CRA Article 13: Security Updates
Manufacturers must provide security updates for products with digital elements for a defined support period.
Last updated 2026-03-01
What Article 13 requires
Article 13 obliges manufacturers to:
- Provide security updates for the product's defined support period.
- Make updates available free of charge where the product was sold commercially.
- Inform users about update availability through documented channels.
Who it applies to
Any manufacturer placing a product with digital elements on the EU market, including integrators who ship third-party open-source components in commercial products.
Practical steps
- Maintain an SBOM for every supported product version.
- Monitor CVE feeds for components in your SBOM.
- Publish security advisories when critical fixes ship.
- Document your support lifecycle and end-of-support dates.