Software supply chain security under the CRA is a lifecycle process. It begins before integration with component due diligence and continues through release, vulnerability monitoring, remediation, security updates and the product support period. Supplier contracts and open-source maintainer activity can support that process, but they do not remove the manufacturer's responsibility for the finished product.
The Manufacturer Owns the Finished-Product Supply Chain Risk
A manufacturer cannot treat a third-party library, firmware package or commercial module as outside the CRA merely because another organisation created it. Article 13 requires due diligence when integrating third-party components so that those components do not compromise the cybersecurity of the product with digital elements.
Due Diligence Starts Before a Component Is Integrated
Recital 34 describes risk-based due diligence that can include checking CRA conformity where applicable, reviewing whether the component receives regular security updates, checking vulnerability databases and performing additional security testing. The level of review should reflect the nature and cybersecurity risk of the component rather than relying on one universal supplier questionnaire.
Free and Open-Source Components Are Included
Article 13(5) expressly includes free and open-source software components that have not been made available on the market in the course of a commercial activity. Manufacturers therefore need a defensible process for selecting and monitoring open-source dependencies even where there is no commercial vendor contract.
Component Vulnerabilities Must Be Treated as Product Vulnerabilities
The CRA vulnerability-handling requirements apply to the product in its entirety, including integrated components. When a component vulnerability affects the finished product, the manufacturer needs to determine affected versions, risk, remediation and security-update actions rather than waiting for the component supplier to solve the finished-product impact.
The Component Maintainer Must Be Informed
Article 13(6) requires a manufacturer that identifies a vulnerability in an integrated component to report it to the person or entity manufacturing or maintaining that component. This applies to open-source components as well as commercial components. Coordinated disclosure to the maintainer should be connected to the manufacturer's own remediation workflow.
Security Fixes May Need to Flow Back Upstream
Where the manufacturer develops a software or hardware modification to address a vulnerability in the component, Article 13 requires relevant code or documentation to be shared with the component manufacturer or maintainer where appropriate, in a machine-readable format where appropriate. The supply chain process therefore includes upstream coordination, not only downstream patching.
Support-Period Planning Depends on Component Support
Article 13 allows manufacturers to consider the support periods of integrated third-party components that provide core functions when determining the product support period. A dependency with a short or uncertain maintenance horizon can therefore create a product-lifecycle risk that should be addressed before release.
Component Evidence Should Be Versioned With the Product
A manufacturer should be able to identify which component version is present in each supported product release, where it came from, how it was assessed and whether known vulnerabilities affect it. This makes vulnerability triage and authority response faster and supports the technical documentation required by Annex VII.
Supply Chain Security Needs Cross-Functional Ownership
Engineering, product security and procurement each see different parts of the component lifecycle. A useful CRA control assigns owners for dependency approval, supplier evidence, SBOM generation, vulnerability monitoring, remediation, update release and end-of-life replacement so that no component falls between organisational boundaries.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.