Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Manufacturer duties after market placement

Last updated:

Manufacturer duties after market placement

Placement is not the end of the obligation. The manufacturer must maintain conformity, respond to vulnerabilities and incidents and be able to correct affected versions across relevant countries.

Law — continuing duties

The manufacturer must:

If the manufacturer knows or has reason to believe that the product or its processes are not in conformity, it must immediately take corrective measures. Depending on the circumstances, bring the product into conformity, withdraw it or recall it. If the product presents a significant cybersecurity risk, immediately inform the market-surveillance authorities in Member States where it was made available, describing the non-conformity and measures taken.

Reporting from 11 September 2026

From Slovakia, start with the SK-CERT route page, which identifies the correct channel for an actively exploited vulnerability or severe product-security incident according to occurrence type and JISKB access:

Stage Deadline
Early warning without undue delay and within 24 hours of awareness
Fuller notification without undue delay and within 72 hours of awareness
Vulnerability final report no later than 14 days after a corrective or mitigating measure is available
Incident final report within one month after the 72-hour notification

Where needed to mitigate impact, inform affected users without undue delay about the event and measures they can take; where appropriate, inform all users. Assess parallel duties such as NIS2 separately.

Guidance — operating model

Run one controlled loop:

  1. Detect: CVD contact, threat monitoring, privacy-appropriate telemetry, suppliers and support.
  2. Triage: affected product/version, exploitability, active exploitation, severity, users and countries.
  3. Escalate: record awareness time, owner, legal clocks and parallel regimes.
  4. Correct: fix or mitigate, securely test and distribute, provide rollback and communication.
  5. Report and notify: update the submission according to the selected channel’s instructions and inform users and authorities when triggered.
  6. Learn: update risk, SBOM, documentation, tests, supplier requirements and future versions.

Readiness check

Page sources: CRA Articles 13(7)–(11), 13(14), 13(20)–(22), 14 and 16; Annex I Part II; Commission reporting page; ENISA SRP guidance and FAQ.