Obligations of manufacturers
Summary
Manufacturers must design/develop/produce products in accordance with Annex I Part I; conduct and document a cybersecurity risk assessment; exercise due diligence integrating third-party/open-source components; report and remediate vulnerabilities in integrated components; maintain vulnerability handling (incl. SBOM per Part II point 1) for at least a 5-year support period; draw up technical documentation and carry out conformity assessment before placing on the market; and keep records, a single point of contact, and user instructions for at least 10 years.
Read the full official text: https://www.cyberresilienceact.eu/regulation.html
← Article 6
Requirements for products with digital elements
Article 13 →
Software bill of materials (Art. 13(8)/(24), Annex I Part II point 1)
Track CRA article 13 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial