CEMarque

What must I do by 11 December 2027?

Last verified 3 September 2026 · Facts v2026.09.2

Everything the Regulation asks for that is not already due. It applies in full from 11 December 2027, and from that date a product placed on the EU market has to be conformant before it goes on sale [1].

The deliverables

Technical documentation. Drawn up before placing on the market, following Annex VII, and kept together with the declaration of conformity for at least ten years after placing on the market or for the support period, whichever is longer [2] [3].

EU declaration of conformity. You draw it up and you sign it, following Annex V; a simplified form is permitted where it points to the full declaration [4].

CE marking. Affixed visibly, legibly and indelibly to the product, or where that is not possible to its packaging or accompanying documentation [5].

A software bill of materials. Manufacturers identify and document vulnerabilities and components, including by drawing up a bill of materials in a commonly used machine-readable format covering at least the top-level dependencies [6].

User information and instructions. Following Annex II: your identity and contact details, the single point of contact for reporting vulnerabilities, the product identification, and the support period [7].

A support period. Determined by you to reflect how long the product is expected to be in use, and at least five years unless the product is expected to be in use for less [8].

The route: who can self-assess

Default-class products may use internal control — Module A — which means you assess conformity yourself, with no notified body and no certificate [9]. Most software products are default class, and this is the ordinary case rather than a concession.

Important and critical products face stricter routes, and for those the choice of route is not yours alone [9]. Checking your class before you plan the work is therefore the first task, not the last.

If your product is already on the market

Products placed on the market before full application are subject to the Regulation only if substantially modified after that date [10]. The reporting duty applies to them regardless [10].

This is the most misunderstood provision in the whole timetable, and it cuts both ways. You are not obliged to retrofit CE marking onto a shipped product on 11 December 2027 [10]. You are obliged to report actively exploited vulnerabilities in it from the earlier date, and the moment you substantially modify it, the full requirements attach [10].

How long the work actually takes

The documentation is not the hard part; the evidence behind it is. A technical file has to describe how the product meets each essential requirement, which means the design decisions, the testing, and the vulnerability-handling process all have to exist before they can be written down [3].

For a small team the realistic sequence is: settle the product boundary and the class, then build the vulnerability-handling process that the reporting duty already requires, then generate the bill of materials from your build, then write the file around what you have [6] [3].

Started in that order, the deadline for full application is comfortable [1]. Started as a documentation exercise three months out, it is not.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex
  2. Technical documentation (Annex VII) is drawn up before placing on the market and kept, with the EU declaration of conformity, for at least ten years after placing on the market or the support period, whichever is longer. Art. 13(13), (16), Art. 31EUR-Lex
  3. Technical documentation contents (Annex VII). Annex VII, Art. 31EUR-Lex
  4. EU declaration of conformity (Annex V) and simplified declaration (Annex VI). Art. 28, Art. 13(15), (27), Annex V, Annex VIEUR-Lex
  5. CE marking is affixed visibly, legibly and indelibly to the product, or where not possible to the packaging or the declaration of conformity/accompanying documents; for software, on the declaration of conformity or the website accompanying the product. Art. 29–30EUR-Lex
  6. Manufacturers identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used machine-readable format covering at the very least the top-level dependencies. Annex I Part II(1), Art. 13(31)EUR-Lex
  7. User information and instructions (Annex II): manufacturer identity and contact; single point of contact for vulnerability reporting; product identification; intended purpose and security environment; circumstances that may lead to significant cybersecurity risks; where fixed-vulnerability information is published; support period end date; update installation and opt-out; secure decommissioning; access to the SBOM where relevant. Annex II, Art. 13(19)–(24)EUR-Lex
  8. Support period: determined by the manufacturer to reflect the expected use time; at least five years unless the product is expected to be in use for less; the end date (month and year) is stated at purchase. A security update, once issued, remains available for at least ten years or the remainder of the support period, whichever is longer. Art. 13(8), (10), (25)EUR-Lex
  9. Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIIIEUR-Lex
  10. Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless. Art. 69(2)–(3)EUR-Lex

Related

  • Does the EU Cyber Resilience Act apply to my mobile app?

    Yes, in almost every case. An installed app that connects to anything is a product with digital elements, and publishing it in an EU app store makes it available on the EU market.

  • Is SaaS in scope of the CRA?

    A pure cloud service is generally outside the CRA and falls under NIS2 instead. But a backend your own installed product cannot function without is part of that product, and is in scope with it.

  • Does the CRA apply to games?

    Yes for a commercially published game with any online component. The awkward parts for studios are the support period, automatic security updates for consumer products, and games that are already shipped.

  • What must I do by 11 September 2026?

    Be able to report. From that date manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA platform, with an early warning within 24 hours of becoming aware.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.