Independent information resource Product security · EU CRA
CRA software supply chain / 09

CRA Security Requirements for Commercial Components

How Cyber Resilience Act manufacturer due diligence applies to commercial software, firmware and hardware components, including supplier evidence, updates, vulnerabilities and lifecycle support.

IN BRIEF

A vendor contract can improve access to security evidence and remediation support, but it does not transfer the CRA manufacturer's responsibility for the finished product. Component selection should therefore combine technical risk, supplier capability and lifecycle support.

01 / 08

Commercial Supply Does Not Remove Manufacturer Due Diligence

Buying a component from a commercial vendor does not make the finished-product manufacturer passive. Article 13 requires due diligence when integrating third-party components so that those components do not compromise product cybersecurity.

02 / 08

Use Available CRA Conformity Evidence Where Relevant

Recital 34 indicates that due diligence may include checking whether a component complies with the CRA where the component itself is subject to the Regulation. Product teams should still assess how the component behaves inside the finished product rather than treating supplier conformity as a blanket guarantee.

03 / 08

Review Security-Update History

A supplier's record of timely security fixes is important evidence of lifecycle capability. Components used in core product functions should have a support model capable of sustaining the manufacturer's own support-period commitments.

04 / 08

Monitor Vendor Advisories

Commercial suppliers often publish security bulletins, CVEs, release notes and end-of-life notices. These should feed the manufacturer's component vulnerability process and be mapped to the exact product releases using the component.

05 / 08

Contract for Timely Vulnerability Information

Where practical, supplier agreements should define vulnerability notification, patch timelines, support periods, component changes and access to relevant security evidence. Contract terms support operations but do not replace statutory responsibility.

06 / 08

Test Critical Components in Product Context

Supplier test reports may not cover the way the component is configured or exposed in the finished product. Risk-sensitive components can require additional integration, misuse-case and security testing by the manufacturer.

07 / 08

Track End-of-Life Commitments

Record supplier support and end-of-life dates for critical components. A commercial component that loses support early can create the same product risk as an abandoned open-source dependency.

08 / 08

Preserve Supplier Evidence With the Product Record

Store relevant supplier security documentation, component versions, support commitments, advisories and assessment decisions alongside the product's technical and supply-chain evidence so that the basis for component selection remains retrievable.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.