today, 11 September 2026 is close. If your reporting process is not already designed, that is the piece to pull forward ahead of everything else, because it is the one obligation that can be breached before your product work is finished.
What the other results get wrong
Three things recur in the published guidance.
The first is quoting a single number. Articles that say CRA compliance takes six months, or eighteen, are describing one company's portfolio without saying so. The classification of your products changes the answer by a factor of four on the assessment phase alone.
The second is treating 11 December 2027 as the deadline. It is the final one, not the first. Planning backwards from 2027 puts the reporting obligation, which lands over a year earlier, in the wrong place in the schedule.
The third is presenting the work as a documentation exercise. The technical file is an output. What takes the time is the engineering change that makes the file true, and no amount of template downloading shortens it.
What can you do in the next 30 days?
Fill this in for your own portfolio. If you cannot complete a row, that row is your first project.
| Question | Your answer | Why it matters |
|---|---|---|
| How many products with digital elements do you place on the EU market? | Without a count there is no scope, and without scope every estimate is a guess. | |
| How many are Annex III important or Annex IV critical? | This sets your conformity route and most of your assessment calendar. | |
| Can you produce an SBOM for your last release? | Annex I Part II. If the answer is no, this is your longest phase. | |
| Who triages an inbound vulnerability report today? | Article 14 needs a named owner and a clock, not an inbox. | |
| Could you file a 24 hour early warning tomorrow? | The obligation starts 11 September 2026 for products already on the market. |
If you want a baseline before committing to a plan, run a free compliance check. It will not size the engineering work, but it will tell you which of the five rows above you are going to struggle with.
Frequently asked questions
Can we be ready by 11 September 2026?
For the reporting duties, yes, in most cases. Designing a reporting process, naming an owner and rehearsing a 24 hour early warning is weeks of work, not months. Being ready for the full essential requirements by then is a different question, and for most manufacturers the answer is no. That is what the extra 15 months to December 2027 are for.
Does the CRA apply to software sold on its own?
Yes. Products with digital elements include software placed on the market independently of hardware. Scope follows the product, not the sector, which our guide to who must comply with the Cyber Resilience Act covers in detail.
Does open source shorten or lengthen the timeline?
Both. Free and open source software supplied outside a commercial activity sits largely outside the operator duties, but if you integrate open source components into a product you place on the market, they are inside your SBOM and your vulnerability handling. Component inventory work usually lengthens the gap assessment phase.
Do we need a notified body?
Only for Annex III important class II products, for critical products under Annex IV, and for important class I products where you do not apply harmonised standards in full. Default products self assess. Check classification early, because this single answer moves the end date by months.
What if we miss a deadline?
Article 64 sets the ceilings, and the top tier covers exactly the Annex I requirements and the Article 13 and 14 duties discussed above. The detail is in our guide to Cyber Resilience Act fines and penalties.
Primary sources
Dates and obligations above are drawn from Regulation (EU) 2024/2847 (Articles 13, 14 and 71, and Annexes I, III and IV) and the European Commission's Cyber Resilience Act policy pages. Durations are planning estimates from implementation work, not figures from the Regulation. Confirm the current text before relying on a specific date.





