CEMarque

How long must I provide security updates under the Cyber Resilience Act?

Last verified 19 September 2026 · Facts v2026.09.4

The support period is the length of time you handle vulnerabilities in the product after sale — and the Regulation makes you declare it, rather than prescribing a single number for everyone.

You determine the period, but under two constraints: it must reflect the time the product is reasonably expected to be in use, and it must be at least five years unless the product is genuinely expected to be used for a shorter time [1]. The end date, to the month and year, is stated at the time of purchase [1]. If a security update ends up delivered near or after the end of the period, its own availability window is also constrained, so the period cannot be quietly shortened by delivering one last patch and switching everything off [1].

What "support" means in practice

During the period you are on the hook for the vulnerability-handling duties, not merely for good intentions. Security updates must be distributed securely, free of charge, in a timely manner, and accompanied by advisory messages [2]. For consumer products, security updates are installed automatically by default, with a clear and easy-to-use opt-out [3]. After a fix ships, information about the fixed vulnerability is publicly disclosed — description, affected products, impacts, severity, remediation [4].

The paperwork outlives the product

Two retention clocks run alongside the support period, and both can be longer than it.

Technical documentation and the EU declaration of conformity are kept for at least ten years after the product is placed on the market, or for the support period, whichever is longer [5]. The user information and instructions stay at the disposal of users and authorities for the same ten-years-or-support-period window, whichever is longer [6].

So a product sold once with a five-year support period can have a documentation obligation running a decade beyond the sale, because the ten-year floor starts at placing on the market [5]. Plan storage and ownership of those artefacts accordingly — "the developer who had them left" is not a defence.

Choosing a number

Most software vendors should start from five years and ask whether anything about the product justifies less, rather than the other way round, because the five-year floor is the default posture of the text [1]. Shorter periods are defensible for products with demonstrably short lives — a promotional app tied to an event, a game with a published end-of-service date. What is not defensible is picking a short period for a product customers will plainly keep using, because the period must reflect expected use time [1].

Remember also that the declared end date becomes a sales artefact: it is stated at purchase, so your customers and their procurement teams will see it and compare it [1]. A longer period is a selling point in exactly the way a longer warranty is.

These duties arrive with full application of the Regulation on 11 December 2027, so a product you place on the market after that date needs its period declared from day one [7].

Check where you stand

The checker asks about your product's expected life and tells you which duties attach and when, each with its citation.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. Support period: determined by the manufacturer to reflect the expected use time; at least five years unless the product is expected to be in use for less; the end date (month and year) is stated at purchase. A security update, once issued, remains available for at least ten years or the remainder of the support period, whichever is longer. Art. 13(8), (9), (19)EUR-Lex
  2. Manufacturers ensure secure distribution of updates and that security updates are provided free of charge, in a timely manner, with advisory messages. Annex I Part II(7)–(8)EUR-Lex
  3. Security updates are installed automatically by default for consumer products, with a clear and easy-to-use opt-out mechanism. Annex I Part I(2)(c), Recital 56EUR-Lex
  4. Manufacturers publicly disclose information about fixed vulnerabilities after a security update is available, including a description, affected products, impacts, severity and remediation information. Annex I Part II(4)EUR-Lex
  5. Technical documentation (Annex VII) is drawn up before placing on the market and kept, with the EU declaration of conformity, for at least ten years after placing on the market or the support period, whichever is longer. Art. 13(12)–(13), Art. 31EUR-Lex
  6. Manufacturers keep the user information and instructions (Annex II) at the disposal of users and authorities for at least ten years after placing on the market or for the support period, whichever is longer; a notification is displayed when the support period ends where technically feasible. Art. 13(18)–(19)EUR-Lex
  7. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex

Related

  • What are the CRA rules on security updates?

    Security updates must be free, timely, securely distributed and accompanied by advisories; consumer products install them automatically by default with an easy opt-out; and the duty runs for the whole declared support period.

  • Does the CRA require a coordinated vulnerability disclosure policy?

    Yes. Every manufacturer must have a coordinated vulnerability disclosure policy in place, a contact address for reports, a single point of contact for users, and a practice of publishing fixed vulnerabilities.

  • What goes in the CRA technical file?

    A technical file in the Annex VII structure — product description, design and vulnerability-handling documentation, risk assessment, SBOM, test reports — drawn up before market placement and kept for ten years or the support period.

  • What goes in a CRA declaration of conformity?

    A one-document statement, in the Annex V structure, in which the manufacturer takes sole responsibility that the product meets the essential requirements. A simplified web-linked form exists, and it travels with the product's paperwork for a decade or more.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.