Article 13(8) ยท Regulation (EU) 2024/2847

How long is the support period under the CRA?

Verified against the Official Journal text on

The manufacturer sets the support period to reflect how long the product is expected to be in use, and it must be at least five years. Where a product is expected to be in use for less than five years, the support period matches that shorter expected use time. You document the reasoning in the technical documentation and state the end date, at least the month and year, at the time of purchase. Separately, each security update you issue must remain available for at least ten years after it is issued, or the remainder of the support period if that is longer.

Basis: Art. 13(8), Art. 13(9), Art. 13(19)

Judgment call: The five-year figure is a floor determined by expected use time; the Commission may set higher minimum support periods for specific product categories by delegated act where market data shows they are inadequate.

The five-year floor Art. 13(8)

The core rule is short. During the support period, the manufacturer must handle vulnerabilities effectively, and the support period must be at least five years. The only way it is shorter is where the product itself is expected to be in use for less than five years, in which case the support period corresponds to that expected use time. So five years is a floor for ordinary products, not a fixed number for every product.

How you determine it Art. 13(8)

You do not pick the number arbitrarily. The support period must reflect the length of time the product is expected to be in use, taking into account in particular reasonable user expectations, the nature of the product including its intended purpose, and relevant Union law on product lifetimes. You may also weigh the support periods of similar products, the availability of the operating environment, the support periods of integrated third-party components providing core functions, and guidance from ADCO and the Commission, all considered proportionately.

For specific product categories where market surveillance data suggests support periods are inadequate, the Commission may adopt delegated acts specifying a minimum support period. So the five-year floor can be raised by category over time.

Where it must be documented and shown Art. 13(8), Art. 13(19), Annex II (7)

The support period is both an internal record and a customer-facing fact. The information taken into account to determine it must be included in the technical documentation. And the end date of the support period, including at least the month and the year, must be clearly and understandably specified at the time of purchase, in an easily accessible manner and, where applicable, on the product, its packaging, or by digital means. The user information also states the end date and the type of security support offered.

The separate ten-year update-availability rule Art. 13(9)

Do not confuse the support period with the ten-year figure that also appears in Article 13. They are different rules. The support period is how long you actively handle vulnerabilities and provide security updates. The ten-year rule is about keeping updates reachable afterwards: each security update made available to users during the support period must remain available, after it has been issued, for a minimum of 10 years or for the remainder of the support period, whichever is longer.

In practice that means a security update issued near the end of a five-year support period may still need to be downloadable for a decade after it went out, well past the end of the support period itself.

What you must do

  • Set a support period of at least five years (or the shorter expected use time), determined on documented reasoning, and handle vulnerabilities effectively throughout it. (Art. 13(8))
  • State the end date of the support period, at least the month and year, at the time of purchase in an easily accessible manner. (Art. 13(19))
  • Keep each security update available for at least 10 years after it is issued, or the remainder of the support period if that is longer. (Art. 13(9))

Frequently asked

Is the CRA support period always five years?

No. It must be at least five years, but only where the product is expected to be in use for at least that long. If the expected use time is shorter, the support period corresponds to that shorter time. The Commission can also raise the minimum for some categories. (Art. 13(8))

Where do I have to publish the end date?

At the time of purchase, in an easily accessible manner, and where applicable on the product, its packaging, or by digital means. It must state at least the month and the year, and it also appears in the user information. (Art. 13(19), Annex II (7))

Is there a ten-year requirement in the CRA?

Yes, but it is not the support period. Each security update issued during the support period must remain available for at least 10 years after it is issued, or the remainder of the support period if longer. That is about update availability, not active support. (Art. 13(9))

Who decides how long the support period is?

The manufacturer, on documented reasoning about expected use time, user expectations, and the nature of the product. The Commission may set minimum support periods for specific categories where market data shows they are inadequate. (Art. 13(8))

The support period only binds manufacturers

The free Vexwatch Scope Checker confirms whether you are a manufacturer under the CRA and therefore have to set, document, and honour a support period for your product.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.