Manufacturer obligations under the CRA
The manufacturer has primary responsibility for the cybersecurity of a product with digital elements—from planning, design and development through vulnerability handling during the declared support period. Securing a finished product just before market launch is not enough. The CRA requires an evidenced process across the lifecycle.
Key dates
- from 11 September 2026: Article 14 obligations to report actively exploited vulnerabilities and severe incidents apply;
- from 11 December 2027: most other CRA obligations apply, including the essential requirements, conformity assessment and CE marking;
- products placed on the market before 11 December 2027 become subject to the main CRA requirements if they undergo a substantial modification from that date; reporting duties nevertheless cover products already made available on the Union market.
1. Are you a manufacturer under the CRA?
Law
A manufacturer is a natural or legal person that develops or manufactures a product with digital elements, or has one designed, developed or manufactured, and markets it under its name or trademark—whether for payment, monetisation or free of charge.
An importer or distributor can also become subject to manufacturer obligations if it places a product on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market. After a substantial modification, the obligations apply to the affected part or, where the modification affects the cybersecurity of the product as a whole, to the entire product.
Practical scope check
Ask these questions for every product and model:
- Is it software, hardware or a component, including a remote data processing solution without which the product would not perform one of its functions?
- Does its intended or reasonably foreseeable use include a direct or indirect logical or physical data connection to a device or network?
- Is it supplied on the EU market in the course of a commercial activity, even if supplied free of charge?
- Does it bear your name or trademark, or did you have it developed or manufactured?
- Is it excluded from the CRA or governed by specific EU rules—for example certain medical devices, in-vitro diagnostic medical devices, motor vehicles, civil-aviation products, marine equipment, or products developed exclusively for national-security or defence purposes?
- Is the relevant code supplied as free and open-source software outside a commercial activity? An open-source licence alone does not create an automatic exemption.
If the first four answers are “yes” and no exclusion applies, you are likely a manufacturer under the CRA. Document borderline cases—including cloud functions, open source, white-label products, component bundles and modifications—and check them against the latest Commission guidance.
Guidance: The Commission’s final guidance of 27 July 2026 gives practical examples on remote data processing solutions, free and open-source software, substantial modification and interaction with other EU law. It is non-binding; the CRA and applicable sector legislation remain controlling.
2. What the manufacturer must put in place
Law — across the lifecycle
The manufacturer must, among other things:
- perform and document a product cybersecurity risk assessment and take it into account during planning, design, development, production, delivery and maintenance;
- design, develop and produce the product in accordance with the Annex I essential requirements, proportionate to identified risks;
- systematically document relevant cybersecurity aspects, including known vulnerabilities and relevant third-party information, and update the risk assessment where appropriate;
- exercise due diligence when integrating third-party components, including free and open-source software;
- ensure that series production remains in conformity and account for changes to the product, production process, standards and technical specifications;
- establish coordinated vulnerability disclosure (CVD), accept reports from internal and external sources, analyse them and remediate vulnerabilities without delay;
- securely distribute security updates without delay and free of charge, with clear user information; a different agreement is possible between a manufacturer and a business user for a tailor-made product;
- handle vulnerabilities in the product and its components effectively throughout the support period;
- monitor conformity after placement, take corrective action and, where appropriate, withdraw or recall the product;
- cooperate with market-surveillance authorities and provide information and documents demonstrating conformity upon a reasoned request.
Practical operating model
Product governance
- assign a CRA owner to each product line and involve engineering, security, quality, legal, procurement and support;
- maintain a record of versions, models, components, markets, support periods and accountable people;
- add a CRA release gate before placing a product or substantially modified version on the market.
Secure development
- connect threat modelling and risk assessment to the Annex I requirements;
- implement secure defaults, access control, confidentiality, integrity and availability protection, data and attack-surface minimisation, resilience and secure updates as appropriate to the risk;
- regularly test and review security, keeping test results, decisions and remediation evidence.
Supply chain
- maintain a machine-readable software bill of materials (SBOM) covering at least top-level dependencies;
- assess component provenance, support, known vulnerabilities, update terms and vulnerability contacts;
- when you identify a vulnerability in an integrated component, inform its manufacturer or maintainer and remediate it in your product. If you developed a component fix, share relevant code or documentation where appropriate.
3. Support period and security updates
Law
The support period must reflect the time for which the product is expected to be in use. Relevant factors include reasonable user expectations, the product’s nature and intended purpose, EU product-lifetime rules and, proportionately, support periods for similar products, availability of the operating environment, support for essential third-party components and relevant guidance.
The support period is at least five years. It may be shorter only where the product is expected to be in use for less than five years; it must then match that expected use time. Where reasonable use is longer, support should be longer than five years.
The manufacturer must:
- record in the technical documentation the information used to determine the support period;
- clearly state the support end date, at least month and year, at the time of purchase;
- where technically feasible in light of the product’s nature, notify users when support ends;
- keep each security update issued during support available for at least ten years after issue or for the remainder of the support period, whichever is longer.
Guidance: Five years is not a default target for every product. It is a legal minimum with a narrow exception for products whose expected use is shorter. The decision must be proportionate, justified and auditable.
4. Technical documentation and records
Law
Technical documentation must be prepared before the product is placed on the market and kept continuously updated where appropriate, at least during the support period. It must contain the information needed to demonstrate that the product and the manufacturer’s processes meet Annex I, including at least the Annex VII elements:
- a general product description, intended purpose, versions and identification;
- design, development, production and vulnerability-handling processes;
- the cybersecurity risk assessment, including how Annex I applies;
- information used to determine the support period;
- applied harmonised standards, common specifications or certification schemes, or descriptions of other solutions;
- test and conformity-assessment results;
- the EU declaration of conformity;
- necessary vulnerability-handling information, including the SBOM; a market-surveillance authority may request the SBOM, but it does not have to be routinely disclosed to users.
Where other EU legislation also requires technical documentation, a single file may cover all applicable requirements.
Keep the technical documentation and EU declaration of conformity available to authorities for at least ten years after the product is placed on the market or for the support period, whichever is longer. Annex II user information and instructions must remain available to users and authorities for the same period; online information must stay accessible and user-friendly.
Set up supply-chain records so that, on request, you can identify the economic operator that supplied you and, where available, those to whom you supplied the product. Article 23 requires these identifiers to be retained for ten years after supply.
5. Conformity assessment, declaration and CE marking
Law
Before placing a product on the market, the manufacturer must:
- determine whether it is a default, important class I, important class II or critical product under Annexes III and IV and the implementing technical descriptions;
- select a permitted Article 32 conformity-assessment procedure;
- carry out, or have carried out, that assessment;
- once conformity is demonstrated, draw up and sign the Annex V EU declaration of conformity, or provide the Annex VI simplified declaration;
- affix CE marking in accordance with Articles 29 and 30;
- provide the required product identifiers, contacts and clear Annex II information and instructions.
Typical route selection
| Product category | Available route |
|---|---|
| Product outside the important and critical categories | internal control (module A), EU-type examination plus conformity to type (B + C), full quality assurance (H), or an applicable European cybersecurity certification scheme |
| Important product, class I | module A only where relevant harmonised standards/common specifications are fully applied, or an applicable certification scheme is used; otherwise third-party assessment (B + C or H) |
| Important product, class II | B + C or H; or an applicable European cybersecurity certification scheme |
| Critical product | B + C or H unless a delegated act requires an applicable European cybersecurity certification scheme |
For third-party assessment, use a body notified for the CRA and verify its authorised scope in NANDO. A notified body’s identification number follows the CE marking only for procedures in which that body participates in the production-control phase; it is not an automatic part of every CE mark.
Check before deciding: Classification depends on the product’s core functionality. Verify the current technical descriptions for important and critical categories, published harmonised standards and available certification schemes. Do not rely only on a product’s marketing name or an outdated comparison diagram.
6. Information supplied with the product
Law
The product must be identifiable by type, batch or serial number or another element. State the manufacturer’s name or registered trade name, postal address, email address or another digital contact and, where applicable, website.
Annex II information and instructions must be clear, understandable, intelligible and legible, in a language easily understood by users and authorities in the Member State concerned. They should cover, among other things:
- intended purpose and reasonably foreseeable use;
- essential functionality and security properties;
- secure installation, configuration, operation and use;
- product changes that may affect security;
- how to install security updates and the default setting for automatic updates;
- the contact point and coordinated vulnerability disclosure policy;
- circumstances or risks in which use may lead to significant cybersecurity risk;
- the support end date, at least month and year;
- access to the EU declaration of conformity where the simplified declaration is used.
7. Vulnerabilities, incidents and reporting
Law
The manufacturer must operate a process for receiving, triaging, analysing, documenting and remediating vulnerabilities. Once a security update is available, it must disclose information about the fixed vulnerability—the description and affected-product identification, severity and impact, and user remediation information—unless delaying disclosure is justified by a security risk.
From 11 September 2026, manufacturers must report the following occurrences under CRA Article 14. JISKB is Slovakia’s preferred route; select the correct entry point for your access and occurrence type through the SK-CERT route page. Direct SRP access is also available:
- an actively exploited vulnerability: reliable evidence shows that a malicious actor exploited it in a system without the system owner’s permission;
- a severe incident affecting product security: an incident meeting the Article 14(5) severity criteria.
| Stage | Deadline from the manufacturer becoming aware |
|---|---|
| Early warning | without undue delay and within 24 hours |
| Vulnerability or incident notification | without undue delay and within 72 hours |
| Final report — vulnerability | no later than 14 days after a corrective or mitigating measure becomes available |
| Final report — severe incident | within one month after the 72-hour notification |
The manufacturer continues the submission according to the selected channel’s instructions. Do not create duplicate reports for the same duty through the national route and direct SRP. The coordinator CSIRT is generally determined by the manufacturer’s main EU establishment. Assess in parallel whether the event triggers another reporting regime such as NIS2; CRA does not automatically replace other obligations.
Where needed to mitigate an actively exploited vulnerability or severe incident, the manufacturer must inform impacted users without undue delay about the event and measures they can take. Where appropriate, it must inform all users.
Preparation: Before an event occurs, appoint authorised reporters, verify both JISKB access and the no-access procedure, and rehearse the 24- and 72-hour process. Confirm the channel on the SK-CERT route page. If you use direct SRP access, prepare EU Login and two-factor authentication.
8. If the product is not in conformity
Law
If a manufacturer knows or has reason to believe that the product or its processes do not conform to the CRA, it must immediately take corrective measures. Depending on the circumstances, bring the product into conformity, withdraw it or recall it. If it presents a significant cybersecurity risk, immediately inform the market-surveillance authorities in Member States where it was made available, giving details of the non-conformity and measures taken.
Provide documentation and information in an easily understood language on a reasoned request and cooperate to eliminate the risk. Maintain a correction and recall process capable of reaching all affected versions and countries.
9. A practical 90-day plan
Guidance
- Build a product inventory. Record the owner, legal role, markets, versions, connections, components and expected use time.
- Decide scope and category. Store a reasoned CRA applicability and important/critical classification decision for each model.
- Gap-assess Annexes I, II and VII. Map every requirement to a control, evidence and owner.
- Establish PSIRT/CVD and SBOM. Define a secure contact, triage, records, remediation targets, disclosure and supplier information flow.
- Operate the reporting process that applies from 11 September 2026. Define awareness, escalation, representation, JISKB access and regularly rehearse the 24-/72-hour process.
- Set and disclose the support period. Justify it and align the product, supplier contracts, update infrastructure and sales information.
- Select the conformity route early. For important or critical products, reserve notified-body capacity and verify its scope.
- Prepare documentation, instructions, declaration and CE marking. Tie them to version control and the pre-market release gate.
- Exercise post-market response. Simulate a component vulnerability, severe incident, corrective update and possible recall.
Pre-market quick check
This content is general information, not legal advice or confirmation that a particular product conforms.