← EU Cyber Resilience Act for Manufacturers

Module 5 of 8 · 45 min

Article 13: the manufacturer's lifecycle obligations

The full Article 13 duty set: risk assessment, component due diligence, the support period and its floors, technical documentation, identification details, and Annex II user information.

Learning objectives

  • Sequence the Article 13 obligations across design, placement on the market, and the support period
  • State the support-period rules: expected-use basis, five-year reference, ten-year update availability, public end date
  • Explain component due diligence including upstream reporting for open-source components
  • List what Annex II requires manufacturers to give users, and the ten-year documentation retention rule
  • Determine when corrective action, recall, or withdrawal duties are triggered

Before the product ships

Article 13 obliges manufacturers to design, develop, and produce products in accordance with Annex I Part I. This work is based on a documented cybersecurity risk assessment that covers the whole lifecycle.

Manufacturers must exercise due diligence when integrating third-party and open-source components. When a manufacturer identifies a component vulnerability, it must report the issue to the maintainer and share any developed fixes.

Before placing a product on the market, the manufacturer completes the applicable conformity assessment. The team draws up Annex VII technical documentation and the EU Declaration of Conformity, then affixes the CE marking.

The support period

Manufacturers must handle vulnerabilities effectively throughout the declared support period. The support period reflects the time the product is expected to remain in use, with a five-year floor unless shorter use is justified.

The support end date must be clearly stated at the time of purchase. Article 13(9) requires every released security update to remain available for at least ten years from its release date, or for the remainder of the support period.

Technical documentation must remain available to authorities for at least ten years after placing the product on the market, or for the duration of the support period if longer.

Three numbers with different jobs: 5 years is the support-period floor, 10 years is update availability after release, and 10 years (or the support period if longer) is documentation retention. Distractors swap them.

Identification and Annex II information

Products must carry identifying numbers, including type, batch, or serial identifiers. Manufacturers must display their name, trade name, physical address, digital contact, and a single point of contact for vulnerability reports.

Annex II specifies user instructions. Required details include manufacturer contacts, intended purpose, essential functions, known risk scenarios, the EU Declaration of Conformity web address, and the support end date.

Instructions must also guide secure setup, daily use, update installation, decommissioning, and where to access the SBOM when applicable.

Series production and things going wrong

Manufacturers must maintain procedures that ensure ongoing series production stays in conformity. These procedures must track changes in design, components, and the threat environment.

If a shipped product is non-conforming, the manufacturer must immediately take corrective measures, withdraw, or recall the product.

When a product presents significant cybersecurity risks, the manufacturer must inform national market surveillance authorities immediately. Ceasing commercial operations does not remove these compliance duties.

Module 5 quiz

10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.

Enroll and confirm your email to take the quiz.

Apply this to your product

The modules teach the obligations in the abstract. These two tools answer them for a product you actually place on the market, and neither needs an account.