Security updates under the Cyber Resilience Act

Security updates under the Cyber Resilience Act

The Cyber Resilience Act requires manufacturers to provide and maintain security updates throughout an appropriate support period. That obligation affects product planning, update delivery, technical documentation and supplier management.

What the CRA requires

The Cyber Resilience Act (CRA) requires manufacturers of products with digital elements to address and remediate vulnerabilities without delay, including by providing security updates. It also requires a coordinated vulnerability-disclosure policy, a contact address for vulnerability reports and a single point of contact through which users can communicate directly and rapidly with the manufacturer. Regulation (EU) 2024/2847

In practice, the requirements include:

  • remediating vulnerabilities without delay, including through security updates;
  • providing a route for reporting potential vulnerabilities;
  • distributing updates through secure mechanisms; and
  • making available security updates free of charge in the circumstances set out in the Regulation.

Security updates and functionality updates must be provided separately where this is technically feasible. This means users should be able to address a security issue without necessarily adopting a functionality update, where the product can support that separation.

Available security updates must be disseminated without delay and free of charge. The Regulation provides a limited exception where a manufacturer and a business user agree otherwise in relation to a tailor-made product with digital elements. That exception should not be assumed to apply to standard products. Regulation (EU) 2024/2847

How long updates must be developed

Manufacturers must determine a support period that reflects the time during which a product is expected to be in use. The support period is normally at least five years. However, where the product is expected to be used for less than five years, the support period corresponds to that shorter expected-use time. Regulation (EU) 2024/2847

The Regulation does not provide a simple formula for setting that period. Manufacturers may take account of the intended purpose of the product, reasonable user expectations, comparable products, the availability of the operating environment and the support periods for integrated third-party components that provide core functions. The information considered when setting the support period must be included in the technical documentation.

For a single product, this may appear manageable. Across a portfolio, it can become a long-term operational commitment. Manufacturers may need to assess vulnerabilities, build and test updates for older versions, maintain release capability and reach users of products already in service.

Ten-year availability for issued updates

The support period determines how long a manufacturer must develop security updates. A separate rule governs how long each issued update must remain available.

Every security update made available during the support period must remain available for at least ten years after it is issued, or for the remainder of the support period if that is longer. Regulation (EU) 2024/2847

These obligations work differently. The support period concerns the development of new updates. The availability rule concerns continued access to an update that has already been issued. An update released near the end of support may therefore need to remain accessible for many years after new development work has stopped.

This calls for update infrastructure that can outlast active development. Download services, update servers, signing arrangements and supporting documentation need to remain managed so that users can obtain an issued security update when required.

Aligning support across the supply chain

A manufacturer's ability to maintain its products depends in part on the components integrated into them. The CRA requires manufacturers to exercise due diligence when integrating third-party components so that those components do not compromise product cybersecurity. It also permits manufacturers to consider the support periods of core third-party components when determining the product support period. Regulation (EU) 2024/2847

That makes supplier support a practical planning issue. Manufacturers need sufficient information about component support, vulnerability management and update availability to meet their own obligations. The CRA does not prescribe particular supplier-contract wording, but supplier commitments and product support planning need to work together.

Accounting for security support

The requirement to provide security updates without charge changes the economics of lifecycle support. Security maintenance, testing, release operations and long-term update availability may need to be planned as part of the product lifecycle rather than treated as optional post-sale support.

The limited exception for tailor-made products agreed with business users does not remove the general obligation for products supplied more widely. Manufacturers should therefore distinguish carefully between security support, feature development and the contractual context in which a product is supplied.

Setting and documenting expected use

Expected use is central to the support period. A manufacturer should make a considered assessment of how long its product is expected to remain in use and document the information used to reach that assessment.

Comparable products, the product's intended purpose, user expectations, operating-environment availability and the support of core components can all be relevant. The assessment is not merely an internal planning exercise: the Regulation requires the supporting information to appear in the technical documentation. Regulation (EU) 2024/2847

Preparing for the application date

The CRA generally applies from 11 December 2027. Its Article 14 reporting obligations apply earlier, from 11 September 2026, but those reporting duties are distinct from the support and update obligations discussed here. Regulation (EU) 2024/2847

Before the general application date, manufacturers should ensure that their product lifecycle arrangements cover legacy build and test environments, secure update delivery, long-term availability of issued updates, documented support-period decisions and supplier support dependencies. The European Commission's manufacturer guidance provides additional lifecycle and post-market context, while the Regulation remains the authoritative legal text. European Commission CRA manufacturer guidance

Need help implementing cyber regulation?

Talk to Secuvi →