- Current Commission implementation page for the 11 September 2026 reporting start, staged notification deadlines, and Single Reporting Platform.
References and citations
- Supports the page framing that the CRA covers software and hardware products with digital elements, lifecycle vulnerability handling, CE marking, market surveillance, and staged application of reporting and main obligations.
"mandatory cybersecurity requirements for manufacturers"
- Supports implementation distinctions used in the checklist, including known exploitable vulnerabilities, secure-by-default expectations, support-period criteria, reporting triggers, conformity modules, CE marking, and declaration-of-conformity handling.
"The CRA does not require manufacturers to ensure that a product is free from all vulnerabilities."
- Supports the checklist items for CRA scope, Annex I essential cybersecurity requirements, Article 14 reporting clocks, technical documentation contents, conformity assessment, declaration retention, CE marking, and support-period obligations.