Manufacturers carry the main CRA duties. Article 13 and the annexes connect product design and production with risk assessment, documentation, conformity and vulnerability handling during the support period.

An editorial work plan; consult Article 13 and the annexes for the legal duties.
Before market placement
Perform and document a cybersecurity risk assessment. Use it to inform product design, development, production, delivery and maintenance. Apply relevant essential requirements and exercise due diligence with third-party components.
- Define product scope and intended use.
- Document risks and chosen security measures.
- Prepare technical documentation and user information.
- Perform the applicable conformity assessment before drawing up the declaration and affixing CE marking.
After market placement
Determine and communicate a support period. Handle vulnerabilities effectively during that period, provide security updates and meet applicable notification duties for actively exploited vulnerabilities and severe incidents.
Evidence is a continuous activity
Keep risk decisions, test findings, component records, user instructions, update plans and vulnerability records connected to the product version and support commitments.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.