Back to briefings
    Briefing

    CRA and the supply chain: components, stewards and what to ask a supplier

    Component due diligence under Article 13(5), the upstream vulnerability duty, open-source stewards, and the questions a component supplier has to answer.

    Risk6 Sept 20269 min read

    Directive (EU) 2022/2555IEC 62443-4-1:2018ISO/IEC 27002:2022NIST CSWP 29Regulation (EU) 2024/2847
    On this page

    What it is

    The Cyber Resilience Act, Regulation (EU) 2024/2847, reaches the supply chain through two paragraphs of Article 13. Paragraph 5 asks for due diligence when integrating components sourced from third parties, so they do not compromise the product's cybersecurity. It says so expressly for free and open-source components not made available commercially 1. Paragraph 6 runs upstream. On identifying a vulnerability in an integrated component, open-source included, the manufacturer reports it to whoever manufactures or maintains that component. It then remediates under Part II of Annex I and shares any fix it wrote 2.

    Open-source is its own category. A steward is a legal person, not a manufacturer, whose aim is systematic sustained support for the development of particular free and open-source products. Those are intended for commercial activities, and the steward keeps them viable 3. Article 24 attaches duties. Article 25 gives the Commission a delegated-act power to create voluntary security attestation programmes, stated as facilitating Article 13(5) 4.

    One decision, three owners: governance accepts the component, risk runs the due diligence and the upstream flow, compliance shows the bill of materials and the supplier evidence. One loop, not three silos.

    Who is in scope (decision test)

    1. Does a product you place on the market integrate components you did not write? Bought and open-source components both count 1. If yes, go to 2; if no, start at CRA obligations by product class.
    2. Do you publish free and open-source software you do not place on the market? Run the Article 3(14) test above. The Commission reads the roles per project: one entity can be a steward for one product and the manufacturer of another 5.
    3. Are you an essential or important entity buying products under NIS2? Supply chain security sits in the baseline measures, covering the security-related aspects of each direct supplier relationship. Weigh that supplier's own vulnerabilities, its product and practice quality, and its secure development procedures 6.
    4. Are you the supplier being asked for evidence? The next section is what a buyer's duties generate.
    5. Have you found a vulnerability in a component you did not write? Article 13(6) attaches from 11 December 2027; the method is vulnerability handling and the SBOM.
    OutcomeWhat it meansNext step
    In scope as integratorDue diligence and the upstream duty both attachBuild the register; open the evidence file
    In scope as stewardArticle 24 reaches what you sustain, not all you hostDocument the policy verifiably
    Needs legal inputPlacing on the market, or the steward test, is arguableHave counsel confirm the role

    What to ask a component supplier

    Each question exists because a duty on the buying side needs the answer. Governance decides who accepts a thin one, risk prices the gap, compliance keeps the file.

    • Support period and update channel. Article 13(8) lets a manufacturer also weigh the support periods of integrated components providing core functions. Point (7) of Annex I Part II asks for mechanisms distributing updates securely 7. Setting it: the support period decision.
    • Disclosure contact and policy. Point (5) asks for a policy on coordinated vulnerability disclosure. Point (6) adds measures easing information sharing about vulnerabilities in the product and its third-party components, including a contact address. Both sit in Annex I Part II 8. Without the supplier's equivalent, an Article 13(6) report has nowhere to go.
    • Bill of materials, and in what form. The Regulation names no particular format, leaving format and elements to a possible implementing act. Where the record is offered, users are told where to reach it 9. Depth, format and storage are settled once, in the SBOM record.
    • Attestation or conformity evidence. Article 25 programmes are voluntary and rest on a delegated act, so today the answer is documentary. The Commission asks the manufacturer to settle what the product needs from a component, then verify in a risk-based way that it delivers that. The maker's own documentation is named as evidence 10.
    • End-of-support notice. Article 13(19) puts the end date, month and year at least, before the buyer at purchase. A user notice is asked for at the end of the period, where technically feasible 11.
    • Who maintains it, and on what footing. An entity that stops giving systematic sustained support may stop meeting the steward definition. The Commission encourages saying so 12. See open-source risk is a maintainer problem.

    Obligations by article

    ArticleWhat it asks (paraphrased)The artefactWho owns it
    CRA Art. 13(5)Due diligence on integration, so a bought or open-source component does not compromise the product 1Due diligence record per componentProduct security lead
    CRA Art. 13(6)Report a component vulnerability upstream, remediate, share the fix 2Upstream report log; shared-fix recordProduct security lead
    CRA Art. 24A steward documents a verifiable cybersecurity policy and gives it to a market surveillance authority on a reasoned request. Article 14 follows the steward's part in development 13Policy; reporting scopeAccountable officer
    CRA Art. 25A delegated-act power to create voluntary attestation programmes for open-source products 4Watch itemGovernance body
    CRA Annex I Part II (1)Identify and document components and vulnerabilities, drawing up a bill of materials 14SBOM per versionRelease engineering
    NIS2 Art. 21(2)(d)Supply chain security in the baseline, covering each direct supplier 15Supplier register with tiersThird-party risk owner

    Dates (verified)

    No date is new; the calendar is at choosing the CRA conformity route.

    DateWhat happensSource
    11 June 2026Chapter IV applies; conformity assessment bodies can be notified16
    11 September 2026Article 14 applies; reporting duties reach products already placed17
    11 December 2027General application; earlier products reached only on substantial modification18

    Mapping to ISO/IEC 27002 and NIST CSF 2.0

    DutyISO/IEC 27002:2022IEC 62443-4-1:2018NIST CSF 2.0Gap
    Accepting a component5.19SM-9GV.SC-06No record tied to a product version
    Putting it in the agreement5.20GV.SC-05Article 13(6) rarely appears as a clause
    Passing it down the chain5.21SM-10GV.SC-07Sub-tier maintainers sit outside agreements
    Watching the relationship5.22GV.SC-09Component support-period drift is missed
    Third-party code in the build8.28SM-9GV.SC-04Library inventory and SBOM stay separate
    Ending the relationship5.22GV.SC-10No trigger for a maintainer leaving

    Control titles as printed 19:

    • 5.19 Information security in supplier relationships
    • 5.20 Addressing information security within supplier agreements
    • 5.21 Managing information security in the ICT supply chain
    • 5.22 Monitoring, review and change management of supplier services
    • 8.28 Secure coding

    Control 5.21 asks suppliers to pass security practices down their own chain and to say what software components are inside; 8.28 reaches open-source components too 20.

    Identifiers and printed titles 21:

    • SM-9: Security requirements for externally provided components
    • SM-10: Custom developed components from third-party suppliers

    GV.SC-04 reads: suppliers are known and prioritized by criticality 22.

    Next 90 days

    These plug into third-party risk across the contract lifecycle: the questions at its pre-contract step, the clauses at its contract step.

    WeekActionOwnerOutput
    1-2List every product with the components it integrates; mark core functions and named maintainersProduct security leadTiered component register
    2-3Write what the product needs from each core-function component, and how it is checkedProduct security leadDue diligence criteria
    2-4Send the questions above; record what comes back and what does notProcurement leadEvidence file per supplier
    3-4Name who accepts thin evidence and who signs the residual riskGovernance bodyDecision-rights entry
    4-6Stand up the upstream path: where a report goes, who sends it, how a fix is sharedProduct security leadUpstream report log
    5-8Test whether anything you publish makes you a steward; if so, draft the policyAccountable officerRole determination; draft policy
    8-12Walk one component end to end: evidence, SBOM row, upstream path, clause setThird-party risk ownerWalk-through record

    References

    1. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://publications.europa.eu/resource/celex/32024R2847 23
    2. European Commission. Commission guidance on the application of the Cyber Resilience Act, annex to C(2026) 5252, 27.7.2026. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation 24
    3. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. https://publications.europa.eu/resource/celex/32022L2555 25
    4. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 26
    5. IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. https://webstore.iec.ch/en/publication/33615 27
    6. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, Appendix A. https://doi.org/10.6028/NIST.CSWP.29 28

    Sources

    1. 1EU Publications Office CELEX 32024R2847 Art. 13(5) · verified 2026-09-06
    2. 2EU Publications Office CELEX 32024R2847 Art. 13(6) · verified 2026-09-06
    3. 3EU Publications Office CELEX 32024R2847 Art. 3(14) · verified 2026-09-06
    4. 4EU Publications Office CELEX 32024R2847 Art. 25 · verified 2026-09-06
    5. 5European Commission C(2026) 5252 annex section 3.3 paragraph 73, ec.europa.eu · verified 2026-09-06
    6. 6EU Publications Office CELEX 32022L2555 Art. 21(2)(d) and Art. 21(3) · verified 2026-09-06
    7. 7EU Publications Office CELEX 32024R2847 Art. 13(8) and Annex I Part II point (7) · verified 2026-09-06
    8. 8EU Publications Office CELEX 32024R2847 Annex I Part II points (5) and (6) · verified 2026-09-06
    9. 9EU Publications Office CELEX 32024R2847 Art. 13(24) and Annex II point 9 · verified 2026-09-06
    10. 10European Commission C(2026) 5252 annex section 7.3 paragraphs 170 and 171, ec.europa.eu · verified 2026-09-06
    11. 11EU Publications Office CELEX 32024R2847 Art. 13(19) · verified 2026-09-06
    12. 12European Commission C(2026) 5252 annex section 3.3.1 paragraph 83, ec.europa.eu · verified 2026-09-06
    13. 13EU Publications Office CELEX 32024R2847 Art. 24(1), 24(2) and 24(3) · verified 2026-09-06
    14. 14EU Publications Office CELEX 32024R2847 Annex I Part II point (1) · verified 2026-09-06
    15. 15EU Publications Office CELEX 32022L2555 Art. 21(2)(d) · verified 2026-09-06
    16. 16EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-05
    17. 17EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
    18. 18EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
    19. 19ISO/IEC 27002:2022 controls 5.19, 5.20, 5.21, 5.22 and 8.28, licensed copy · verified 2026-09-06
    20. 20ISO/IEC 27002:2022 controls 5.21 and 8.28, licensed copy · verified 2026-09-06
    21. 21IEC 62443-4-1:2018 clauses 5.11 and 5.12, licensed copy · verified 2026-09-06
    22. 22NIST CSWP 29 Appendix A GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-09 and GV.SC-10, nvlpubs.nist.gov · verified 2026-09-06
    23. 23EU Publications Office CELEX 32024R2847 · verified 2026-09-06
    24. 24European Commission C(2026) 5252 annex, ec.europa.eu · verified 2026-09-06
    25. 25EU Publications Office CELEX 32022L2555 · verified 2026-09-06
    26. 26ISO/IEC 27002:2022, licensed copy · verified 2026-09-06
    27. 27IEC 62443-4-1:2018 product page, webstore.iec.ch · verified 2026-09-03
    28. 28NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-06