Independent information resource Product security · EU CRA
CRA software supply chain / 10

Supplier Security Assessments for CRA Products

A practical framework for assessing software and component suppliers under the Cyber Resilience Act, including evidence, support, vulnerability handling, provenance and change control.

IN BRIEF

Supplier review should be risk based. A low-impact utility package does not need the same depth of assessment as a security-critical cryptographic module, identity component or remote-management subsystem, but every dependency should have enough evidence for its risk profile.

01 / 08

Start With Component Criticality

Assess the security importance of the component before deciding how deeply to review its supplier. Consider privileges, network exposure, data handled, update path, replaceability and the consequences of supplier failure.

02 / 08

Verify Component Identity and Provenance

Confirm what product or package the supplier is providing, how releases are identified and how the manufacturer can verify that the component received is the expected one. Ambiguous provenance weakens both SBOM accuracy and vulnerability response.

03 / 08

Review Vulnerability Disclosure and Response

Check whether the supplier has a monitored security contact, a vulnerability disclosure process, a history of advisories and a defined route for notifying customers of affected versions and fixes.

04 / 08

Assess Security-Update Capability

Review how security patches are created, tested, distributed and supported. Critical suppliers should be able to provide timely information that lets the manufacturer assess and remediate finished-product impact.

05 / 08

Check Support and End-of-Life Commitments

Understand how long the supplier plans to support the component and what happens when support ends. This is particularly important where replacement would require major redesign or conformity work.

06 / 08

Request Evidence Proportionate to Risk

Useful evidence can include security development practices, testing summaries, conformity information where applicable, component inventories, advisories, support policies and architecture documentation. Avoid collecting large questionnaires that are never evaluated.

07 / 08

Assess Change-Control Communication

Suppliers should provide enough notice of security-relevant component, dependency, firmware or manufacturing changes for the product manufacturer to reassess risk and update its evidence.

08 / 08

Make Supplier Assessment Ongoing

Reassess critical suppliers when major vulnerabilities, ownership changes, support changes, quality failures or material product changes occur. CRA supply-chain due diligence should remain active during the product lifecycle.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.