Back to briefings
    Briefing

    The support period decision

    How a CRA support period is set, evidenced, published and closed: the Article 13(8) criteria, the duties that run over it, and who owns each.

    Governance5 Sept 20269 min read

    ISO/IEC 27002:2022ISO/SAE 21434:2021Regulation (EU) 2024/2847UN Regulation No. 155 [2025/5]
    On this page

    What it is

    The Cyber Resilience Act, Regulation (EU) 2024/2847, defines the support period. It is the period in which a manufacturer must ensure that a product's vulnerabilities are handled effectively, to Part II of Annex I 1.

    The Regulation supplies no per-product number. Article 13(8) asks the manufacturer to determine the period so that it reflects how long the product is expected to be in use. A floor of at least five years applies, and a product expected to be in use for less takes its expected use time 2. The Commission reads that floor as a safeguard, not a default. Recital 60: a product expected to last longer carries a longer period 3.

    So it is a decision, and it needs three owners. Governance fixes the period per product and names who may move it. Risk supplies the expected-use evidence and prices the duties running over it. Compliance publishes the end date, keeps the records, and closes the period as Annex II requires. One loop, not three silos.

    Who must decide (decision test)

    1. In scope, and placed when? A product placed on the market before 11 December 2027 takes the substantive requirements only if substantially modified from that date; the Article 14 duties reach all of them 4. Class and route: CRA obligations by product class.
    2. What is the expected use time, and what evidence shows it? The Article 13(8) criteria, set out below, answer both 2. That evidence sits beside the risk assessment, documented and updated as appropriate across the period 5.
    3. What runs over the period? The Part II requirements, and the duty to correct, withdraw or recall on belief of non-conformity 6. Method: vulnerability handling and the SBOM. Reporting is the exception, continuing after support ends 7.
    4. What must the user be told? Annex II item 7 asks for the type of technical security support offered and the end date 8.
    5. What happens at the end? Article 13(19) puts that date, month and year at least, before the buyer at purchase, and asks for an end-of-support notification where technically feasible 9.
    OutcomeWhat it meansNext step
    Set and evidencedThe determination names the criteria and evidencePublish the end date; open the record
    AssertedA number declared with nothing behind itRebuild it from Article 13(8) before publication
    Needs legal inputUnion law may fix the lifetime, or the placing date is arguableWrite it up; have counsel confirm

    Setting the period

    Article 13(8) separates two lists. Taken into account in particular: reasonable user expectations, the nature of the product including its intended purpose, and Union law determining product lifetimes. A second list may also count: the periods others offer for similar functionality, and the availability of the operating environment. It runs on to the periods of third-party components providing core functions, and guidance from the administrative cooperation group and the Commission. All of it is weighed so the result stays proportionate 2.

    A product line decides once and records its exceptions. Below five years is open only where the product is genuinely expected to be in use for less. Recital 60 pushes the other way: industrial control systems are often in use significantly longer 10. Longer is a commitment, and its cost lands on release engineering.

    Substantial modification reopens the decision without resetting it, calling for a fresh test against the Article 13(8) criteria. Where it leaves the factors that set expected use time untouched, the product keeps the remaining original period. Where it changes them, the period is recalculated 11. Each substantially modified software version carries a declared period of its own 12.

    The three disciplines meet again. Governance names who may move the period and against what evidence. Risk owns the expected-use analysis and the cost of the duties. Compliance files the determination in the technical documentation, where Annex VII item 4 expects the information taken into account 13. That file does not stay private: authorities monitor how the criteria were applied, and the cooperation group publishes statistics and indicative periods 14.

    What the period obliges

    DutyCRA article / annexWho owns itThe record
    Handle vulnerabilitiesArt. 13(8); Annex I Part II 15Product security leadTriage and fix log
    Test and review as new input arrivesAnnex I Part II point (3) 16Engineering leadDated review record
    Disclose each fix once its update shipsAnnex I Part II point (4) 17Product security leadPublished advisory
    Keep issued updates available ten years, or to the period's end if laterArt. 13(9) 18Release engineeringDated update archive
    Notify exploited vulnerabilities and severe incidentsArt. 14 19Reporting roleTimestamped submissions
    Carry support type, end date and decommissioning stepsAnnex II points 7, 8 20Documentation ownerShipped instructions
    State the end date at purchaseArt. 13(19) 9Product ownerPurchase surface capture
    Retain documentation, declaration and user informationArt. 13(13), 13(18) 21Product compliance roleRetention schedule
    Tell authorities and users before operations ceaseArt. 13(23) 22Accountable officerDated notice

    Dates (verified)

    DateWhat happensSource
    2024-12-10Entry into force, the twentieth day after publication23
    2026-06-11Chapter IV, Articles 35 to 51, applies24
    2026-09-11Article 14 applies, reaching products already placed25
    2027-12-11General application; earlier products only if modified26

    Mapping

    Decision elementCRAISO/SAE 21434:2021 or R155ISO/IEC 27002:2022Evidence
    Setting the periodArt. 13(8); Annex VII point 4End of cybersecurity support is considered in the concept phase and in product development 278.32Dated determination
    Component and supplier periodsArt. 13(8), third subparagraphThe interface agreement records where cybersecurity support ends for an item or component 28; supplier dependencies are demonstrated 295.20, 5.22Interface agreements
    Duties running over itAnnex I Part II; Art. 13(21)Each vulnerability is managed so that its risks are treated, or removed by a remediation 308.8Triage log
    Monitoring across itAnnex I Part II point (3)The management system covers development, production and post-production, reassessing whether measures still work 318.8Review record
    Telling the userAnnex II point 7; Art. 13(19)A procedure communicates the decision to end cybersecurity support 32no control fitsInstructions; purchase page
    Closing the periodArt. 13(11), on unsupported software in public archives 33; Art. 13(19)Post-development requirements for decommissioning are made available 347.14Closure procedure

    Control titles as printed 35:

    • 5.20 Addressing information security within supplier agreements
    • 5.22 Monitoring, review and change management of supplier services
    • 7.14 Secure disposal or re-use of equipment
    • 8.8 Management of technical vulnerabilities
    • 8.32 Change management

    Next 90 days

    WeekActionOwnerOutput
    1List every product with its placing date and periodProduct compliance roleSupport-period register
    1-2Write the expected-use analysis against the Article 13(8) criteriaProduct security leadDated determination
    2Name who may shorten or extend a period, on what evidenceGovernance bodyDecision-rights entry
    3Price the duties: updates, tests, disclosure, archiveEngineering leadCost estimate per line
    3-4Collect the periods of components carrying core functionsComponent ownerComponent period table
    4-6Put the end date, month and year, on every purchase surfaceProduct ownerPurchase pages captured
    5-8Add support type and end date to the Annex II textDocumentation ownerRevised instructions
    6-10Stand up the update archive with a retention clockRelease engineeringArchive with dates
    8-12Write the end-of-support procedure; re-test one change against the criteriaProduct security leadProcedure; re-test record

    References

    1. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://publications.europa.eu/resource/celex/32024R2847 36
    2. European Commission. Commission guidance on the application of the Cyber Resilience Act, annex to C(2026) 5252, 27.7.2026. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation 37
    3. UNECE. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025. https://publications.europa.eu/resource/celex/42025X0005 38
    4. ISO and SAE International. Road vehicles — Cybersecurity engineering. ISO/SAE 21434:2021. https://www.iso.org/standard/70918.html 39
    5. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 40

    Sources

    1. 1EU Publications Office CELEX 32024R2847 Art. 3(20) · verified 2026-09-05
    2. 2EU Publications Office CELEX 32024R2847 Art. 13(8) · verified 2026-09-05
    3. 3European Commission C(2026) 5252 annex paragraphs 125 and 126, ec.europa.eu · verified 2026-09-05
    4. 4EU Publications Office CELEX 32024R2847 Art. 69(2) and 69(3) · verified 2026-09-05
    5. 5EU Publications Office CELEX 32024R2847 Art. 13(3) · verified 2026-09-05
    6. 6EU Publications Office CELEX 32024R2847 Art. 13(8) and Art. 13(21) · verified 2026-09-05
    7. 7European Commission C(2026) 5252 annex paragraph 210, ec.europa.eu · verified 2026-09-05
    8. 8EU Publications Office CELEX 32024R2847 Annex II point 7 · verified 2026-09-05
    9. 9EU Publications Office CELEX 32024R2847 Art. 13(19) · verified 2026-09-05
    10. 10EU Publications Office CELEX 32024R2847 recital 60 · verified 2026-09-05
    11. 11European Commission C(2026) 5252 annex paragraphs 133 to 135, ec.europa.eu · verified 2026-09-05
    12. 12European Commission C(2026) 5252 annex paragraph 128, ec.europa.eu · verified 2026-09-05
    13. 13EU Publications Office CELEX 32024R2847 Annex VII point 4 · verified 2026-09-05
    14. 14EU Publications Office CELEX 32024R2847 Art. 52(16) · verified 2026-09-05
    15. 15EU Publications Office CELEX 32024R2847 Art. 13(8) and Annex I Part II · verified 2026-09-05
    16. 16European Commission C(2026) 5252 annex paragraph 238, ec.europa.eu · verified 2026-09-05
    17. 17EU Publications Office CELEX 32024R2847 Annex I Part II point (4) · verified 2026-09-05
    18. 18EU Publications Office CELEX 32024R2847 Art. 13(9) · verified 2026-09-05
    19. 19EU Publications Office CELEX 32024R2847 Art. 14(1) and 14(3) · verified 2026-09-05
    20. 20EU Publications Office CELEX 32024R2847 Annex II points 7 and 8 · verified 2026-09-05
    21. 21EU Publications Office CELEX 32024R2847 Art. 13(13) and 13(18) · verified 2026-09-05
    22. 22EU Publications Office CELEX 32024R2847 Art. 13(23) · verified 2026-09-05
    23. 23EU Publications Office CELEX 32024R2847 Art. 71(1) · verified 2026-09-05
    24. 24EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-05
    25. 25EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
    26. 26EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
    27. 27ISO/SAE 21434:2021 clause 14.1, licensed copy · verified 2026-09-05
    28. 28ISO/SAE 21434:2021 clause 7.4.3, licensed copy · verified 2026-09-05
    29. 29EU Publications Office CELEX 42025X0005 para. 7.2.2.5 · verified 2026-09-05
    30. 30ISO/SAE 21434:2021 clause 8.6, licensed copy · verified 2026-09-05
    31. 31EU Publications Office CELEX 42025X0005 paras. 7.2.2.1 and 7.2.2.2 · verified 2026-09-05
    32. 32ISO/SAE 21434:2021 clause 14.3, licensed copy · verified 2026-09-05
    33. 33EU Publications Office CELEX 32024R2847 Art. 13(11) · verified 2026-09-05
    34. 34ISO/SAE 21434:2021 clause 14.4, licensed copy · verified 2026-09-05
    35. 35ISO/IEC 27002:2022 controls 5.20, 5.22, 7.14, 8.8 and 8.32, licensed copy · verified 2026-09-05
    36. 36EU Publications Office CELEX 32024R2847 · verified 2026-09-05
    37. 37European Commission C(2026) 5252 annex, ec.europa.eu · verified 2026-09-05
    38. 38EU Publications Office CELEX 42025X0005 · verified 2026-09-05
    39. 39ISO/SAE 21434:2021, licensed copy · verified 2026-09-05
    40. 40ISO/IEC 27002:2022, licensed copy · verified 2026-09-05