CRA Reporting Deadline: September 11, 2026

Is your engineering team CRA ready?

The EU Cyber Resilience Act requires continuous compliance evidence from your software development process. Reporting obligations start in September 2026. Check your readiness below — then scan your repo for free.

150
Days
21
Hours
00
Min
47
Sec

Until CRA reporting obligations begin (Article 14)

Key Deadlines

Jun 11, 2026
Conformity assessment bodies notified
Sep 11, 2026
Reporting obligations begin — vulnerability & incident reporting to ENISA
Dec 11, 2027
Full enforcement — CE marking required for market access

Quick Readiness Check

Can your team answer yes to these today? Tick what you have in place.

Your readiness: 0%0/8 critical items

Vulnerability Handling

Software Bill of Materials

Secure Development Lifecycle

Evidence & Documentation

Start your assessment to see where you stand.

Most teams have 4-6 months of work to close critical gaps. Run a free scan to get your personalised roadmap.

Scan Your Repo Free →

No sign-up required. Read-only access. Your code is never stored.

What the CRA Requires

21 Essential Requirements, 5 Categories

Annex I of the Cyber Resilience Act defines what every software product must demonstrate. Concordance maps your engineering practices to each requirement automatically.

🛡️Security by Design6 req.

Products delivered with secure defaults, minimal attack surface, limited exploit impact

🔐Data Protection3 req.

Confidentiality, integrity and availability of stored, transmitted and processed data

🔑Access Control2 req.

Protection against unauthorised access, logging of security-relevant events

Resilience & Recovery2 req.

Availability functions, resilience and mitigation against denial-of-service

🔍Vulnerability Management8 req.

Identification, documentation, remediation and disclosure of vulnerabilities

How Concordance Helps

From evidence gap to audit-ready in weeks, not months.

1
Connect

OAuth to GitHub, GitLab, or Bitbucket. Read-only. 60 seconds.

2
Score

50 engineering protocols scored from real toolchain data. Not surveys.

3
Map

Every protocol maps to specific Annex I requirements with evidence strength.

4
Fix

Prioritised remediation playbook. Close critical gaps first.

Don't wait for your auditor to tell you.

Teams that start now will have 4+ months of continuous evidence by the September deadline. Teams that wait will be scrambling.

Run Your Free CRA Scan →See Full Annex I Mapping
Read-only accessNo sign-up requiredYour code is never stored

CRA Resources

CRA Compliance Guide for Engineering Teams
12 min read
2026 CRA Deadlines Explained
5 min read
CRA for US Companies
8 min read
Preparing Your Team for CRA
4 min read
CRA Tools Compared
8 min read
Full Annex I Mapping
Interactive