Support and maintenance

Can a CRA support period be shorter than five years?

A shorter period needs a genuinely shorter expected use time and a documented basis. An ordinary commercial warranty is not the same thing as the CRA support commitment.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A manufacturer compares a device expected to be used for eight years with a short-life product expected to be used for three. Both are initially assigned three years of support. The expected-use evidence creates different assessments even though the proposed support number is identical.

Facts that change the answer

  • How long can users reasonably be expected to use the product?
  • Does the proposed period match that expected use?
  • If it is below five years, is the shorter-use basis documented?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Eight years of expected use; three years of support

Hypothetical example 1

Assessment resultsupport period too short

Recalculate the support period. It must reflect expected use and is at least five years unless expected use is shorter, in which case it must match that shorter expected use time.(CRA Article 13(8); Commission 2026 guidance section 5)

Key facts in this example
Reasonably expected use time in years
8
All recorded assumptions (18)
Product with digital elements
Hypothetical example product
Reasonably expected use time in years
8
Declared support period in years
3
The under-five-year support period matches a genuinely shorter expected use time and its basis is documented
Yes
Reasonable user expectations, product nature and purpose, relevant Union law and other applicable Article 13(8) factors are documented
Yes
The support-period end date is disclosed clearly and accessibly at purchase and in the required user information
Yes
The information used to determine the support period is included in the technical documentation
Yes
End-of-support notification to users
planned or not technically feasible
Vulnerabilities and components are identified and documented, including a machine-readable software bill of materials covering at least top-level dependencies
Yes
Internal and external vulnerability intake, a coordinated vulnerability-disclosure policy and a vulnerability-reporting contact are in place
Yes
Integrated-component vulnerabilities are reported to maintainers and remediated, with relevant fix code or documentation shared where appropriate
Yes
Security updates are made available without delay, separately from functionality updates where technically feasible, and free of charge unless the tailor-made-product exception applies
Yes
Updates are distributed securely with accessible information on purpose, effect and user action
Yes
Effective and regular security tests and reviews continue during the support period
Yes
Fixed-vulnerability information is shared and publicly disclosed, subject to the justified security-delay exception
Yes
Article 13(10) latest-version-only remediation route
not used
Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
Yes
Public software archive position
no public archive maintained

Three-year expected use with documented shorter-life basis

Hypothetical example 2

Assessment resultsupport record ready for review
Key facts in this example
Reasonably expected use time in years
3
All recorded assumptions (18)
Product with digital elements
Hypothetical example product
Reasonably expected use time in years
3
Declared support period in years
3
The under-five-year support period matches a genuinely shorter expected use time and its basis is documented
Yes
Reasonable user expectations, product nature and purpose, relevant Union law and other applicable Article 13(8) factors are documented
Yes
The support-period end date is disclosed clearly and accessibly at purchase and in the required user information
Yes
The information used to determine the support period is included in the technical documentation
Yes
End-of-support notification to users
planned or not technically feasible
Vulnerabilities and components are identified and documented, including a machine-readable software bill of materials covering at least top-level dependencies
Yes
Internal and external vulnerability intake, a coordinated vulnerability-disclosure policy and a vulnerability-reporting contact are in place
Yes
Integrated-component vulnerabilities are reported to maintainers and remediated, with relevant fix code or documentation shared where appropriate
Yes
Security updates are made available without delay, separately from functionality updates where technically feasible, and free of charge unless the tailor-made-product exception applies
Yes
Updates are distributed securely with accessible information on purpose, effect and user action
Yes
Effective and regular security tests and reviews continue during the support period
Yes
Fixed-vulnerability information is shared and publicly disclosed, subject to the justified security-delay exception
Yes
Article 13(10) latest-version-only remediation route
not used
Each security update remains available for at least ten years after issue or the remaining support period, whichever is longer
Yes
Public software archive position
no public archive maintained

Evaluated on 2026-09-13 using EU Cyber Resilience Act support-period and vulnerability-handling record, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Expected-use and user-expectation rationale
  • Declared support period and purchase information
  • Technical-documentation reference supporting the chosen period

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Review the expected life before publishing a support end date. Retain the basis and the ongoing vulnerability-handling arrangements together.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations