Manufacturer duties after market placement
Placement is not the end of the obligation. The manufacturer must maintain conformity, respond to vulnerabilities and incidents and be able to correct affected versions across relevant countries.
Law — continuing duties
The manufacturer must:
- keep series production in conformity and account for changes to design, characteristics, production process, standards and specifications;
- handle product and component vulnerabilities effectively throughout support;
- systematically document vulnerabilities and relevant third-party information and update the risk assessment and technical file where appropriate;
- test and review security, provide secure updates and publish required fixed-vulnerability information;
- keep updates and user information available for the applicable periods;
- cooperate with market surveillance and demonstrate conformity on a reasoned request.
If the manufacturer knows or has reason to believe that the product or its processes are not in conformity, it must immediately take corrective measures. Depending on the circumstances, bring the product into conformity, withdraw it or recall it. If the product presents a significant cybersecurity risk, immediately inform the market-surveillance authorities in Member States where it was made available, describing the non-conformity and measures taken.
Reporting from 11 September 2026
From Slovakia, start with the SK-CERT route page, which identifies the correct channel for an actively exploited vulnerability or severe product-security incident according to occurrence type and JISKB access:
| Stage | Deadline |
|---|---|
| Early warning | without undue delay and within 24 hours of awareness |
| Fuller notification | without undue delay and within 72 hours of awareness |
| Vulnerability final report | no later than 14 days after a corrective or mitigating measure is available |
| Incident final report | within one month after the 72-hour notification |
Where needed to mitigate impact, inform affected users without undue delay about the event and measures they can take; where appropriate, inform all users. Assess parallel duties such as NIS2 separately.
Guidance — operating model
Run one controlled loop:
- Detect: CVD contact, threat monitoring, privacy-appropriate telemetry, suppliers and support.
- Triage: affected product/version, exploitability, active exploitation, severity, users and countries.
- Escalate: record awareness time, owner, legal clocks and parallel regimes.
- Correct: fix or mitigate, securely test and distribute, provide rollback and communication.
- Report and notify: update the submission according to the selected channel’s instructions and inform users and authorities when triggered.
- Learn: update risk, SBOM, documentation, tests, supplier requirements and future versions.
Readiness check
Page sources: CRA Articles 13(7)–(11), 13(14), 13(20)–(22), 14 and 16; Annex I Part II; Commission reporting page; ENISA SRP guidance and FAQ.