Regulations are usually late in one direction: the obligations arrive before industry is ready. The Cyber Resilience Act is currently late in the other one, and the asymmetry is worth understanding before September.
The CRA does not only impose deadlines on manufacturers. It imposes two on the Commission, and it wrote them into its own text.
What was due on 11 December 2025
Article 7 requires the Commission to specify which products are which:
“By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements as set out in Annex IV.”
Article 14 — the reporting article — requires a second instrument:
“By 11 December 2025, the Commission shall adopt delegated acts … specifying the terms and conditions for applying the cybersecurity-related grounds in relation to delaying the dissemination of notifications…”
As of 12 August 2026, EUR-Lex lists three procedures based on the CRA. All three are drafts: an implementing regulation on the technical description of important and critical products, a delegated regulation on excluding L-category vehicles from scope, and a delegated regulation on delaying the dissemination of notifications. None has been adopted.
That is eight months past a date the regulation set for itself.
Why the Article 7 act is the one that stings
Annex III lists important products with digital elements, split into class I and class II. Annex IV lists critical products. Which annex and which class your product falls into determines which conformity assessment route you are required to take — whether you can self-assess, or whether a third party has to be involved.
The implementing act that has not been adopted is the one that gives the technical description of those categories. So the regulation tells you that your classification decides your route, and the instrument that lets you make the classification with confidence is not out.
Manufacturers are not blocked — Annex III and Annex IV exist and are readable, and most products are not close to the line. But the companies that are close to the line are precisely the ones who need the technical description, and they are the ones being asked to plan without it.
Why the Article 14 one matters more right now
Look at where the second missing instrument lives. It is a delegated act under Article 14 — the article that carries the reporting obligations, and the one that starts applying on 11 September 2026.
The delegated act covers a narrow question: when a manufacturer may ask that dissemination of a notification be delayed on cybersecurity-related grounds. That is not the core duty. The core duty applies on schedule regardless: an early warning within 24 hours, a notification within 72 hours, and a final report — 14 days for actively exploited vulnerabilities, one month for severe incidents.
The point is not that the missing act excuses anything. It is the opposite. The reporting date does not move because the surrounding instruments are late. A manufacturer in scope on 11 September is in scope with an incomplete rulebook, and the 24-hour clock is not waiting for Brussels.
The gap does not stay empty
There is a third instrument the CRA authorises and that has not appeared at all — not even as a draft procedure. Annex I empowers the Commission, by implementing act, to specify the format and elements of the software bill of materials.
Until it does, the only operative requirement in the text is the floor: an SBOM “in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products.” That is one level deep.
Germany did not wait. The Federal Office for Information Security published BSI TR-03183, Part 2: Software Bill of Materials, presented as the BSI's interpretation of the cyber resilience requirements. Its level-of-detail requirement is not one level:
“… recursive dependency resolution MUST be performed at least for each component included in the scope of delivery on each path downward … at least up to and including the first component that is outside the scope of delivery.”
It also requires that the SBOM contain the same information available during the build process, and it maps its data fields onto SPDX and CycloneDX.
Read the two side by side and the practical situation is clear enough. The regulation's floor is top-level dependencies. A national technical guideline, from the largest member state, asks for the full transitive tree with build fidelity. Both are addressed to the same manufacturer selling into the same single market.
This is the part worth carrying away, and it is more general than the SBOM: when the central instrument is late, the vacuum does not stay a vacuum. It gets filled by whoever can — and what fills it is national, which is the opposite of what a harmonising regulation is for.
What you can decide without the missing acts
Most of the September work does not depend on anything that has not been adopted.
- Whether you are in scope at all. Article 2(2) excludes products covered by the MDR and IVDR. That exclusion is in force and is not waiting on an implementing act. What it does not cover is everything else you place on the market.
- Whether you can meet a 24-hour clock. This is an operational question — monitoring, decision authority, a named route to file — and no delegated act is going to make it easier.
- What is actually in your product. If your SBOM covers only top-level dependencies, you satisfy the text as written today. Whether that is the right target when you sell into Germany is a commercial decision you can make now, with the BSI guideline in front of you, rather than after an implementing act lands.
The regulation being behind schedule is a real fact and it is worth knowing. It is not a reason to be behind schedule yourself, because the one date that has not slipped is the one that arrives first.