Independent information resource Product security · EU CRA
CRA readiness, templates, tools and software / 11

CRA Supplier Security Questionnaire

A practical Cyber Resilience Act supplier security questionnaire for gathering third-party component, vulnerability, update, support, SBOM, secure development and security-contact information needed for manufacturer due diligence.

IN BRIEF

Ask only questions that feed product decisions. Link supplier answers to the component and product that depend on them, validate high-risk claims with evidence, and flag missing security contacts, unsupported components, weak vulnerability processes or unclear update commitments. Supplier assurance is an input to the manufacturer's cybersecurity risk assessment and vulnerability handling, not a substitute for them.

01 / 12

Identify the Supplier, Component and Product Relationship

Start with the legal supplier or maintainer, component name, version, licensing model and the manufacturer products that integrate it. A questionnaire that is not tied to a specific component is difficult to use in product risk and vulnerability work.

02 / 12

Ask About Secure Development Practices

Collect information about security design, code review, testing, dependency management, release controls and change management that is relevant to the supplied component. The manufacturer should use the answers to inform product risk rather than scoring the supplier in isolation.

03 / 12

Ask for a Monitored Vulnerability Contact

The manufacturer may need to communicate quickly when a vulnerability is identified in an integrated component. Record the supplier's monitored security contact, escalation path and expected response process.

04 / 12

Ask How Vulnerabilities Are Received and Remediated

Ask how the supplier validates reports, prioritises remediation, coordinates disclosure, tests fixes and communicates security updates. Request evidence or policy references for critical components instead of relying only on yes-or-no answers.

05 / 12

Ask for Component and Dependency Information

Where useful, ask whether the supplier can provide SBOM or dependency information, component identifiers and release-linked versions. This can improve the manufacturer's own SBOM quality and speed up vulnerability matching.

06 / 12

Ask About Security Update Delivery

Record how updates are authenticated, distributed and communicated, how quickly critical fixes can be released and whether the supplier supports older versions. These facts can affect the manufacturer's own vulnerability-handling and support commitments.

07 / 12

Ask About Support Commitments and End-of-Support

The supplier's support period is not automatically the finished product's CRA support period. Still, unsupported dependencies can create manufacturer risk. Record support timelines, end-of-support notice periods and options for extended support or replacement.

08 / 12

Ask About Known Security Limitations and Open Vulnerabilities

Request information about known unresolved vulnerabilities, compensating controls, security advisories and relevant product limitations. High-risk or unsupported issues should feed the manufacturer's Article 13 cybersecurity risk assessment.

09 / 12

Ask About Incident and Exploitation Notification

Define how the supplier will notify the manufacturer of active exploitation, severe security events or urgent vulnerability information affecting the component. Fast upstream communication can be essential because Article 14 deadlines run from the manufacturer's awareness.

10 / 12

Validate Critical Responses With Evidence

For higher-risk components, request policy documents, test reports, certification evidence, SBOM extracts, support statements or other records that support the supplier's answers. Supplier declarations should be treated as evidence inputs, not unquestioned proof.

11 / 12

Feed Supplier Answers Into Product Risk and Documentation

Store the questionnaire with the component record and link important answers to the product cybersecurity risk assessment, SBOM, vulnerability process and technical documentation. This prevents procurement evidence from becoming disconnected from the product it is meant to support.

12 / 12

Reassess Suppliers When Components or Support Change

Trigger review when the component changes materially, the supplier changes ownership or support terms, serious vulnerabilities emerge, security contacts fail or a previously supported version approaches end of support. Due diligence should remain current enough to support ongoing product decisions.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.