Most of the Cyber Resilience Act's text is about the system that surrounds a product: notified bodies, market surveillance, delegated acts, the single reporting platform. The part a software manufacturer has to act on is much shorter, and most of it sits in one article. Article 13, "Obligations of manufacturers", has twenty-five paragraphs, and reading them in order is the fastest way to know what the Regulation asks of a company that ships software. Twenty-one of them are duties, two are options a manufacturer may take, and two belong to the Commission and the market surveillance authorities. The free page lists every one of the eighty-five rows the Regulation puts on a manufacturer, an importer, a distributor or an open-source software steward, in the Official Journal's words in the reader's language, with a status per row; this article is the reading that goes with it.
Paragraphs 1 to 7: the product and its components
Paragraph 1 is the whole Regulation in a sentence: a product placed on the market has to be designed, developed and produced in accordance with the essential cybersecurity requirements of Part I of Annex I. Paragraphs 2 to 4 are the risk assessment that decides how: undertaken for the product, documented and kept up to date during the support period, based on the intended purpose and the reasonably foreseeable use, saying which of the Part I point 2 properties apply and how, and included in the technical documentation with a clear justification for every requirement judged not applicable. Paragraph 5 is due diligence on components sourced from third parties, open-source ones included, so that they do not compromise the product; paragraph 6 is what to do on finding a vulnerability in such a component: report it to whoever maintains the component, remediate it under Part II, and share the fix where one was developed. Paragraph 7 asks for the systematic documentation of the product's cybersecurity aspects, the vulnerabilities the manufacturer learns of and the information third parties provide, and for the risk assessment to be updated when that changes.
Paragraphs 8 to 11: the support period and the updates
Paragraph 8 is the longest and carries three separate duties. First, vulnerabilities are handled effectively for the support period, under the eight requirements of Part II of Annex I. Second, the support period is determined by the manufacturer to reflect the time the product is expected to be in use, at least five years unless the expected use is shorter, with the reasoning kept in the technical documentation. Third, the manufacturer has policies and procedures, the coordinated vulnerability disclosure policy among them, to process and remediate vulnerabilities reported from inside and outside. Paragraph 9 keeps each security update available for ten years after it is issued or for the rest of the support period, whichever is longer. Paragraphs 10 and 11 are the two options: a manufacturer that has placed substantially modified versions of a software product on the market may meet the Part II point 2 remediation requirement for the latest version only, provided users of the earlier versions get the latest one free of charge and without adjusting their environment; and it may maintain public archives of historical versions as long as users are clearly told the risks of using unsupported software.
Paragraphs 12 to 20: the file, the marking and what accompanies the product
Paragraph 12 is the conformity sequence: the technical documentation of Article 31 drawn up before placing on the market, the conformity assessment of Article 32 carried out, the EU declaration of conformity drawn up under Article 28 and the CE marking affixed under Article 30. Paragraph 13 keeps the documentation and the declaration at the disposal of the market surveillance authorities for at least ten years or the support period, whichever is longer. Paragraph 14 wants procedures so that series production stays in conformity when the process, the design or the harmonised standards change. Paragraphs 15 and 16 are identification: a type, batch or serial number, and the manufacturer's name, address and contact details on the product, its packaging or a document with it. Paragraph 17 is the single point of contact users can reach directly, including to report vulnerabilities, not limited to automated tools. Paragraph 18 is the information and instructions of Annex II, in a language users understand, kept for ten years; paragraph 19 the end date of the support period stated at purchase, at least month and year, with a notification when the product reaches it where feasible; paragraph 20 the declaration of conformity, or its simplified form with an address, supplied with the product.
Paragraphs 21 to 25: when something is wrong, and the two that are not yours
Paragraph 21 is the corrective duty: a manufacturer that knows or has reason to believe the product or its processes no longer conform takes the corrective measures immediately, withdrawing or recalling where appropriate. Paragraph 22 answers a reasoned request from a market surveillance authority with the information that demonstrates conformity, in a language the authority understands, and cooperates on the measures taken. Paragraph 23 is easy to miss: a manufacturer that ceases operations and can no longer comply informs the authorities and, as far as possible, the users before the cessation takes effect. The last two paragraphs are not the manufacturer's. Paragraph 24 lets the Commission specify the format and elements of the software bill of materials by implementing act, and paragraph 25 lets the market surveillance authorities request the bill of materials from manufacturers of a product category when ADCO, the administrative cooperation group, runs a Union-wide dependency assessment; the fourth subparagraph of paragraph 8 likewise lets the Commission set minimum support periods for product categories by delegated act. None of these is a row on the checklist until the act or the request exists.
Beyond Article 13: the rows the page adds
Article 13 is not the whole list. Article 14 adds the reporting duties, the actively exploited vulnerability and the severe incident each with an early warning within 24 hours, a notification within 72 hours and a final report, the first 14 days after a corrective measure is available and the second one month after the notification, all via the single reporting platform to the CSIRT coordinator of the manufacturer's main establishment. Annex I adds the twenty-two requirements the product and its processes must meet, which is where "not applicable" needs the paragraph 4 justification. Articles 19 and 20 give an importer and a distributor their own shorter lists, Article 21 turns either into a manufacturer when it sells under its own name or substantially modifies the product, Article 22 does the same for anyone else who modifies substantially, Article 23 asks every operator to name its suppliers and customers for ten years, and Article 24 gives an open-source software steward a cybersecurity policy, cooperation with the authorities and the Article 14 duties to the extent of paragraph 3. Article 69 keeps products placed before 11 December 2027 out of the Regulation until substantially modified, except for Article 14, which applies to all of them from 11 September 2026. The free page holds these eighty-five rows by role with a status and an evidence line each, the scope tool says which role you play, the deadline calculator runs the Article 14 clocks, and the Annex I mapping says which of the requirements an ISO 27001 system runs the process for.