Insights · cetome.com
The CRA deadline that matters is not December 2027
A reassuring story about the Cyber Resilience Act circulates among manufacturers. The September 2026 reporting obligation is a form to fill in, with national CSIRTs handling the coordination. The real work can wait until December 2027. And for most products, self-assessment against a relevant standard will make the CE mark a formality.
Each part of that story is wrong, and manufacturers who plan around it will find out at the worst possible time.
Reporting is a capability, not a form
Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report afterwards. This applies to products already on the market, not only to new ones.
Filling in the notification is the easy part. Before that, you have to know a vulnerability is being exploited, determine which products and versions are affected, assess the risk, decide on a course of action, and inform your users. Doing that in 24 hours requires a process, named people and product knowledge that is already organised. It cannot be improvised during an incident, and no authority will do it for you.
December 2027 is a finish line
From 11 December 2027, products placed on the market must comply. That is the date by which the work must be done, not the date to begin.
Consider how long things take in practice. A connected product takes 18 to 36 months from concept to launch, so anything reaching the market in early 2028 is being specified now, and its security requirements are being fixed or forgotten now. A new policy takes months to write, approve and adopt. A new process takes longer before it runs reliably. Demonstrating compliance takes time after all of that. Marketing commitments are often made before development starts.
Nothing in the regulation asks manufacturers to wait. Those who start in 2027 will be retrofitting security into finished designs, which is the slowest and most expensive way to do it.
Self-assessment is not a free pass
Most products fall in the default category and can follow self-assessment. That changes who checks the work, not how much work there is. The manufacturer still needs a risk assessment, evidence for every applicable essential requirement, complete technical documentation and a signed declaration of conformity, and carries full liability for it. Market surveillance authorities can ask for that file at any time.
Harmonised standards will help, but they are not an instruction to wait. The essential requirements in Annex I are already known, and a manufacturer can implement them today. A standard published late will confirm good work. It will not rescue work that was never started.
Three things to do first
- Run a gap analysis Establish what you already do well, what needs improvement and what could block you. Most manufacturers are further along than they fear in some areas and have nothing at all in others. Until you know which, you cannot plan.
- Put the risk assessment first Everything else depends on it, because it determines which essential requirements apply to each product and how. It does not need to be complicated. It needs to be repeatable, so that product teams can apply it consistently across the portfolio.
- Invest in vulnerability handling now Annex I Part II is where most manufacturers have the least in place. RED compliance does not cover it, and the UK PSTI regime covers only part of it. Build the policy and the process: intake, triage, risk evaluation, decision, remediation, and notification to customers and authorities. A structured SBOM is one input to that process, alongside threat intelligence and disclosure reports.
These three steps serve both deadlines. They make the reporting obligation manageable today, and they are the foundation of the compliance file due in 2027. Our five-objective framework shows where each of them sits in the wider programme.
Summary
| What manufacturers hear | What the CRA requires |
|---|---|
| Reporting is a form, and the CSIRT coordinates | Detection, impact analysis and decision within 24 hours, for products already on the market |
| The work starts in December 2027 | Products placed on the market from that date must already comply |
| Self-assessment is an easy pass | Full risk assessment, evidence and documentation, under the manufacturer’s sole liability |
| Wait for harmonised standards | Annex I requirements are known and can be implemented now |
To find out where you stand, check the category of your products with CRAscoping, see how we approach CRA readiness or talk to us.
About cetome
cetome is an independent product cyber security advisory, in London and Lyon since 2017. We help connected-product manufacturers ship secure products on time, in compliance with the Cyber Resilience Act, RED and other regulations, and we publish our research and tools for the community.
This article: https://cetome.com/insights/cra-deadline-that-matters/ · More insights: https://cetome.com/insights/ · Talk to us: https://cetome.com/contact/

