Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Manufacturer obligations under the CRA

Last updated:

Manufacturer obligations under the CRA

The manufacturer has primary responsibility for the cybersecurity of a product with digital elements—from planning, design and development through vulnerability handling during the declared support period. Securing a finished product just before market launch is not enough. The CRA requires an evidenced process across the lifecycle.

Key dates

1. Are you a manufacturer under the CRA?

Law

A manufacturer is a natural or legal person that develops or manufactures a product with digital elements, or has one designed, developed or manufactured, and markets it under its name or trademark—whether for payment, monetisation or free of charge.

An importer or distributor can also become subject to manufacturer obligations if it places a product on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market. After a substantial modification, the obligations apply to the affected part or, where the modification affects the cybersecurity of the product as a whole, to the entire product.

Practical scope check

Ask these questions for every product and model:

  1. Is it software, hardware or a component, including a remote data processing solution without which the product would not perform one of its functions?
  2. Does its intended or reasonably foreseeable use include a direct or indirect logical or physical data connection to a device or network?
  3. Is it supplied on the EU market in the course of a commercial activity, even if supplied free of charge?
  4. Does it bear your name or trademark, or did you have it developed or manufactured?
  5. Is it excluded from the CRA or governed by specific EU rules—for example certain medical devices, in-vitro diagnostic medical devices, motor vehicles, civil-aviation products, marine equipment, or products developed exclusively for national-security or defence purposes?
  6. Is the relevant code supplied as free and open-source software outside a commercial activity? An open-source licence alone does not create an automatic exemption.

If the first four answers are “yes” and no exclusion applies, you are likely a manufacturer under the CRA. Document borderline cases—including cloud functions, open source, white-label products, component bundles and modifications—and check them against the latest Commission guidance.

Guidance: The Commission’s final guidance of 27 July 2026 gives practical examples on remote data processing solutions, free and open-source software, substantial modification and interaction with other EU law. It is non-binding; the CRA and applicable sector legislation remain controlling.

2. What the manufacturer must put in place

Law — across the lifecycle

The manufacturer must, among other things:

Practical operating model

Product governance

Secure development

Supply chain

3. Support period and security updates

Law

The support period must reflect the time for which the product is expected to be in use. Relevant factors include reasonable user expectations, the product’s nature and intended purpose, EU product-lifetime rules and, proportionately, support periods for similar products, availability of the operating environment, support for essential third-party components and relevant guidance.

The support period is at least five years. It may be shorter only where the product is expected to be in use for less than five years; it must then match that expected use time. Where reasonable use is longer, support should be longer than five years.

The manufacturer must:

Guidance: Five years is not a default target for every product. It is a legal minimum with a narrow exception for products whose expected use is shorter. The decision must be proportionate, justified and auditable.

4. Technical documentation and records

Law

Technical documentation must be prepared before the product is placed on the market and kept continuously updated where appropriate, at least during the support period. It must contain the information needed to demonstrate that the product and the manufacturer’s processes meet Annex I, including at least the Annex VII elements:

Where other EU legislation also requires technical documentation, a single file may cover all applicable requirements.

Keep the technical documentation and EU declaration of conformity available to authorities for at least ten years after the product is placed on the market or for the support period, whichever is longer. Annex II user information and instructions must remain available to users and authorities for the same period; online information must stay accessible and user-friendly.

Set up supply-chain records so that, on request, you can identify the economic operator that supplied you and, where available, those to whom you supplied the product. Article 23 requires these identifiers to be retained for ten years after supply.

5. Conformity assessment, declaration and CE marking

Law

Before placing a product on the market, the manufacturer must:

  1. determine whether it is a default, important class I, important class II or critical product under Annexes III and IV and the implementing technical descriptions;
  2. select a permitted Article 32 conformity-assessment procedure;
  3. carry out, or have carried out, that assessment;
  4. once conformity is demonstrated, draw up and sign the Annex V EU declaration of conformity, or provide the Annex VI simplified declaration;
  5. affix CE marking in accordance with Articles 29 and 30;
  6. provide the required product identifiers, contacts and clear Annex II information and instructions.

Typical route selection

Product category Available route
Product outside the important and critical categories internal control (module A), EU-type examination plus conformity to type (B + C), full quality assurance (H), or an applicable European cybersecurity certification scheme
Important product, class I module A only where relevant harmonised standards/common specifications are fully applied, or an applicable certification scheme is used; otherwise third-party assessment (B + C or H)
Important product, class II B + C or H; or an applicable European cybersecurity certification scheme
Critical product B + C or H unless a delegated act requires an applicable European cybersecurity certification scheme

For third-party assessment, use a body notified for the CRA and verify its authorised scope in NANDO. A notified body’s identification number follows the CE marking only for procedures in which that body participates in the production-control phase; it is not an automatic part of every CE mark.

Check before deciding: Classification depends on the product’s core functionality. Verify the current technical descriptions for important and critical categories, published harmonised standards and available certification schemes. Do not rely only on a product’s marketing name or an outdated comparison diagram.

6. Information supplied with the product

Law

The product must be identifiable by type, batch or serial number or another element. State the manufacturer’s name or registered trade name, postal address, email address or another digital contact and, where applicable, website.

Annex II information and instructions must be clear, understandable, intelligible and legible, in a language easily understood by users and authorities in the Member State concerned. They should cover, among other things:

7. Vulnerabilities, incidents and reporting

Law

The manufacturer must operate a process for receiving, triaging, analysing, documenting and remediating vulnerabilities. Once a security update is available, it must disclose information about the fixed vulnerability—the description and affected-product identification, severity and impact, and user remediation information—unless delaying disclosure is justified by a security risk.

From 11 September 2026, manufacturers must report the following occurrences under CRA Article 14. JISKB is Slovakia’s preferred route; select the correct entry point for your access and occurrence type through the SK-CERT route page. Direct SRP access is also available:

Stage Deadline from the manufacturer becoming aware
Early warning without undue delay and within 24 hours
Vulnerability or incident notification without undue delay and within 72 hours
Final report — vulnerability no later than 14 days after a corrective or mitigating measure becomes available
Final report — severe incident within one month after the 72-hour notification

The manufacturer continues the submission according to the selected channel’s instructions. Do not create duplicate reports for the same duty through the national route and direct SRP. The coordinator CSIRT is generally determined by the manufacturer’s main EU establishment. Assess in parallel whether the event triggers another reporting regime such as NIS2; CRA does not automatically replace other obligations.

Where needed to mitigate an actively exploited vulnerability or severe incident, the manufacturer must inform impacted users without undue delay about the event and measures they can take. Where appropriate, it must inform all users.

Preparation: Before an event occurs, appoint authorised reporters, verify both JISKB access and the no-access procedure, and rehearse the 24- and 72-hour process. Confirm the channel on the SK-CERT route page. If you use direct SRP access, prepare EU Login and two-factor authentication.

8. If the product is not in conformity

Law

If a manufacturer knows or has reason to believe that the product or its processes do not conform to the CRA, it must immediately take corrective measures. Depending on the circumstances, bring the product into conformity, withdraw it or recall it. If it presents a significant cybersecurity risk, immediately inform the market-surveillance authorities in Member States where it was made available, giving details of the non-conformity and measures taken.

Provide documentation and information in an easily understood language on a reasoned request and cooperate to eliminate the risk. Maintain a correction and recall process capable of reaching all affected versions and countries.

9. A practical 90-day plan

Guidance

  1. Build a product inventory. Record the owner, legal role, markets, versions, connections, components and expected use time.
  2. Decide scope and category. Store a reasoned CRA applicability and important/critical classification decision for each model.
  3. Gap-assess Annexes I, II and VII. Map every requirement to a control, evidence and owner.
  4. Establish PSIRT/CVD and SBOM. Define a secure contact, triage, records, remediation targets, disclosure and supplier information flow.
  5. Operate the reporting process that applies from 11 September 2026. Define awareness, escalation, representation, JISKB access and regularly rehearse the 24-/72-hour process.
  6. Set and disclose the support period. Justify it and align the product, supplier contracts, update infrastructure and sales information.
  7. Select the conformity route early. For important or critical products, reserve notified-body capacity and verify its scope.
  8. Prepare documentation, instructions, declaration and CE marking. Tie them to version control and the pre-market release gate.
  9. Exercise post-market response. Simulate a component vulnerability, severe incident, corrective update and possible recall.

Pre-market quick check

This content is general information, not legal advice or confirmation that a particular product conforms.