The situation
A vendor plans to retire its download service when a product’s support ends. Some security updates would disappear much earlier than the required availability period. The team must account for update issue dates, remaining support and any public archive’s unsupported-version information.
Facts that change the answer
- Does each update remain available for the required period after issue?
- Is the remaining support period longer?
- Does a public archive clearly explain the risks of unsupported versions?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Issued updates will not remain available long enough
Hypothetical example 1
Plan for each issued security update to remain available for at least ten years after issue or for the remaining support period, whichever is longer.(CRA Article 13(9))
Key facts in this example
- Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
- No
- Public software archive position
- no public archive maintained
All recorded assumptions (17)
- Product with digital elements
- Hypothetical example product
- Reasonably expected use time in years
- 7
- Declared support period in years
- 7
- Reasonable user expectations, product nature and purpose, relevant Union law and other applicable Article 13(8) factors are documented
- Yes
- The support-period end date is disclosed clearly and accessibly at purchase and in the required user information
- Yes
- The information used to determine the support period is included in the technical documentation
- Yes
- End-of-support notification to users
- planned or not technically feasible
- Vulnerabilities and components are identified and documented, including a machine-readable software bill of materials covering at least top-level dependencies
- Yes
- Internal and external vulnerability intake, a coordinated vulnerability-disclosure policy and a vulnerability-reporting contact are in place
- Yes
- Integrated-component vulnerabilities are reported to maintainers and remediated, with relevant fix code or documentation shared where appropriate
- Yes
- Security updates are made available without delay, separately from functionality updates where technically feasible, and free of charge unless the tailor-made-product exception applies
- Yes
- Updates are distributed securely with accessible information on purpose, effect and user action
- Yes
- Effective and regular security tests and reviews continue during the support period
- Yes
- Fixed-vulnerability information is shared and publicly disclosed, subject to the justified security-delay exception
- Yes
- Article 13(10) latest-version-only remediation route
- not used
- Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
- No
- Public software archive position
- no public archive maintained
Unsupported archive lacks risk information
Hypothetical example 2
Key facts in this example
- Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
- Yes
- Public software archive position
- archive maintained without required risk information
All recorded assumptions (17)
- Product with digital elements
- Hypothetical example product
- Reasonably expected use time in years
- 7
- Declared support period in years
- 7
- Reasonable user expectations, product nature and purpose, relevant Union law and other applicable Article 13(8) factors are documented
- Yes
- The support-period end date is disclosed clearly and accessibly at purchase and in the required user information
- Yes
- The information used to determine the support period is included in the technical documentation
- Yes
- End-of-support notification to users
- planned or not technically feasible
- Vulnerabilities and components are identified and documented, including a machine-readable software bill of materials covering at least top-level dependencies
- Yes
- Internal and external vulnerability intake, a coordinated vulnerability-disclosure policy and a vulnerability-reporting contact are in place
- Yes
- Integrated-component vulnerabilities are reported to maintainers and remediated, with relevant fix code or documentation shared where appropriate
- Yes
- Security updates are made available without delay, separately from functionality updates where technically feasible, and free of charge unless the tailor-made-product exception applies
- Yes
- Updates are distributed securely with accessible information on purpose, effect and user action
- Yes
- Effective and regular security tests and reviews continue during the support period
- Yes
- Fixed-vulnerability information is shared and publicly disclosed, subject to the justified security-delay exception
- Yes
- Article 13(10) latest-version-only remediation route
- not used
- Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
- Yes
- Public software archive position
- archive maintained without required risk information
Evaluated on 2026-09-13 using EU Cyber Resilience Act support-period and vulnerability-handling record, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Update issue dates and retention schedule
- Hosting and availability responsibility
- Archive notices and supported-version guidance
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Review the download-retention policy separately from the support end date. Article 13(9) uses at least ten years after issue or remaining support, whichever is longer.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Article 13(6)–(11); Annex I Part II; Annex II point 7
- European Commission CRA implementation guidance (2026)Section 5 — support period and substantial modifications
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.