Cyber Resilience Act
Support period
Legal definition Art. 3(20) CRA
“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I”
The support period answers the question of how long a manufacturer stands behind the security of its product. It starts at the placing on the market and covers the whole of vulnerability handling under Annex I, Part II.
It is therefore not a service level or a maintenance contract, but a statutory obligation with a clearly stated floor.
How the period is determined
Article 13(8) of the Cyber Resilience Act (CRA) sets the direction: manufacturers determine the support period so that it reflects the duration for which the product is expected to be in use. The provision separates what manufacturers have to take into account from what they may take into account in addition
- Mandatory: reasonable user expectations.
- Mandatory: the nature of the product, including its intended purpose.
- Mandatory: relevant Union law determining the lifetime of products with digital elements.
- Optional: the support periods of products offering a similar functionality placed on the market by other manufacturers, the availability of the operating environment, and the support periods of integrated components that provide core functions and are sourced from third parties.
- Optional: relevant guidance from the administrative cooperation group (ADCO) and Commission guidelines.
Independently of all that: at least five years. Where the product is expected to be in use for less than five years, the support period must correspond to that expected use time.
Why five years is rarely the right answer
The five-year mark is often read as a target. The regulation suggests the opposite: it is the floor, and the actual requirement is the real duration of use. For mainboards, routers or operating systems, realistic service life sits well above it, and so do user expectations.
Setting the period too tightly invites not only a discussion with a market surveillance authority but also hands competitors an argument.
What has to be delivered during that time
Throughout the period, vulnerabilities must be handled effectively. That means identified, documented, fixed, and users informed. The cybersecurity risk assessment is likewise documented during this time and updated where necessary.
That is why the support period matters commercially: it determines how long a product keeps generating cost after the revenue has been booked.
Communicating it
The period is not an internal figure. Users need to know how long they can expect security updates. Under Annex II, point 7 the end date belongs with the information that accompanies the product, and Article 13(19) requires it to be indicated clearly at the time of purchase in an easily accessible manner, with at least the month and the year. The information taken into account when determining the period goes, under Article 13(8), into the technical documentation set out in Annex VII.
The reasoning itself is therefore part of the documentation: a number without a justification anyone can follow is not enough.
Practical questions
-
No, they are the floor. Article 13(8) requires the period to reflect how long the product is expected to be used, and then names five years as the minimum. For products that stay in service longer, such as network equipment or operating systems, a longer period is the logical consequence. Where the product is expected to be in use for less than five years, the period must correspond to that expected use time.
-
Once communicated, the figure is a commitment to users and the market that purchasing decisions rely on. Cutting it retroactively would sit badly with the very expectations the determination is meant to reflect. Extending it, by contrast, is possible at any time. If in doubt, set it conservatively. Correcting downwards is the problematic direction.
-
The problem stays with you. The CRA explicitly names the support periods of integrated components that provide core functions and are sourced from third parties as a factor manufacturers may take into account when setting their own. It does not, however, shift responsibility. In practice: either secure maintenance contractually, or plan to replace the component.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.