Independent information resource Product security · EU CRA
User information and security communications

CRA User Information and Product Security Communications

A practical guide to Cyber Resilience Act user information and product security communications, including Article 13, Annex II, vulnerability contacts, support periods, secure-use instructions, security updates, known risks and decommissioning guidance.

IN BRIEF

CRA user information is part of product cybersecurity, not a packaging afterthought. The manufacturer must give users enough information to identify the product, understand its intended security environment, report vulnerabilities, operate it securely, install security updates, understand support limits and decommission it safely.

01 / 10

Article 13 Makes Annex II User Information a Manufacturer Obligation

Article 13(18) requires products with digital elements to be accompanied by the information and instructions set out in Annex II. The information can be supplied in paper or electronic form, but it must be clear, understandable, intelligible and legible. It must also allow users to install, operate and use the product securely. This makes user-facing security information part of the CRA compliance system rather than optional product documentation.

  • Provide Annex II information with the product.
  • Use a language users and market surveillance authorities can easily understand.
  • Keep the information clear and legible.
  • Support secure installation, operation and use.
02 / 10

Users Need Clear Manufacturer and Vulnerability Contacts

Annex II requires manufacturer identification and contact information, including the postal address and an email address or other digital contact. It also requires the single point of contact where information about product vulnerabilities can be reported and received and where the manufacturer's coordinated vulnerability disclosure policy can be found. Article 13(17) separately requires that single point of contact to be easily identifiable by users.

  • Manufacturer name or registered trade identity.
  • Postal and digital contact information.
  • Single vulnerability-reporting point of contact.
  • Location of the coordinated vulnerability disclosure policy.
03 / 10

The Product Must Be Uniquely Identifiable

Annex II requires the name and type of the product together with additional information enabling unique identification. Product security communications depend on this precision because users need to know whether a security advisory, update or support notice applies to the exact product they operate. Version, model, build or platform information can be necessary where a broad commercial product name covers several technically different products.

  • Product name and type.
  • Model, version or build where relevant.
  • Platform or hardware revision where relevant.
  • Identifiers consistent with security advisories and updates.
04 / 10

Explain Intended Purpose, Security Environment and Security Properties

Annex II requires the intended purpose of the product, including the security environment provided by the manufacturer, together with the product's essential functionalities and information about its security properties. This gives users the context needed to understand the conditions under which the product is designed to operate securely. A secure-use instruction is much more useful when it explains the assumed environment rather than presenting isolated configuration steps.

  • Intended purpose.
  • Manufacturer-provided security environment.
  • Essential product functions.
  • Relevant security properties.
05 / 10

Communicate Known or Foreseeable Cybersecurity Risk Circumstances

Annex II requires information about known or foreseeable circumstances related to intended use or reasonably foreseeable misuse that may lead to significant cybersecurity risks. This is not a generic instruction to list every theoretical threat. The manufacturer should identify material circumstances users need to understand in order to avoid or reduce significant cybersecurity risk during real product use.

  • Known risk-producing use conditions.
  • Reasonably foreseeable misuse.
  • Important environmental assumptions.
  • User actions that materially reduce risk.
06 / 10

Support Information Must Include the End Date

Annex II requires the type of technical security support offered by the manufacturer and the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be provided. Article 13(19) reinforces this by requiring the support-period end date, including at least the month and year, to be clearly and understandably specified at the time of purchase in an easily accessible manner.

  • Describe technical security support.
  • State the support-period end date.
  • Include at least month and year.
  • Make the date accessible at purchase.
07 / 10

Detailed Security Instructions Must Cover the Product Lifecycle

Annex II requires detailed instructions or an internet address pointing to them. The required topics cover secure commissioning and use throughout the product lifetime, the security effect of product changes, installation of security-relevant updates, secure decommissioning and secure removal of user data, and control of the default automatic security-update setting. Products intended for integration into other products also need information that helps integrators meet CRA requirements.

  • Secure commissioning and lifetime use.
  • Security impact of product changes.
  • Security-relevant update installation.
  • Secure decommissioning and data removal.
  • Automatic security-update control.
  • Integrator information where applicable.
08 / 10

Online User Information Has a Long Availability Requirement

Article 13(18) requires Annex II information and instructions to remain available to users and market surveillance authorities for at least 10 years after the product is placed on the market or for the support period, whichever is longer. Where the information is supplied online, it must remain accessible, user-friendly and available online for the same period. Documentation URLs should therefore be treated as long-lived product-security infrastructure.

  • Retain information for the longer applicable period.
  • Keep online documentation accessible.
  • Avoid breaking historical documentation links.
  • Preserve version-specific instructions where products differ.
09 / 10

User Information Is Different From Internal Technical Documentation

Annex II is user-facing, while Annex VII technical documentation is primarily evidence supporting conformity and regulatory review. The two should be consistent, but they serve different audiences. A risk decision or technical security control may be documented internally in detail while the corresponding user information explains only what users need to know to operate, update or decommission the product securely.

  • Keep internal evidence and user instructions consistent.
  • Do not expose unnecessary sensitive implementation details.
  • Translate technical decisions into actionable user guidance.
  • Update both records when product security assumptions change.
10 / 10

Treat Product Security Communication as a Maintained System

CRA user information should be maintained across product releases rather than written once before launch. Product changes can alter secure configuration, support dates, known risks, update paths and decommissioning instructions. Manufacturers should assign ownership for user-facing security information and connect updates to engineering, product security, support and release-management processes.

  • Assign documentation ownership.
  • Review information after security-relevant product changes.
  • Synchronise advisories, support dates and update instructions.
  • Retain historical information for affected versions.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.