Cyber Resilience Act

Support period

Legal definition Art. 3(20) CRA

“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I”
Regulation (EU) 2024/2847, Art. 3(20) CRA

The support period answers the question of how long a manufacturer stands behind the security of its product. It starts at the placing on the market and covers the whole of vulnerability handling under Annex I, Part II.

It is therefore not a service level or a maintenance contract, but a statutory obligation with a clearly stated floor.

How the period is determined

Article 13(8) of the Cyber Resilience Act (CRA) sets the direction: manufacturers determine the support period so that it reflects the duration for which the product is expected to be in use. The provision separates what manufacturers have to take into account from what they may take into account in addition

  • Mandatory: reasonable user expectations.
  • Mandatory: the nature of the product, including its intended purpose.
  • Mandatory: relevant Union law determining the lifetime of products with digital elements.
  • Optional: the support periods of products offering a similar functionality placed on the market by other manufacturers, the availability of the operating environment, and the support periods of integrated components that provide core functions and are sourced from third parties.
  • Optional: relevant guidance from the administrative cooperation group (ADCO) and Commission guidelines.

Independently of all that: at least five years. Where the product is expected to be in use for less than five years, the support period must correspond to that expected use time.

Why five years is rarely the right answer

The five-year mark is often read as a target. The regulation suggests the opposite: it is the floor, and the actual requirement is the real duration of use. For mainboards, routers or operating systems, realistic service life sits well above it, and so do user expectations.

Setting the period too tightly invites not only a discussion with a market surveillance authority but also hands competitors an argument.

What has to be delivered during that time

Throughout the period, vulnerabilities must be handled effectively. That means identified, documented, fixed, and users informed. The cybersecurity risk assessment is likewise documented during this time and updated where necessary.

That is why the support period matters commercially: it determines how long a product keeps generating cost after the revenue has been booked.

Communicating it

The period is not an internal figure. Users need to know how long they can expect security updates. Under Annex II, point 7 the end date belongs with the information that accompanies the product, and Article 13(19) requires it to be indicated clearly at the time of purchase in an easily accessible manner, with at least the month and the year. The information taken into account when determining the period goes, under Article 13(8), into the technical documentation set out in Annex VII.

The reasoning itself is therefore part of the documentation: a number without a justification anyone can follow is not enough.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.