Independent information resource Product security · EU CRA
CRA software supply chain / 11

CRA Security Clauses for Software Suppliers

Contract topics manufacturers can use with software and component suppliers to support CRA vulnerability handling, SBOM evidence, support, updates, change control and regulatory cooperation.

IN BRIEF

The best supplier clauses map directly to operational dependencies. They ensure the manufacturer receives the information and cooperation needed to manage component risk throughout the product lifecycle instead of discovering after an incident that the contract contains no security obligations.

01 / 08

Contracts Should Support, Not Replace, CRA Responsibility

The manufacturer remains responsible for its CRA obligations even where a supplier performs security work. Contract clauses should therefore secure evidence, communication and remediation support rather than claim to transfer statutory responsibility wholesale.

02 / 08

Require Timely Vulnerability Notification

Define how and when the supplier must notify the manufacturer of vulnerabilities affecting supplied components, including affected versions, severity information, exploitation status and available mitigations or fixes.

03 / 08

Require Component and Dependency Information

Where relevant, require enough package, dependency and version information to support the manufacturer's product SBOM, vulnerability analysis and technical documentation. A supplier-generated SBOM can be an input but does not replace the finished-product SBOM.

04 / 08

Define Security-Update Expectations

Address how quickly critical security updates should be provided, which versions are supported, how fixes are tested and how emergency updates are communicated. Operational targets should be realistic for the component's risk and integration complexity.

05 / 08

Document Support and End-of-Life Notice

Require clear support periods and advance notice of end of support where possible. This gives the manufacturer time to migrate before a critical dependency becomes unsupported during the product support period.

06 / 08

Control Security-Relevant Changes

Require notice of material changes to component architecture, dependencies, cryptography, build process or security behaviour that could affect the finished product's cybersecurity risk or conformity evidence.

07 / 08

Include Incident and Regulatory Cooperation

Critical suppliers should cooperate with incident investigation, evidence requests, root-cause analysis and remediation where their component may be involved. This helps the manufacturer meet authority and reporting obligations with accurate technical information.

08 / 08

Plan for Supplier Exit

Address access to source, build materials, documentation, replacement support or transition assistance where loss of the supplier could jeopardise vulnerability handling. The exact mechanism should reflect component criticality and commercial feasibility.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.