Cyber Resilience Act decision examples
CRA support and maintenance
Record expected use, dependency support and ongoing vulnerability handling. Compare worked examples and the evidence behind each CRA assessment.
Can the support commitment be maintained?
Open a situation to compare the relevant facts, worked results and evidence to retain.
Can a CRA support period be shorter than five years?
A shorter period needs a genuinely shorter expected use time and a documented basis. An ordinary commercial warranty is not the same thing as the CRA support commitment.
View facts and examplesWhat happens when a dependency loses support before your product?
A component’s upstream end-of-support date does not by itself shorten the product’s commitment. The manufacturer needs a workable vulnerability-handling plan for the remaining period.
View facts and examplesHow long should CRA security updates remain available?
Update availability and active product support are separate commitments. The record must cover the retention period for each issued security update.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.