CRA knowledge base

Manufacturer obligations

Risk assessment, vulnerabilities, security updates, components and support period.

← Back to the FAQ overview

All questions in this topic

What does the CRA require of the manufacturer’s cybersecurity risk assessment?

As usual under the New Legislative Framework: carry out a risk assessment and, based on it, implement, document and keep current the relevant essential requirements.

Source: European Commission · FAQ 4.1 Official EU FAQ (original text)

Does the CRA mandate a specific risk assessment methodology?

No. Manufacturers may choose the methodology they use to identify and treat the relevant risks.

Source: European Commission · FAQ 4.1.2 Official EU FAQ (original text)

Does a manufacturer need to implement all the essential requirements?

The vulnerability-handling requirements (Annex I Part II) always apply. The product-property requirements (Part I) apply to the extent relevant based on the risk assessment.

Source: European Commission · FAQ 4.1.3 Official EU FAQ (original text)

What are intended purpose and reasonably foreseeable use, and how do they affect the assessment?

They frame the risk assessment (Art. 13): the planned use and realistically foreseeable use scenarios must be considered to minimise risks and prevent incidents.

Source: European Commission · FAQ 4.1.4 Official EU FAQ (original text)

What is reasonably foreseeable misuse, and how does it affect the assessment?

Manufacturers inform about secure deployment conditions; foreseeable misuse must be considered in the risk assessment (Art. 13(18)), while users observe the intended conditions of use.

Source: European Commission · FAQ 4.1.5 Official EU FAQ (original text)

How does the expected time in use affect the risk assessment?

The expected time in use determines the support period and feeds into the risk assessment (Art. 13(3)): the longer the use, the longer security and updates must be ensured.

Source: European Commission · FAQ 4.1.6 Official EU FAQ (original text)

How do harmonised standards relate to the risk assessment?

Harmonised standards do not replace the legally binding requirements – they are one possible technical means of meeting them (presumption of conformity).

Source: European Commission · FAQ 4.1.7 Official EU FAQ (original text)

What must the technical documentation include regarding the risk assessment?

The technical documentation (Art. 13(12), Art. 31) must demonstrate conformity – including the risk assessment – and be available to market surveillance authorities on request.

Source: European Commission · FAQ 4.1.8 Official EU FAQ (original text)

Which technical measures does a manufacturer need to implement?

The essential requirements in Annex I Part I – objective-oriented and technology-neutral, applying horizontally to all products with digital elements, implemented according to the risk assessment.

Source: European Commission · FAQ 4.2 Official EU FAQ (original text)

How can a manufacturer ensure a product is free from vulnerabilities?

Absolute freedom from flaws is not required. Products must, however, be placed on the market without known exploitable vulnerabilities (Annex I, req. 2(a)), based on the risk assessment.

Source: European Commission · FAQ 4.2.2 Official EU FAQ (original text)

How to handle known vulnerabilities found after placing on the market but before reaching the user?

Such vulnerabilities must be addressed before the product reaches the final user – e.g. while still in the distribution chain, via updates or fixes.

Source: European Commission · FAQ 4.2.3 Official EU FAQ (original text)

How does the secure-by-default requirement work?

Products must ship with a secure default configuration (Annex I) – deviations only where agreed with a business user for a tailor-made product.

Source: European Commission · FAQ 4.2.4 Official EU FAQ (original text)

When is a product “tailor-made” and what documentation is required?

Tailor-made products are adapted for a specific business user. Only here are justified deviations from individual requirements possible – to be documented transparently.

Source: European Commission · FAQ 4.2.5 Official EU FAQ (original text)

Must manufacturers patch all vulnerabilities found during the support period?

Vulnerabilities must be addressed and remediated without delay, including via security updates (Annex I Part II). The how/when is risk-based; not every fix needs to be a separate update.

Source: European Commission · FAQ 4.3 Official EU FAQ (original text)

Must the manufacturer remediate vulnerabilities for all versions of a software product?

Where several substantially modified versions exist, the obligation may be limited to the version last placed on the market – under certain conditions.

Source: European Commission · FAQ 4.3.2 Official EU FAQ (original text)

Is the manufacturer responsible for users installing security updates?

Manufacturers must provide updates and design products/processes so updates can be applied promptly. Installing them is, in principle, up to the users.

Source: European Commission · FAQ 4.3.3 Official EU FAQ (original text)

Must the manufacturer recall the product if a vulnerability cannot be fixed?

In case of non-conformity, corrective measures must be taken without delay – depending on risk, up to withdrawal or recall of the product.

Source: European Commission · FAQ 4.3.4 Official EU FAQ (original text)

How to separate security and functionality updates when one update serves both?

Security updates should be provided separately where possible, so users can apply them without unwanted functional changes – even when an update serves both purposes.

Source: European Commission · FAQ 4.3.5 Official EU FAQ (original text)

How should vulnerabilities in integrated components be addressed?

The obligations apply to the entire product including all integrated components. The manufacturer must also address vulnerabilities in components.

Source: European Commission · FAQ 4.3.6 Official EU FAQ (original text)

How does a component’s end of support affect the product’s CRA compliance?

When setting the support period, the support periods of integrated components must be taken into account so the overall product stays securely supported.

Source: European Commission · FAQ 4.3.7 Official EU FAQ (original text)

What does the CRA prescribe when integrating components?

The finished product must meet the essential requirements (Art. 13(1)). For sourced components, due diligence must ensure they do not compromise the product’s security.

Source: European Commission · FAQ 4.4 Official EU FAQ (original text)

What is the appropriate level of due diligence?

It depends on the nature and level of cybersecurity risk of the component – the aim is that integrated components do not compromise the product’s cybersecurity.

Source: European Commission · FAQ 4.4.2 Official EU FAQ (original text)

May only CE-marked components be integrated?

No. Non-CE-marked components, or those placed on the market before the CRA applies, may also be integrated, provided due diligence ensures the product’s security (Art. 13(5)).

Source: European Commission · FAQ 4.4.3 Official EU FAQ (original text)

How to exercise due diligence for open-source components not subject to the CRA?

Such open-source components (not made available commercially, or published by an open-source steward) may be integrated – with risk-appropriate due diligence.

Source: European Commission · FAQ 4.4.4 Official EU FAQ (original text)

Which criteria determine a product’s support period?

The support period must reflect the expected time in use – based on, among other things, reasonable user expectations, the nature and purpose of the product, and relevant Union law.

Source: European Commission · FAQ 4.5 Official EU FAQ (original text)

Is there a minimum support period?

Yes: at least five years. If the product is expected to be in use for less, the support period corresponds to the expected use time (Art. 13(8)).

Source: European Commission · FAQ 4.5.2 Official EU FAQ (original text)

Can products be sold without a support period?

No. A support period must be set for all products placed on the market after 11 December 2027. After it expires, they may still be made available on the market.

Source: European Commission · FAQ 4.5.3 Official EU FAQ (original text)

Can a third-country manufacturer place products directly on the EU market?

Only if there is an economic operator established in the EU (e.g. authorised representative, importer) responsible for the prescribed tasks.

Source: European Commission · FAQ 4.6 Official EU FAQ (original text)

Topic blocks

Summarised and translated from the European Commission’s “FAQs on the Cyber Resilience Act” (v1.2, 16 January 2026), licensed under CC BY 4.0. Simplified by Lehner & Szecsey – the original text prevails. Official EU FAQ (original text).