CRA and the supply chain: components, stewards and what to ask a supplier
Component due diligence under Article 13(5), the upstream vulnerability duty, open-source stewards, and the questions a component supplier has to answer.
Risk6 Sept 20269 min read
On this page
What it is
The Cyber Resilience Act, Regulation (EU) 2024/2847, reaches the supply chain through two paragraphs of Article 13. Paragraph 5 asks for due diligence when integrating components sourced from third parties, so they do not compromise the product's cybersecurity. It says so expressly for free and open-source components not made available commercially 1. Paragraph 6 runs upstream. On identifying a vulnerability in an integrated component, open-source included, the manufacturer reports it to whoever manufactures or maintains that component. It then remediates under Part II of Annex I and shares any fix it wrote 2.
Open-source is its own category. A steward is a legal person, not a manufacturer, whose aim is systematic sustained support for the development of particular free and open-source products. Those are intended for commercial activities, and the steward keeps them viable 3. Article 24 attaches duties. Article 25 gives the Commission a delegated-act power to create voluntary security attestation programmes, stated as facilitating Article 13(5) 4.
One decision, three owners: governance accepts the component, risk runs the due diligence and the upstream flow, compliance shows the bill of materials and the supplier evidence. One loop, not three silos.
Who is in scope (decision test)
- Does a product you place on the market integrate components you did not write? Bought and open-source components both count 1. If yes, go to 2; if no, start at CRA obligations by product class.
- Do you publish free and open-source software you do not place on the market? Run the Article 3(14) test above. The Commission reads the roles per project: one entity can be a steward for one product and the manufacturer of another 5.
- Are you an essential or important entity buying products under NIS2? Supply chain security sits in the baseline measures, covering the security-related aspects of each direct supplier relationship. Weigh that supplier's own vulnerabilities, its product and practice quality, and its secure development procedures 6.
- Are you the supplier being asked for evidence? The next section is what a buyer's duties generate.
- Have you found a vulnerability in a component you did not write? Article 13(6) attaches from 11 December 2027; the method is vulnerability handling and the SBOM.
| Outcome | What it means | Next step |
|---|---|---|
| In scope as integrator | Due diligence and the upstream duty both attach | Build the register; open the evidence file |
| In scope as steward | Article 24 reaches what you sustain, not all you host | Document the policy verifiably |
| Needs legal input | Placing on the market, or the steward test, is arguable | Have counsel confirm the role |
What to ask a component supplier
Each question exists because a duty on the buying side needs the answer. Governance decides who accepts a thin one, risk prices the gap, compliance keeps the file.
- Support period and update channel. Article 13(8) lets a manufacturer also weigh the support periods of integrated components providing core functions. Point (7) of Annex I Part II asks for mechanisms distributing updates securely 7. Setting it: the support period decision.
- Disclosure contact and policy. Point (5) asks for a policy on coordinated vulnerability disclosure. Point (6) adds measures easing information sharing about vulnerabilities in the product and its third-party components, including a contact address. Both sit in Annex I Part II 8. Without the supplier's equivalent, an Article 13(6) report has nowhere to go.
- Bill of materials, and in what form. The Regulation names no particular format, leaving format and elements to a possible implementing act. Where the record is offered, users are told where to reach it 9. Depth, format and storage are settled once, in the SBOM record.
- Attestation or conformity evidence. Article 25 programmes are voluntary and rest on a delegated act, so today the answer is documentary. The Commission asks the manufacturer to settle what the product needs from a component, then verify in a risk-based way that it delivers that. The maker's own documentation is named as evidence 10.
- End-of-support notice. Article 13(19) puts the end date, month and year at least, before the buyer at purchase. A user notice is asked for at the end of the period, where technically feasible 11.
- Who maintains it, and on what footing. An entity that stops giving systematic sustained support may stop meeting the steward definition. The Commission encourages saying so 12. See open-source risk is a maintainer problem.
Obligations by article
| Article | What it asks (paraphrased) | The artefact | Who owns it |
|---|---|---|---|
| CRA Art. 13(5) | Due diligence on integration, so a bought or open-source component does not compromise the product 1 | Due diligence record per component | Product security lead |
| CRA Art. 13(6) | Report a component vulnerability upstream, remediate, share the fix 2 | Upstream report log; shared-fix record | Product security lead |
| CRA Art. 24 | A steward documents a verifiable cybersecurity policy and gives it to a market surveillance authority on a reasoned request. Article 14 follows the steward's part in development 13 | Policy; reporting scope | Accountable officer |
| CRA Art. 25 | A delegated-act power to create voluntary attestation programmes for open-source products 4 | Watch item | Governance body |
| CRA Annex I Part II (1) | Identify and document components and vulnerabilities, drawing up a bill of materials 14 | SBOM per version | Release engineering |
| NIS2 Art. 21(2)(d) | Supply chain security in the baseline, covering each direct supplier 15 | Supplier register with tiers | Third-party risk owner |
Dates (verified)
No date is new; the calendar is at choosing the CRA conformity route.
Mapping to ISO/IEC 27002 and NIST CSF 2.0
| Duty | ISO/IEC 27002:2022 | IEC 62443-4-1:2018 | NIST CSF 2.0 | Gap |
|---|---|---|---|---|
| Accepting a component | 5.19 | SM-9 | GV.SC-06 | No record tied to a product version |
| Putting it in the agreement | 5.20 | — | GV.SC-05 | Article 13(6) rarely appears as a clause |
| Passing it down the chain | 5.21 | SM-10 | GV.SC-07 | Sub-tier maintainers sit outside agreements |
| Watching the relationship | 5.22 | — | GV.SC-09 | Component support-period drift is missed |
| Third-party code in the build | 8.28 | SM-9 | GV.SC-04 | Library inventory and SBOM stay separate |
| Ending the relationship | 5.22 | — | GV.SC-10 | No trigger for a maintainer leaving |
Control titles as printed 19:
- 5.19 Information security in supplier relationships
- 5.20 Addressing information security within supplier agreements
- 5.21 Managing information security in the ICT supply chain
- 5.22 Monitoring, review and change management of supplier services
- 8.28 Secure coding
Control 5.21 asks suppliers to pass security practices down their own chain and to say what software components are inside; 8.28 reaches open-source components too 20.
Identifiers and printed titles 21:
- SM-9: Security requirements for externally provided components
- SM-10: Custom developed components from third-party suppliers
GV.SC-04 reads: suppliers are known and prioritized by criticality 22.
Next 90 days
These plug into third-party risk across the contract lifecycle: the questions at its pre-contract step, the clauses at its contract step.
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | List every product with the components it integrates; mark core functions and named maintainers | Product security lead | Tiered component register |
| 2-3 | Write what the product needs from each core-function component, and how it is checked | Product security lead | Due diligence criteria |
| 2-4 | Send the questions above; record what comes back and what does not | Procurement lead | Evidence file per supplier |
| 3-4 | Name who accepts thin evidence and who signs the residual risk | Governance body | Decision-rights entry |
| 4-6 | Stand up the upstream path: where a report goes, who sends it, how a fix is shared | Product security lead | Upstream report log |
| 5-8 | Test whether anything you publish makes you a steward; if so, draft the policy | Accountable officer | Role determination; draft policy |
| 8-12 | Walk one component end to end: evidence, SBOM row, upstream path, clause set | Third-party risk owner | Walk-through record |
Related
- Vulnerability handling and the SBOM · Conformity route · Support period decision
- Obligations by product class · Third-party risk lifecycle · Control catalogue
- Maintainer problem · AI bill of materials · Radar: CRA guidance · CRA reporting
References
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://publications.europa.eu/resource/celex/32024R2847 23
- European Commission. Commission guidance on the application of the Cyber Resilience Act, annex to C(2026) 5252, 27.7.2026. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation 24
- European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. https://publications.europa.eu/resource/celex/32022L2555 25
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 26
- IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. https://webstore.iec.ch/en/publication/33615 27
- National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, Appendix A. https://doi.org/10.6028/NIST.CSWP.29 28
Sources
- 1EU Publications Office CELEX 32024R2847 Art. 13(5) · verified 2026-09-06
- 2EU Publications Office CELEX 32024R2847 Art. 13(6) · verified 2026-09-06
- 3EU Publications Office CELEX 32024R2847 Art. 3(14) · verified 2026-09-06
- 4EU Publications Office CELEX 32024R2847 Art. 25 · verified 2026-09-06
- 5European Commission C(2026) 5252 annex section 3.3 paragraph 73, ec.europa.eu · verified 2026-09-06
- 6EU Publications Office CELEX 32022L2555 Art. 21(2)(d) and Art. 21(3) · verified 2026-09-06
- 7EU Publications Office CELEX 32024R2847 Art. 13(8) and Annex I Part II point (7) · verified 2026-09-06
- 8EU Publications Office CELEX 32024R2847 Annex I Part II points (5) and (6) · verified 2026-09-06
- 9EU Publications Office CELEX 32024R2847 Art. 13(24) and Annex II point 9 · verified 2026-09-06
- 10European Commission C(2026) 5252 annex section 7.3 paragraphs 170 and 171, ec.europa.eu · verified 2026-09-06
- 11EU Publications Office CELEX 32024R2847 Art. 13(19) · verified 2026-09-06
- 12European Commission C(2026) 5252 annex section 3.3.1 paragraph 83, ec.europa.eu · verified 2026-09-06
- 13EU Publications Office CELEX 32024R2847 Art. 24(1), 24(2) and 24(3) · verified 2026-09-06
- 14EU Publications Office CELEX 32024R2847 Annex I Part II point (1) · verified 2026-09-06
- 15EU Publications Office CELEX 32022L2555 Art. 21(2)(d) · verified 2026-09-06
- 16EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-05
- 17EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
- 18EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
- 19ISO/IEC 27002:2022 controls 5.19, 5.20, 5.21, 5.22 and 8.28, licensed copy · verified 2026-09-06
- 20ISO/IEC 27002:2022 controls 5.21 and 8.28, licensed copy · verified 2026-09-06
- 21IEC 62443-4-1:2018 clauses 5.11 and 5.12, licensed copy · verified 2026-09-06
- 22NIST CSWP 29 Appendix A GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-09 and GV.SC-10, nvlpubs.nist.gov · verified 2026-09-06
- 23EU Publications Office CELEX 32024R2847 · verified 2026-09-06
- 24European Commission C(2026) 5252 annex, ec.europa.eu · verified 2026-09-06
- 25EU Publications Office CELEX 32022L2555 · verified 2026-09-06
- 26ISO/IEC 27002:2022, licensed copy · verified 2026-09-06
- 27IEC 62443-4-1:2018 product page, webstore.iec.ch · verified 2026-09-03
- 28NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-06