3 September 2026
If your product lands in Annex III Class I of the Cyber Resilience Act, you have two routes to conformity. Right now, in September 2026, both of them are obstructed — and the reason is not in any single document, it is in the gap between two of them.
The CRA sorts products with digital elements into three tiers, and the tier determines the route:
| Tier | Route |
|---|---|
| Default — everything not listed in Annex III or IV | Self-assessment under Module A, internal control. Permitted regardless of which technical specification you use. Roughly 90% of products. |
| Important, Class I — password managers, VPNs, routers, browsers, operating systems, SIEM, identity management, smart locks and cameras | Self-assessment only if you fully apply harmonised standards, common specifications, or a European cybersecurity certification scheme. Otherwise a notified body. |
| Important Class II and Critical — firewalls, hypervisors, TPMs, smart meter gateways, secure elements | Notified body. No self-assessment route exists. |
Default-tier manufacturers are fine and can act today. Class II and Critical know they need a third party. Class I is the awkward middle, and its route depends on something that has not arrived.
Standardisation request M/606 was accepted by CEN, CENELEC and ETSI in April 2025, covering 41 harmonised standards, originally due Q3 2026. In early July 2026 the Commission proposed pushing those deadlines back: the A and B vulnerability management standards to 31 October 2026, the C standards to 31 December 2026.
Delivery is not the finish line, and this is the part that is easy to miss. A harmonised standard only confers the Article 27 presumption of conformity once its reference is cited in the Official Journal, which happens after delivery, assessment, and a formal citation decision. That lag is measured in months.
So "the standards land in late 2026" and "you can rely on the standards in late 2026" are different statements, and only the first one is true.
The CRA's rules on notified bodies started to apply on 11 June 2026. As of late June 2026, zero notified bodies had been designated in the Commission's NANDO database. Not few. None.
Article 35(2) sets 11 December 2026 as the point by which Member States should strive to ensure sufficient notified body capacity, expressly to avoid bottlenecks that hinder market entry. "Strive to ensure" is a best-efforts objective, not a guarantee, and it says nothing about whether capacity will exist for any particular product category.
Anyone waiting for designations to appear will be competing for scarce capacity against everyone else who waited, in the run-up to full application on 11 December 2027.
For a Class I manufacturer today, the honest position is that neither route can be completed right now. That is not a reason to do nothing; it is a reason to do the part that does not depend on either.
All of the above concerns the December 2027 deadline. Article 14 reporting started on 11 September 2026, applies regardless of tier, and applies to products already on the market. Reporting is not conformity assessment: no standard, no notified body, and no classification question stands between a manufacturer and a 24-hour early warning obligation.
Which produces the strange situation many Class I manufacturers are in this month: blocked on the thing due next year, and already live on the thing due now.
Flagrante reads an SBOM and tells you which components carry a vulnerability CISA says is being exploited — the ones that start an Article 14 clock, separated from the thousands that do not.
pip install flagrante then syft dir:. -o cyclonedx-json | flagrante
Or drop an SBOM in the browser. It is never stored, anywhere.