Module 5 of 8 · 45 min
Article 13: the manufacturer's lifecycle obligations
The full Article 13 duty set: risk assessment, component due diligence, the support period and its floors, technical documentation, identification details, and Annex II user information.
Learning objectives
- Sequence the Article 13 obligations across design, placement on the market, and the support period
- State the support-period rules: expected-use basis, five-year reference, ten-year update availability, public end date
- Explain component due diligence including upstream reporting for open-source components
- List what Annex II requires manufacturers to give users, and the ten-year documentation retention rule
- Determine when corrective action, recall, or withdrawal duties are triggered
Before the product ships
Article 13 obliges the manufacturer to design, develop and produce in accordance with Annex I Part I, on the basis of a documented cybersecurity risk assessment that is kept up to date and covers the whole lifecycle. When integrating components from third parties, including free and open-source components, the manufacturer must exercise due diligence so they do not compromise the product's security, and when it finds a vulnerability in such a component it must report it to the component's maintainer and, if it develops a fix, share the code. Before placing on the market, the manufacturer runs the applicable conformity assessment, draws up the Annex VII technical documentation and the EU Declaration of Conformity, and affixes the CE marking.
The support period
Vulnerabilities must be handled effectively for a support period that reflects the length of time the product is expected to be in use, and that must be no shorter than five years unless the product is expected to be in use for less. The end date must be stated at the time of purchase and made easily accessible. Independently of the support period's length, Article 13(9) requires each security update made available during the support period to remain available for at least ten years after that update was issued, or for the remainder of the support period, whichever is longer. The clock runs from the issue of each update, not from placing the product on the market, so an update shipped late in a long support period stays available well beyond the product's tenth year. Technical documentation must be kept at the disposal of authorities for at least ten years after placing on the market or for the support period, whichever is longer.
Three numbers with different jobs: 5 years is the support-period floor, 10 years is update availability after release, and 10 years (or the support period if longer) is documentation retention. Distractors swap them.
Identification and Annex II information
Products must carry a type, batch or serial number allowing identification, and the manufacturer's name, registered trade name or trademark, postal address, email address or other digital contact, and a single point of contact where users can report vulnerabilities and choose to communicate. Annex II sets the information and instructions to the user: the manufacturer's identity and contact, the single point of contact for reports, the product's intended purpose and essential functionality, known circumstances that may lead to significant cybersecurity risks, the internet address of the EU Declaration of Conformity, the type of technical security support and the support period end date, instructions for secure commissioning, secure use, installing updates, secure decommissioning, and where applicable where the SBOM can be accessed.
Series production and things going wrong
Procedures must ensure series production stays in conformity, accounting for changes in the development process, in components, and in the threat landscape. A manufacturer who considers or has reason to believe a shipped product is non-conforming must immediately take corrective measures to bring it into conformity, or where appropriate withdraw or recall it. Where the product presents a significant cybersecurity risk, the manufacturer must immediately inform the market surveillance authorities of the Member States where it was made available, and users must be informed about incidents and vulnerabilities as Article 14 requires. Ceasing operations does not erase duties: the manufacturer must inform the authorities and, to the extent possible, users.
Official sources for this module
Module 5 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.