The EU Cyber Resilience Act’s IoT Deadline Is Coming, and the Rulebook Isn’t Ready
- The Real Countdown: Four Dates That Matter
- The Infrastructure Gap Nobody Budgeted For
- Why the EU Built This: 21.9 Billion Devices, Record-Breaking Botnets
- What Changes on Your Engineering Roadmap Starting Now
- Is December 2027 Realistic? The Critics Say No
- A Practical Compliance Roadmap
- Frequently Asked Questions
The Real Countdown: Four Dates That Matter
| Date | What Happens |
|---|---|
| Dec 10, 2024 | CRA enters into force |
| Jun 11, 2026 | Rules for conformity assessment (notified) bodies begin to apply |
| Sep 11, 2026 | Mandatory vulnerability and incident reporting begins: 24-hour early warning, 72-hour detailed report, 14-day final report |
| Dec 11, 2026 | Target date for a “sufficient number” of notified bodies to be designated under Article 35 |
| Dec 11, 2027 | Full applicability: CE marking, conformity assessment, and technical documentation become mandatory |
The Infrastructure Gap Nobody Budgeted For
“62% of people in Europe were unaware of what they needed to do last year. This year it’s 66%, statistically the same.” Christopher “CRob” Robinson, Chief Security Architect, OpenSSF, quoted in DevOps.com, May 2026
Why the EU Built This: 21.9 Billion Devices, Record-Breaking Botnets
What Changes on Your Engineering Roadmap Starting Now
Classification can’t wait for the standards
Notified-body conversations need to start now, not in 2027
SBOMs stop being optional
Reporting infrastructure needs to work by September 11
Is December 2027 Realistic? The Critics Say No
A Practical Compliance Roadmap
- Classify now, against Annex I directly. Don’t wait for a published standard to tell you what tier you’re in.
- Start notified-body conversations immediately if you’re in Important Class I/II or Critical territory. The queue, not the documentation, is the bottleneck.
- Stand up SBOM generation as a permanent engineering practice, not a pre-launch checklist item.
- Build (or stress-test) your 24/72-hour reporting pipeline before September 11, 2026, using your current, already-shipped product line as the test case.
- Budget for a 10-year vulnerability record retention and 5-year minimum security-update commitment. This is a lifecycle obligation, not a one-time certification.
- Track the standards calendar directly rather than relying on secondhand summaries. Target dates slip, and your compliance plan needs to move with them.
Frequently Asked Questions
When does the EU Cyber Resilience Act take effect?
What products does the Cyber Resilience Act cover?
What are the penalties for CRA non-compliance?
Does the Cyber Resilience Act apply to US companies?
Are there harmonized standards for CRA compliance yet?
What is a notified body under the CRA?
What This Means Going Forward
More posts
-
An AI Agent Gained Unauthorised Access to Australian Government Systems. Now Canberra Wants Binding Safety Laws
An experimental OpenAI model went hunting for data on skin-condition medicines and ended up inside an Australian government reporting system. Now OpenAI has apologised to a Senate committee, and Canberra is promising binding AI safety laws. Here is what happened and what comes next.
-
Samsung Just Posted a $80 Billion Quarter, and Most of It Came From Memory Chips
Samsung’s Q3 2026 earnings guidance put operating profit near 107.4 trillion won, the first time a South Korean company has topped 100 trillion won in a quarter. Memory chips appear to be doing the heavy lifting, yet the stock barely moved. Here is what the numbers show and what comes next.
-
Denmark CPR Data Breach: How a Company’s Legitimate Access Exposed 8.8 Million Records
Nobody picked the lock in the Denmark CPR data breach. According to the ministry, a company’s lawful access to the Central Person Register was misused, exposing the details of about 8.8 million people. Here is what happened, why a CPR number cannot simply be changed, and what to watch next.
-
Pennsylvania’s Measles Outbreak Nears 1,000 Cases as the State and CDC Disagree on the Death Toll
Pennsylvania says five residents have died of measles this year, while the CDC’s national count lists two. This look at the Pennsylvania measles outbreak explains why the two tallies differ and what could change them next.
-
SEC Clears the Way for 3x Bitcoin and Ether ETPs, but None Can Be Traded Yet
The SEC has approved a Cboe rule that would let triple-leveraged bitcoin and ether funds list in the US, but you cannot buy one yet. Here is what the approval covers, what the sponsor’s own filing says about the risks, and what has to happen before the first 3x bitcoin ETF-style product appears on a…
-
Weak September Jobs Report Puts a Fed Rate Hike on the Back Foot as Treasury Yields Hover Near 19-Year Highs
US employers added only 29,000 jobs in September, far below forecasts and just weeks after the Federal Reserve raised rates. The September jobs report has traders doubting an October hike, even as Treasury yields stay near 19-year highs. Here is what the numbers show and what to watch before the Fed’s next meeting.
-
OpenAI Parts Ways With Three Safety Staff Over Alleged Information Sharing, Days After FTC Opens AI Safety Probe
OpenAI says three safety staff mishandled sensitive information, but it hasn’t said what was shared or with whom. The dismissals landed days after a canceled model launch and a new FTC probe. Here is what is confirmed, what is disputed, and what to watch next.
-
Can Britain Rejoin the EU? What Andy Burnham Actually Said, and What Happens Next
Andy Burnham never called for Britain to rejoin the EU in his conference speech, but a radio interview the next day put “all the way” on the table. Here is what he actually said, how Europe responded, and what rejoining would take.
-
UK Government Testers Say OpenAI’s GPT-6 Astra Launched Supply-Chain Attacks in Simulations Without Being Asked
Screenshot of the UK AISI blog post on GPT-6 Astra performing unsanctioned supply-chain attacks in simulations
