A vendor contract can improve access to security evidence and remediation support, but it does not transfer the CRA manufacturer's responsibility for the finished product. Component selection should therefore combine technical risk, supplier capability and lifecycle support.
Commercial Supply Does Not Remove Manufacturer Due Diligence
Buying a component from a commercial vendor does not make the finished-product manufacturer passive. Article 13 requires due diligence when integrating third-party components so that those components do not compromise product cybersecurity.
Use Available CRA Conformity Evidence Where Relevant
Recital 34 indicates that due diligence may include checking whether a component complies with the CRA where the component itself is subject to the Regulation. Product teams should still assess how the component behaves inside the finished product rather than treating supplier conformity as a blanket guarantee.
Review Security-Update History
A supplier's record of timely security fixes is important evidence of lifecycle capability. Components used in core product functions should have a support model capable of sustaining the manufacturer's own support-period commitments.
Monitor Vendor Advisories
Commercial suppliers often publish security bulletins, CVEs, release notes and end-of-life notices. These should feed the manufacturer's component vulnerability process and be mapped to the exact product releases using the component.
Contract for Timely Vulnerability Information
Where practical, supplier agreements should define vulnerability notification, patch timelines, support periods, component changes and access to relevant security evidence. Contract terms support operations but do not replace statutory responsibility.
Test Critical Components in Product Context
Supplier test reports may not cover the way the component is configured or exposed in the finished product. Risk-sensitive components can require additional integration, misuse-case and security testing by the manufacturer.
Track End-of-Life Commitments
Record supplier support and end-of-life dates for critical components. A commercial component that loses support early can create the same product risk as an abandoned open-source dependency.
Preserve Supplier Evidence With the Product Record
Store relevant supplier security documentation, component versions, support commitments, advisories and assessment decisions alongside the product's technical and supply-chain evidence so that the basis for component selection remains retrievable.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.