The support period is the CRA's answer to the question every buyer of software asks and few sellers answer in writing: for how long will you fix it? The Cyber Resilience Act, Regulation (EU) 2024/2847, makes the manufacturer determine that period, publish its end date at the point of sale, and deliver the vulnerability-handling requirements of Annex I, Part II for its whole length. Three other retention clocks hang off it.

The minimum: Article 13(8)

Article 13(8) requires manufacturers to determine the support period so that it "reflects the length of time during which the product is expected to be in use", taking into account reasonable user expectations, the nature of the product and its intended purpose, and relevant Union law on product lifetimes. It may also take into account the support periods of similar products from other manufacturers, the availability of the operating environment, the support periods of integrated third-party components that provide core functions, and guidance from the CRA's administrative cooperation group and the Commission.

Then the floor: "the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time."

So five years is the default minimum, and shorter is possible only where the product is genuinely expected to be used for less, which is a claim you have to be able to defend. The Commission may, by delegated act, set minimum support periods for specific product categories where market surveillance data shows periods are inadequate.

The information taken into account to determine the period goes into the technical documentation (Annex VII, point 4). A number without the reasoning behind it is the first thing a market surveillance authority asks about.

The end date, shown at purchase: Article 13(19) and Annex II

Article 13(19): the end date of the support period, "including at least the month and the year", must be "clearly and understandably specified at the time of purchase in an easily accessible manner" and, where applicable, on the product, its packaging or by digital means. Where technically feasible, the product must notify users when it reaches the end of its support period.

Annex II, point 7, puts the same fact into the user information that accompanies the product: the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and security updates provided.

For software sold online, "at the time of purchase" means on the page where the purchase decision is made, not in a PDF after payment.

Updates that outlive the period: Article 13(9)

Article 13(9): each security update made available during the support period must remain available after it is issued "for a minimum of 10 years or for the remainder of the support period, whichever is longer".

That is a distinct obligation from the support period itself. A product supported for five years, with a security update issued in year four, must keep that update available until year fourteen. Update servers, download pages and package repositories are a ten-year commitment from the last update, which is worth knowing before an infrastructure is chosen.

Article 13(10) offers relief for software with successive substantially modified versions: the manufacturer may meet the remediation requirement only for the latest version, provided earlier users can move to it free of charge and without extra cost to adjust their environment.

Everything else kept for the same length

Three more retention rules use the same formula, "10 years after the product has been placed on the market or for the support period, whichever is longer":

  • The technical documentation and the EU declaration of conformity, at the disposal of the national authorities (Annex VIII).
  • The user information and instructions of Annex II, at the disposal of users and authorities, and where provided online, kept accessible online (Article 13(18)).
  • The support period is also the length for which Article 13(8)'s vulnerability handling runs, and Article 14's reporting duty runs for as long as the product is on the market and supported.

What to write down

One paragraph per product, in the technical file and on the product page: the support period and its end date (month and year), the reasoning behind the length, the type of technical support offered, and where updates will remain available for ten years after each one. If the period is shorter than five years, the reasoning is the whole document.

Then the release process that makes it true: an update channel that does not disappear when a product line does, a notification at end of support where the product can show one, and a file that records the date each update was made available, because that date is also the anchor for the Article 14 final report.

Sources

  • Regulation (EU) 2024/2847, Article 13(8) (quoted), 13(9), 13(10), 13(18), 13(19); Annex II, point 7; Annex VII, point 4; Annex VIII Part I point 4.2 and Part II point 10; Article 71(2) for the dates. Read from the Official Journal text on EUR-Lex on 11 September 2026.

This is not legal advice. Article 13(8) and (9) are two paragraphs; read them before you print an end date on a product page.