The support period decision
How a CRA support period is set, evidenced, published and closed: the Article 13(8) criteria, the duties that run over it, and who owns each.
Governance5 Sept 20269 min read
On this page
What it is
The Cyber Resilience Act, Regulation (EU) 2024/2847, defines the support period. It is the period in which a manufacturer must ensure that a product's vulnerabilities are handled effectively, to Part II of Annex I 1.
The Regulation supplies no per-product number. Article 13(8) asks the manufacturer to determine the period so that it reflects how long the product is expected to be in use. A floor of at least five years applies, and a product expected to be in use for less takes its expected use time 2. The Commission reads that floor as a safeguard, not a default. Recital 60: a product expected to last longer carries a longer period 3.
So it is a decision, and it needs three owners. Governance fixes the period per product and names who may move it. Risk supplies the expected-use evidence and prices the duties running over it. Compliance publishes the end date, keeps the records, and closes the period as Annex II requires. One loop, not three silos.
Who must decide (decision test)
- In scope, and placed when? A product placed on the market before 11 December 2027 takes the substantive requirements only if substantially modified from that date; the Article 14 duties reach all of them 4. Class and route: CRA obligations by product class.
- What is the expected use time, and what evidence shows it? The Article 13(8) criteria, set out below, answer both 2. That evidence sits beside the risk assessment, documented and updated as appropriate across the period 5.
- What runs over the period? The Part II requirements, and the duty to correct, withdraw or recall on belief of non-conformity 6. Method: vulnerability handling and the SBOM. Reporting is the exception, continuing after support ends 7.
- What must the user be told? Annex II item 7 asks for the type of technical security support offered and the end date 8.
- What happens at the end? Article 13(19) puts that date, month and year at least, before the buyer at purchase, and asks for an end-of-support notification where technically feasible 9.
| Outcome | What it means | Next step |
|---|---|---|
| Set and evidenced | The determination names the criteria and evidence | Publish the end date; open the record |
| Asserted | A number declared with nothing behind it | Rebuild it from Article 13(8) before publication |
| Needs legal input | Union law may fix the lifetime, or the placing date is arguable | Write it up; have counsel confirm |
Setting the period
Article 13(8) separates two lists. Taken into account in particular: reasonable user expectations, the nature of the product including its intended purpose, and Union law determining product lifetimes. A second list may also count: the periods others offer for similar functionality, and the availability of the operating environment. It runs on to the periods of third-party components providing core functions, and guidance from the administrative cooperation group and the Commission. All of it is weighed so the result stays proportionate 2.
A product line decides once and records its exceptions. Below five years is open only where the product is genuinely expected to be in use for less. Recital 60 pushes the other way: industrial control systems are often in use significantly longer 10. Longer is a commitment, and its cost lands on release engineering.
Substantial modification reopens the decision without resetting it, calling for a fresh test against the Article 13(8) criteria. Where it leaves the factors that set expected use time untouched, the product keeps the remaining original period. Where it changes them, the period is recalculated 11. Each substantially modified software version carries a declared period of its own 12.
The three disciplines meet again. Governance names who may move the period and against what evidence. Risk owns the expected-use analysis and the cost of the duties. Compliance files the determination in the technical documentation, where Annex VII item 4 expects the information taken into account 13. That file does not stay private: authorities monitor how the criteria were applied, and the cooperation group publishes statistics and indicative periods 14.
What the period obliges
| Duty | CRA article / annex | Who owns it | The record |
|---|---|---|---|
| Handle vulnerabilities | Art. 13(8); Annex I Part II 15 | Product security lead | Triage and fix log |
| Test and review as new input arrives | Annex I Part II point (3) 16 | Engineering lead | Dated review record |
| Disclose each fix once its update ships | Annex I Part II point (4) 17 | Product security lead | Published advisory |
| Keep issued updates available ten years, or to the period's end if later | Art. 13(9) 18 | Release engineering | Dated update archive |
| Notify exploited vulnerabilities and severe incidents | Art. 14 19 | Reporting role | Timestamped submissions |
| Carry support type, end date and decommissioning steps | Annex II points 7, 8 20 | Documentation owner | Shipped instructions |
| State the end date at purchase | Art. 13(19) 9 | Product owner | Purchase surface capture |
| Retain documentation, declaration and user information | Art. 13(13), 13(18) 21 | Product compliance role | Retention schedule |
| Tell authorities and users before operations cease | Art. 13(23) 22 | Accountable officer | Dated notice |
Dates (verified)
Mapping
| Decision element | CRA | ISO/SAE 21434:2021 or R155 | ISO/IEC 27002:2022 | Evidence |
|---|---|---|---|---|
| Setting the period | Art. 13(8); Annex VII point 4 | End of cybersecurity support is considered in the concept phase and in product development 27 | 8.32 | Dated determination |
| Component and supplier periods | Art. 13(8), third subparagraph | The interface agreement records where cybersecurity support ends for an item or component 28; supplier dependencies are demonstrated 29 | 5.20, 5.22 | Interface agreements |
| Duties running over it | Annex I Part II; Art. 13(21) | Each vulnerability is managed so that its risks are treated, or removed by a remediation 30 | 8.8 | Triage log |
| Monitoring across it | Annex I Part II point (3) | The management system covers development, production and post-production, reassessing whether measures still work 31 | 8.8 | Review record |
| Telling the user | Annex II point 7; Art. 13(19) | A procedure communicates the decision to end cybersecurity support 32 | no control fits | Instructions; purchase page |
| Closing the period | Art. 13(11), on unsupported software in public archives 33; Art. 13(19) | Post-development requirements for decommissioning are made available 34 | 7.14 | Closure procedure |
Control titles as printed 35:
- 5.20 Addressing information security within supplier agreements
- 5.22 Monitoring, review and change management of supplier services
- 7.14 Secure disposal or re-use of equipment
- 8.8 Management of technical vulnerabilities
- 8.32 Change management
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1 | List every product with its placing date and period | Product compliance role | Support-period register |
| 1-2 | Write the expected-use analysis against the Article 13(8) criteria | Product security lead | Dated determination |
| 2 | Name who may shorten or extend a period, on what evidence | Governance body | Decision-rights entry |
| 3 | Price the duties: updates, tests, disclosure, archive | Engineering lead | Cost estimate per line |
| 3-4 | Collect the periods of components carrying core functions | Component owner | Component period table |
| 4-6 | Put the end date, month and year, on every purchase surface | Product owner | Purchase pages captured |
| 5-8 | Add support type and end date to the Annex II text | Documentation owner | Revised instructions |
| 6-10 | Stand up the update archive with a retention clock | Release engineering | Archive with dates |
| 8-12 | Write the end-of-support procedure; re-test one change against the criteria | Product security lead | Procedure; re-test record |
Related
- Choosing the CRA conformity route — the file this lands in.
- Vulnerability handling and the SBOM under the CRA — the duties that run.
- CRA in fifteen months: what to do first — the first quarter.
- Product CSMS as a management system — the analogues.
- Radar: CRA guidance · CRA manufacturer reporting.
References
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). OJ L, 2024/2847, 20.11.2024. https://publications.europa.eu/resource/celex/32024R2847 36
- European Commission. Commission guidance on the application of the Cyber Resilience Act, annex to C(2026) 5252, 27.7.2026. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation 37
- UNECE. UN Regulation No. 155 [2025/5]. OJ L, 2025/5, 10.1.2025. https://publications.europa.eu/resource/celex/42025X0005 38
- ISO and SAE International. Road vehicles — Cybersecurity engineering. ISO/SAE 21434:2021. https://www.iso.org/standard/70918.html 39
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 40
Sources
- 1EU Publications Office CELEX 32024R2847 Art. 3(20) · verified 2026-09-05
- 2EU Publications Office CELEX 32024R2847 Art. 13(8) · verified 2026-09-05
- 3European Commission C(2026) 5252 annex paragraphs 125 and 126, ec.europa.eu · verified 2026-09-05
- 4EU Publications Office CELEX 32024R2847 Art. 69(2) and 69(3) · verified 2026-09-05
- 5EU Publications Office CELEX 32024R2847 Art. 13(3) · verified 2026-09-05
- 6EU Publications Office CELEX 32024R2847 Art. 13(8) and Art. 13(21) · verified 2026-09-05
- 7European Commission C(2026) 5252 annex paragraph 210, ec.europa.eu · verified 2026-09-05
- 8EU Publications Office CELEX 32024R2847 Annex II point 7 · verified 2026-09-05
- 9EU Publications Office CELEX 32024R2847 Art. 13(19) · verified 2026-09-05
- 10EU Publications Office CELEX 32024R2847 recital 60 · verified 2026-09-05
- 11European Commission C(2026) 5252 annex paragraphs 133 to 135, ec.europa.eu · verified 2026-09-05
- 12European Commission C(2026) 5252 annex paragraph 128, ec.europa.eu · verified 2026-09-05
- 13EU Publications Office CELEX 32024R2847 Annex VII point 4 · verified 2026-09-05
- 14EU Publications Office CELEX 32024R2847 Art. 52(16) · verified 2026-09-05
- 15EU Publications Office CELEX 32024R2847 Art. 13(8) and Annex I Part II · verified 2026-09-05
- 16European Commission C(2026) 5252 annex paragraph 238, ec.europa.eu · verified 2026-09-05
- 17EU Publications Office CELEX 32024R2847 Annex I Part II point (4) · verified 2026-09-05
- 18EU Publications Office CELEX 32024R2847 Art. 13(9) · verified 2026-09-05
- 19EU Publications Office CELEX 32024R2847 Art. 14(1) and 14(3) · verified 2026-09-05
- 20EU Publications Office CELEX 32024R2847 Annex II points 7 and 8 · verified 2026-09-05
- 21EU Publications Office CELEX 32024R2847 Art. 13(13) and 13(18) · verified 2026-09-05
- 22EU Publications Office CELEX 32024R2847 Art. 13(23) · verified 2026-09-05
- 23EU Publications Office CELEX 32024R2847 Art. 71(1) · verified 2026-09-05
- 24EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-05
- 25EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
- 26EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
- 27ISO/SAE 21434:2021 clause 14.1, licensed copy · verified 2026-09-05
- 28ISO/SAE 21434:2021 clause 7.4.3, licensed copy · verified 2026-09-05
- 29EU Publications Office CELEX 42025X0005 para. 7.2.2.5 · verified 2026-09-05
- 30ISO/SAE 21434:2021 clause 8.6, licensed copy · verified 2026-09-05
- 31EU Publications Office CELEX 42025X0005 paras. 7.2.2.1 and 7.2.2.2 · verified 2026-09-05
- 32ISO/SAE 21434:2021 clause 14.3, licensed copy · verified 2026-09-05
- 33EU Publications Office CELEX 32024R2847 Art. 13(11) · verified 2026-09-05
- 34ISO/SAE 21434:2021 clause 14.4, licensed copy · verified 2026-09-05
- 35ISO/IEC 27002:2022 controls 5.20, 5.22, 7.14, 8.8 and 8.32, licensed copy · verified 2026-09-05
- 36EU Publications Office CELEX 32024R2847 · verified 2026-09-05
- 37European Commission C(2026) 5252 annex, ec.europa.eu · verified 2026-09-05
- 38EU Publications Office CELEX 42025X0005 · verified 2026-09-05
- 39ISO/SAE 21434:2021, licensed copy · verified 2026-09-05
- 40ISO/IEC 27002:2022, licensed copy · verified 2026-09-05
Related
- Choosing the CRA conformity route
Playbook
- Governing security in the product organisation
Engagement pattern
- IEC 62443 for governance people
Briefing