Obligations

The CRA support period: five years, or the expected use time

Published . Reviewed against Regulation (EU) 2024/2847, OJ L, 20.11.2024.

Most CRA summaries mention the support period in a single line and move on. It deserves more room, because it is the one requirement that reaches into pricing, roadmaps and end-of-life notices rather than into a document nobody outside the compliance file will read.

What a support period actually is

It is not a warranty and it is not a service-level commitment. The CRA defines it as the window in which vulnerability handling is owed.

“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I” (Art. 3, point (20), 'support period', CELEX 32024R2847)

The obligation it holds open is the one in Article 13.

“vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements” (Art. 13, vulnerability handling, CELEX 32024R2847)

So the support period is a duration attached to a duty. Everything else about it follows from that.

The floor is five years

“the support period shall be at least five years” (Art. 13(8), CELEX 32024R2847)

Five years, counted from the moment the product is placed on the market, which the Regulation defines as the first making available of the product on the Union market. Not from the customer's purchase date, not from the last release. The clock is per product on the market, not per contract.

The exception, and its limit

There is one way down from five years, and it is narrower than teams hope.

“Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.” (Art. 13(8), CELEX 32024R2847)

The test is expected use time, not intended sales window, not the term of your subscription, not how long you would prefer to maintain the code. If the product is realistically in service for seven years, a three-year support period is not available to you because you would rather not fund it. If it is truly a two-year device, two years is the answer, and the reasoning behind that expectation is worth writing down at the time you set it, not reconstructing later.

SituationExpected use timeSupport period under Art. 13(8)
Business software with long deploymentsTen yearsAt least five years
Consumer app with annual releasesSix yearsAt least five years
Short-life connected deviceThree yearsThree years, the expected use time
No documented expectationNot determinedNot addressed by Art. 13(8); our reading is to apply the five-year floor

What has to happen during the period

Two things run for the whole duration.

Vulnerabilities are handled. That is the definition itself: effective handling, in line with Annex I Part II, for the whole period. In practice that means the ability to ship a security update to the installed base for as long as the period lasts, which is an engineering commitment before it is a compliance one.

The technical documentation stays current.

“The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period.” (Art. 31(2), CELEX 32024R2847)

The support period therefore sets the lifetime of the Annex VII technical documentation, not just of the patches.

It has to be declared, not just decided

A support period that exists only in an internal roadmap does not do the job. The period is declared to users, which is why Cybiq's compliance pack produces a support-period statement as a separate document: the determined period, the date it ends, the reasoning where the expected use time is shorter than five years, and where the statement is published.

Once it is published it is a commitment you have made in public, which is the point of the requirement.

What five years does to pricing and end-of-life

Three consequences, in the order teams usually hit them:

Products already on the market

The support period is an Article 13 requirement, so the transitional rule applies to it.

“Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.” (Art. 69(2), CELEX 32024R2847)

A product placed on the market before 11 December 2027 does not acquire a declared support period on that date. It acquires one if it is substantially modified afterwards, which the Regulation defines as a change following placing on the market that affects the product's compliance with the Annex I Part I essential requirements, or that changes the intended purpose it was assessed for.

One duty does reach back regardless, and it is not this one.

“By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.” (Art. 69(3), CELEX 32024R2847)

Article 14 reporting applies to the existing catalogue from 11 September 2026. The support period does not. Keeping those two apart saves a lot of unnecessary work on legacy releases.

Run the free Cybiq check to see whether the support period applies to your product and from which date: six questions, about five minutes, no signup, every claim anchored word for word to the Official Journal. The CRA compliance pack (EUR 199) includes the support-period statement alongside the classification memo, the vulnerability-handling procedure, the SBOM policy and the Annex V declaration index.

Orientation, not legal advice. Verify against the official text before relying on any item.