Obligations of Manufacturers
Article 13 of the EU Cyber Resilience Act is the master obligations article for manufacturers. It applies in full to products placed on the EU market from 11 December 2027. The article contains 25 paragraphs covering the full product lifecycle. Paragraphs 1 to 4 cover design-phase requirements, the cybersecurity risk assessment, and technical documentation. Paragraphs 5 and 6 govern third-party component due diligence and upstream vulnerability reporting. Paragraphs 7 and 8 mandate cybersecurity documentation, vulnerability handling processes, support periods, and coordinated vulnerability disclosure policies. Paragraphs 9 to 11 govern security update availability, modified software versions, and public archives. Paragraphs 12 to 14 require conformity assessment, CE marking, record retention, and series production controls. Paragraphs 15 to 20 set requirements for product identification, manufacturer contacts, user instructions, and declarations of conformity. Paragraphs 21 to 23 cover corrective measures, authority cooperation, and ceasing operations. Paragraphs 24 and 25 address software bills of materials format specifications and market surveillance authority requests.