Enforcement Roadmap // Statutory Milestones

CRA Regulatory Enforcement Timeline

A definitive operational roadmap of statutory deadlines, multi-regulation collisions, and incident reporting countdowns under Regulation (EU) 2024/2847. Explore the 4 specialized timeline tracks below.

Baseline Law
Dec 10, 2024
Entry into Force
✓ Passed (In Force)
Article 14 Gate
Sep 11, 2026
ENISA 24h Early Warning
● Active Law Today
Machinery Collision
Jan 20, 2027
Reg (EU) 2023/1230 OT Safety
⚡ T-4 Months Ahead of CRA
Full Enforcement
Dec 11, 2027
100% PDE CE Mark Required
⏳ T-15 Months Remaining
Interactive Studio

Four Specialized Statutory Timeline Tracks

Select a timeline view below to analyze multi-year statutory trajectories, the fast 24h/72h incident response clock, the industrial machinery regulatory collision, or grandfathering rules for existing products.

36-Month Macro Regulatory & Harmonisation Calendar (2024–2027)

Statutory progression from initial Official Journal publication to mandatory European market surveillance.

Regulation (EU) 2024/2847
MILESTONE 01
Dec 10, 2024
Entry into Force

CRA published in OJEU. Standardisation request issued to CEN/CENELEC/ETSI for harmonised European standards.

MILESTONE 02
Jun 11, 2026
NANDO CAB Guidelines

Member states notify designation criteria for Conformity Assessment Bodies (CABs) under Articles 39–45.

MILESTONE 03 // ACTIVE
Sep 11, 2026
Article 14 Early Warning

ENISA Single Reporting Platform goes live. Mandatory 24h exploit notice & 72h technical dossiers become legally binding.

MILESTONE 04 // COLLISION
Jan 20, 2027
Machinery Cyber Mandate

Regulation (EU) 2023/1230 forces industrial machinery to withstand cyber corruption 11 months before full CRA.

MILESTONE 05 // CE MARK
Dec 11, 2027
Full CRA Application

100% of PDE on EU market must conform to Annex I, hold 10-yr technical file, CycloneDX SBOM, and bear CE marking.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
Interactive Statutory Milestones

Operational Action Plans & Technical Dossiers

Click any card to flip between strategic overview and mandatory engineering deliverables with statutory penalties.

Tip: Click card to flip 3D dossier
ACTIVE LAW TODAYSeptember 11, 2026
Flip

Article 14 ENISA SRP 24h Early Warning Mandate

Regulation (EU) 2024/2847, Article 14(1) & (2)

Statutory mandatory 24-hour early warning notice to the ENISA Single Reporting Platform and national CSIRTs upon becoming aware of any actively exploited vulnerability or severe incident affecting Products with Digital Elements.

✓ 24h Early Warning Notice to ENISA & national CSIRT✓ 72h Technical Incident Dossier with CVSS & telemetry✓ 14-Day Final Corrective Action & patch completion report
ACTIVE TODAYInspect Deliverables
Statutory Deliverables & Enforcement

Article 14 ENISA SRP 24h Early Warning Mandate

Mandatory Operational Actions:
  • •Obtain and test authentication credentials for the ENISA Single Reporting Platform (SRP)
  • •Establish 24/7 internal incident response triage team for rapid escalation
  • •Pre-authorize Article 14 communication templates with legal and product engineering teams
  • •Appoint official EU Authorised Representative (Article 11) for non-EU manufacturers
Statutory Penalty:
Administrative fines up to €10,000,000 or 2.0% of total annual worldwide turnover for Article 14 non-compliance.
Read Article 14 Incident Playbook
UPCOMING COLLISIONJanuary 20, 2027
Flip

Machinery Regulation Cyber Mandate Enforcement

Regulation (EU) 2023/1230, Annex III § 1.1.9

Horizontal machinery safety regulation requiring all industrial machines with digital interfaces to be resilient against cyber corruption 11 months ahead of full CRA application. Unprotected network interfaces violate essential health and safety requirements.

✓ Hardware/software connection controls preventing physical hazard corruption✓ Validation of safety control circuits against network spoofing and MITM attacks✓ Harmonized alignment with IEC 62443 and EN ISO 13849 safety functions
T-4 MONTHSInspect Deliverables
Statutory Deliverables & Enforcement

Machinery Regulation Cyber Mandate Enforcement

Mandatory Operational Actions:
  • •Audit industrial Ethernet, Fieldbus, and wireless communication channels against unauthorized access
  • •Validate safety control loops (E-stops, limiters) cannot be altered via network ports
  • •Compile machinery technical files incorporating empirical cybersecurity risk assessments
  • •Bridge OT plant automation engineers with corporate IT security teams
Statutory Penalty:
Market surveillance stop-sale orders, mandatory EU-wide product recalls, and customs seizure at EU borders.
Read Industrial OT & Machinery Guide
STATUTORY DEADLINEDecember 11, 2027
Flip

Full CRA Application & CE Marking Enforcement

Regulation (EU) 2024/2847, Articles 10, 13, 24 & Annex I

100% of Products with Digital Elements placed on the EU Single Market must fully conform to Annex I, hold an Annex VII technical dossier, provide continuous CycloneDX/SPDX SBOMs, and bear the CE mark.

✓ Mandatory CE Mark affixed to hardware and digital PDE✓ Continuous machine-readable CycloneDX / SPDX SBOM generation✓ 10-Year technical file archival repository requirement✓ Third-party Notified Body certification for Class I & Class II PDE
T-15 MONTHSInspect Deliverables
Statutory Deliverables & Enforcement

Full CRA Application & CE Marking Enforcement

Mandatory Operational Actions:
  • •Sign formal EU Declaration of Conformity (EU DoC) under internal Module A control or CAB certificate
  • •Complete third-party Notified Body conformity audits for Important Class I & Class II PDE
  • •Deploy statutory Coordinated Vulnerability Disclosure (CVD) and security.txt
  • •Implement automated, free-of-charge security patches for expected product lifetime
Statutory Penalty:
Total prohibition from commercial distribution across all 27 EU member states plus fines up to €15M or 2.5% of turnover.
View Annex I Requirements
LEGISLATIVE BASELINEDecember 10, 2024
Flip

Entry into Force of the Cyber Resilience Act

Regulation (EU) 2024/2847, Article 71

Official legislative enactment following publication in the Official Journal of the European Union (OJEU), commencing the 21-month transition period for Article 14 and 36-month transition for full Annex I conformity.

✓ Publication in EU Official Journal (L series)✓ Standardisation request issued to CEN/CENELEC/ETSI✓ Commencement of statutory transitional countdowns
PASSEDInspect Deliverables
Statutory Deliverables & Enforcement

Entry into Force of the Cyber Resilience Act

Mandatory Operational Actions:
  • •Establish cross-functional CRA compliance steering committee
  • •Inventory all product hardware, firmware, and software architectures under PDE definition
Statutory Penalty:
Legislative baseline established across all 27 EU member states.
Statutory Sanction Matrix (Articles 52–54)

Administrative Fines & Market Surveillance Authority Powers

National market surveillance authorities in all 27 EU member states possess binding powers to impose turnover-based financial penalties, issue market withdrawal orders, and initiate customs border blocks.

Violation CategoryStatutory BasisMaximum Financial FineOperational / Market Sanction
Non-compliance with Annex I Essential RequirementsArticle 53(1)Up to €15,000,000 or 2.5% of total annual global turnoverImmediate ban on placement on the EU market; mandatory product recall across 27 member states.
Failure to comply with Article 14 Incident ReportingArticle 53(2)Up to €10,000,000 or 2.0% of total annual global turnoverFormal notice of non-compliance; referral to national CSIRTs and judicial authorities.
Supply of misleading information to Notified BodiesArticle 53(3)Up to €5,000,000 or 1.0% of total annual global turnoverRevocation of EU-Type Examination Certificate; revocation of Module H approval.
Preparation Playbook

Quarterly Engineering & Regulatory Readiness Roadmap

Recommended operational cadence for engineering leaders, product security directors, and legal compliance officers.

Q3–Q4 2025
Foundation Phase
  • • Conduct complete product inventory under PDE scope
  • • Deploy automated CycloneDX / SPDX SBOM tooling in CI/CD
  • • Publish RFC 9116 security.txt on domain
Q1–Q2 2026
Triage Drill Phase
  • • Register credentials with ENISA Single Reporting Platform
  • • Conduct 24h mock incident escalation simulation
  • • Appoint EU Authorised Representative (Article 11)
Q3–Q4 2026
Article 14 Live
  • • September 11: Article 14 24h early warning mandatory
  • • Begin Machinery Regulation cyber audit for industrial PDE
  • • Select accredited Notified Body for Class I/II PDE
2027 Full Enforcement
CE Mark Affixation
  • • January 20: Machinery Regulation cyber mandate live
  • • Finalize Annex VII technical file archival system
  • • December 11: Sign EU DoC and affix CE mark

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.