The best supplier clauses map directly to operational dependencies. They ensure the manufacturer receives the information and cooperation needed to manage component risk throughout the product lifecycle instead of discovering after an incident that the contract contains no security obligations.
Contracts Should Support, Not Replace, CRA Responsibility
The manufacturer remains responsible for its CRA obligations even where a supplier performs security work. Contract clauses should therefore secure evidence, communication and remediation support rather than claim to transfer statutory responsibility wholesale.
Require Timely Vulnerability Notification
Define how and when the supplier must notify the manufacturer of vulnerabilities affecting supplied components, including affected versions, severity information, exploitation status and available mitigations or fixes.
Require Component and Dependency Information
Where relevant, require enough package, dependency and version information to support the manufacturer's product SBOM, vulnerability analysis and technical documentation. A supplier-generated SBOM can be an input but does not replace the finished-product SBOM.
Define Security-Update Expectations
Address how quickly critical security updates should be provided, which versions are supported, how fixes are tested and how emergency updates are communicated. Operational targets should be realistic for the component's risk and integration complexity.
Document Support and End-of-Life Notice
Require clear support periods and advance notice of end of support where possible. This gives the manufacturer time to migrate before a critical dependency becomes unsupported during the product support period.
Control Security-Relevant Changes
Require notice of material changes to component architecture, dependencies, cryptography, build process or security behaviour that could affect the finished product's cybersecurity risk or conformity evidence.
Include Incident and Regulatory Cooperation
Critical suppliers should cooperate with incident investigation, evidence requests, root-cause analysis and remediation where their component may be involved. This helps the manufacturer meet authority and reporting obligations with accurate technical information.
Plan for Supplier Exit
Address access to source, build materials, documentation, replacement support or transition assistance where loss of the supplier could jeopardise vulnerability handling. The exact mechanism should reflect component criticality and commercial feasibility.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.