The CRA support date should be a clear product-security fact, not a hidden lifecycle assumption. Users need to know how long vulnerabilities will be handled and security updates provided, and they should be able to see the support end date before or at purchase.
Communicate the Type of Technical Security Support
Annex II point 7 requires the type of technical security support offered by the manufacturer. The statement should focus on cybersecurity support, such as vulnerability handling and security updates, rather than relying only on broad customer-service language. Users should be able to distinguish security support from ordinary product help, warranty service or feature development.
- Describe vulnerability-handling support.
- Describe security-update support.
- Separate security support from general customer service.
- Use product-specific language.
State the Support End Date Clearly
Annex II point 7 requires the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be provided. The date should be tied to the identifiable product or product version so users are not left to infer support from a general corporate policy that may cover several different lifecycles.
- State the support end date.
- Tie it to the correct product.
- Keep the date consistent across sales and support materials.
- Update public records when an officially extended period is adopted.
Article 13(19) Requires at Least the Month and Year
Article 13(19) requires the support-period end date to include at least the month and the year. A statement such as five years of support can be useful context but does not replace the need for a clear calendar end date once the applicable period is known.
- Provide at least month and year.
- Avoid only relative duration language.
- Keep the date readable without calculation.
- Use the same date in product and support records.
Make the Date Available at the Time of Purchase
Article 13(19) requires the support end date to be clearly and understandably specified at the time of purchase in an easily accessible manner. For online sales, that can require placing the information where a customer can reasonably find it before completing the purchase rather than burying it in post-purchase documentation.
- Make the date easily accessible at purchase.
- Avoid post-purchase-only disclosure.
- Keep retailer or marketplace information aligned where the manufacturer controls it.
- Use clear language rather than lifecycle jargon.
Use Product, Packaging or Digital Means Where Applicable
Article 13(19) says the end date should also be specified, where applicable, on the product, its packaging or by digital means. The appropriate method depends on the product, but the result should make the security-support horizon easy to identify throughout the product lifecycle.
- Product marking where appropriate.
- Packaging information where appropriate.
- Digital product information.
- Durable online support records.
Do Not Confuse the Support Period With Warranty
The CRA support period concerns vulnerability handling and security updates. A commercial warranty can be shorter, longer or governed by different legal rules. Manufacturers should avoid wording that causes customers to think cybersecurity support ends when a hardware warranty expires if the CRA support period continues beyond it.
- Label security support separately.
- Keep warranty wording distinct.
- Avoid using warranty expiry as the security-support date unless it actually matches.
- Train support teams on the distinction.
Do Not Confuse Support Duration With Availability of Issued Updates
Article 13(9) creates a separate availability rule for security updates already issued during the support period. Those updates must remain available for at least 10 years after issuance or for the remainder of the support period, whichever is longer. Communication should therefore avoid implying that all previously issued security updates disappear when active support ends.
- Separate active support from historical update availability.
- Preserve access to issued updates for the required period.
- Explain historical update locations where users need them.
- Avoid misleading end-of-support messages.
Keep Support Information Consistent Across Channels
Support dates often appear on product pages, packaging, account portals, knowledge bases and reseller listings. Inconsistent dates can create compliance and customer confusion. The manufacturer should maintain a controlled support record and use it as the source for public communication.
- Maintain one controlled support record.
- Synchronise product and support pages.
- Correct outdated reseller information where possible.
- Retain historical support statements.
Plan End-of-Support Communication Before the Final Date
Article 13(19) addresses purchase-time visibility, but good security communication also requires operational preparation as the date approaches. Manufacturers can remind users of the support end date, identify supported migration options and distinguish the end of new vulnerability handling from any continued availability of previously issued updates.
- Plan advance reminders.
- Identify migration options.
- Explain what changes at end of support.
- Keep historical update availability clear.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.