The support period is generally at least five years. Where the product is expected to be in use for less than five years, the support period corresponds to that expected use time. The manufacturer must document the information used to make the decision and communicate the end date clearly to users.
Start With the Length of Time the Product Is Expected to Be in Use
Article 13(8) requires the support period to reflect the length of time during which the product is expected to be in use. The decision should therefore begin with the actual product lifecycle rather than an arbitrary commercial support package. Manufacturers should consider how customers normally deploy, retain and replace the product and whether cybersecurity-relevant functions are likely to remain active throughout that period.
- Estimate expected product use.
- Consider normal deployment patterns.
- Consider replacement cycles.
- Document the resulting lifecycle assumption.
Consider Reasonable User Expectations
Article 13 expressly requires reasonable user expectations to be taken into account. Those expectations can differ significantly between product categories. Users may reasonably expect a long-lived industrial controller, network appliance or installed device to remain usable much longer than a short-lived digital accessory. Sales positioning, historical product support and the surrounding market can help inform what a reasonable user would expect.
- Review how the product is marketed.
- Review historical replacement patterns.
- Consider the relevant user group.
- Avoid support periods inconsistent with obvious product use.
Consider the Nature of the Product and Its Intended Purpose
The nature of the product and its intended purpose are mandatory Article 13 factors. Security support for embedded equipment, operating-system software, a connected consumer device and a short-lived specialist application can involve very different lifecycles. The manufacturer should consider whether the product performs a core infrastructure function, remains installed for long periods, controls physical processes or depends on continued network connectivity.
- Consider hardware and software characteristics.
- Consider intended purpose.
- Consider installation permanence.
- Consider cybersecurity consequences of long-term use.
Check Relevant Union Law Determining Product Lifetime
Article 13 also requires manufacturers to take into account relevant Union law determining the lifetime of products with digital elements. Product-specific legislation can therefore affect the support-period analysis. Teams responsible for CRA implementation should identify whether other applicable Union rules establish or materially influence the expected lifetime of the relevant product category rather than determining the support period in isolation.
- Identify other applicable Union legislation.
- Determine whether it affects product lifetime.
- Record the interaction in the support-period rationale.
- Escalate product-specific legal questions where necessary.
The General Minimum Is at Least Five Years
Article 13 states that, without prejudice to the product-use factors, the support period shall be at least five years. This is the general minimum rather than a universal statement that every product should receive exactly five years of support. If the expected use is longer, the support-period determination should reflect that longer expected lifecycle.
- Treat five years as the general minimum.
- Do not automatically stop the analysis at five years.
- Use a longer period where expected use supports it.
- Document the basis for the selected duration.
A Product Expected to Be Used for Less Than Five Years Can Have a Shorter Period
Article 13 contains a specific rule for products expected to be in use for less than five years. In that case, the support period corresponds to the expected use time. A manufacturer relying on a shorter expected use should therefore have evidence supporting that lifecycle assumption. The exception should not be treated as a general mechanism for choosing a short commercial support term for products that users are realistically expected to continue operating for longer.
- Establish that expected use is less than five years.
- Match support to the expected use time.
- Retain evidence supporting the shorter lifecycle.
- Avoid arbitrary shortening.
Comparable Products Can Provide Additional Evidence
When determining the support period, Article 13 allows manufacturers to consider support periods of products with similar functionality placed on the market by other manufacturers. Comparable products can provide useful market evidence, but they do not replace the manufacturer's own expected-use analysis. A competitor's unusually short support period does not automatically make the same period appropriate for another product.
- Identify genuinely comparable products.
- Review their support periods.
- Use comparisons as supporting evidence.
- Keep the product-specific analysis primary.
Consider Availability of the Operating Environment
Article 13 permits consideration of the availability of the operating environment. Software may depend on operating systems, runtimes, hardware platforms, cloud environments or other infrastructure. The manufacturer should consider whether that environment is expected to remain realistically available throughout the proposed support period and whether migration or compatibility planning can extend safe product use.
- Identify important platform dependencies.
- Review expected platform availability.
- Consider compatibility constraints.
- Document material lifecycle dependencies.
Integrated Components Can Influence the Support Decision
Manufacturers may consider the support periods of integrated components that provide core functions and are sourced from third parties. This can include operating systems, chipsets, security modules, important libraries or other core dependencies. Third-party support should inform product planning, but choosing an unsupported core component does not automatically eliminate the manufacturer's own CRA responsibilities. Component lifecycle risk should be considered before product release.
- Identify integrated components providing core functions.
- Record their support periods.
- Identify lifecycle gaps.
- Plan replacement, migration or other risk treatment where needed.
Consider ADCO and Commission Guidance
Article 13 permits manufacturers to consider relevant guidance from the CRA Administrative Cooperation Group, ADCO, and the European Commission. The Regulation also allows further action where market-surveillance data shows inadequate support periods for particular product categories. Manufacturers should therefore treat support-period determination as an area that may receive more category-specific guidance over time.
- Monitor ADCO guidance.
- Monitor Commission guidance.
- Review the support decision when relevant guidance changes.
- Keep product-category assumptions current.
Apply the Factors Proportionately
Article 13 requires the matters used to determine the support period to be considered in a manner that ensures proportionality. The depth of analysis can therefore reflect the nature and complexity of the product while still addressing the required factors. A simple product does not need unnecessary bureaucracy, but the final support period should remain explainable and supported by evidence.
- Use an analysis proportionate to the product.
- Address the required factors.
- Record material assumptions.
- Keep the conclusion explainable.
Document the Support-Period Rationale in Technical Documentation
Article 13 requires manufacturers to include in the technical documentation the information taken into account to determine the support period. A useful record can identify expected use, reasonable user expectations, product nature and intended purpose, relevant Union law and any additional factors such as comparable products, operating-environment availability or integrated component support. The record should explain the resulting duration rather than merely state an end date.
- Record the factors considered.
- Record supporting evidence.
- Record the selected duration.
- Keep the rationale with the technical documentation.
Communicate the End Date Clearly
Article 13(19) requires the end date of the support period, including at least the month and the year, to be clearly and understandably specified at the time of purchase in an easily accessible manner and, where applicable, on the product, its packaging or by digital means. Annex II point 7 also requires information about the type of technical security support and the end date during which users can expect vulnerabilities to be handled and to receive security updates.
- State at least the month and the year.
- Make the information clear at purchase.
- Identify the technical security support offered.
- Keep product and documentation information consistent.
Do Not Confuse the Support Period With Update Availability
The support period determines how long vulnerabilities must be handled effectively. Article 13(9) creates a separate rule for security updates already issued during that period: each such update must remain available for a minimum of 10 years after issuance or for the remainder of the support period, whichever is longer. The update-availability rule can therefore continue after the support period without extending the obligation to create new fixes indefinitely.
- Track vulnerability-handling support separately.
- Track availability of issued updates.
- Preserve historical security-update packages.
- Avoid treating the two periods as identical.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.