Obligations
The CRA support period: five years, or the expected use time
Published . Reviewed against Regulation (EU) 2024/2847, OJ L, 20.11.2024.
Most CRA summaries mention the support period in a single line and move on. It deserves more room, because it is the one requirement that reaches into pricing, roadmaps and end-of-life notices rather than into a document nobody outside the compliance file will read.
What a support period actually is
It is not a warranty and it is not a service-level commitment. The CRA defines it as the window in which vulnerability handling is owed.
“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I” (Art. 3, point (20), 'support period', CELEX 32024R2847)
The obligation it holds open is the one in Article 13.
“vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements” (Art. 13, vulnerability handling, CELEX 32024R2847)
So the support period is a duration attached to a duty. Everything else about it follows from that.
The floor is five years
“the support period shall be at least five years” (Art. 13(8), CELEX 32024R2847)
Five years, counted from the moment the product is placed on the market, which the Regulation defines as the first making available of the product on the Union market. Not from the customer's purchase date, not from the last release. The clock is per product on the market, not per contract.
The exception, and its limit
There is one way down from five years, and it is narrower than teams hope.
“Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.” (Art. 13(8), CELEX 32024R2847)
The test is expected use time, not intended sales window, not the term of your subscription, not how long you would prefer to maintain the code. If the product is realistically in service for seven years, a three-year support period is not available to you because you would rather not fund it. If it is truly a two-year device, two years is the answer, and the reasoning behind that expectation is worth writing down at the time you set it, not reconstructing later.
| Situation | Expected use time | Support period under Art. 13(8) |
|---|---|---|
| Business software with long deployments | Ten years | At least five years |
| Consumer app with annual releases | Six years | At least five years |
| Short-life connected device | Three years | Three years, the expected use time |
| No documented expectation | Not determined | Not addressed by Art. 13(8); our reading is to apply the five-year floor |
What has to happen during the period
Two things run for the whole duration.
Vulnerabilities are handled. That is the definition itself: effective handling, in line with Annex I Part II, for the whole period. In practice that means the ability to ship a security update to the installed base for as long as the period lasts, which is an engineering commitment before it is a compliance one.
The technical documentation stays current.
“The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period.” (Art. 31(2), CELEX 32024R2847)
The support period therefore sets the lifetime of the Annex VII technical documentation, not just of the patches.
It has to be declared, not just decided
A support period that exists only in an internal roadmap does not do the job. The period is declared to users, which is why Cybiq's compliance pack produces a support-period statement as a separate document: the determined period, the date it ends, the reasoning where the expected use time is shorter than five years, and where the statement is published.
Once it is published it is a commitment you have made in public, which is the point of the requirement.
What five years does to pricing and end-of-life
Three consequences, in the order teams usually hit them:
- Perpetual and one-time licences carry a tail. A single payment now funds at least five years of security maintenance. That is a cost of goods sold, and it belongs in the price rather than in next year's surprise.
- End-of-life notices get a floor. You cannot end-of-life a product out of its support period. Discontinuing sales is fine. Discontinuing vulnerability handling before the declared period ends is not.
- Old versions accumulate. Every release still inside its period is a branch you can ship a fix to. Support-period arithmetic is usually the argument that finally shortens a company's release matrix.
Products already on the market
The support period is an Article 13 requirement, so the transitional rule applies to it.
“Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.” (Art. 69(2), CELEX 32024R2847)
A product placed on the market before 11 December 2027 does not acquire a declared support period on that date. It acquires one if it is substantially modified afterwards, which the Regulation defines as a change following placing on the market that affects the product's compliance with the Annex I Part I essential requirements, or that changes the intended purpose it was assessed for.
One duty does reach back regardless, and it is not this one.
“By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.” (Art. 69(3), CELEX 32024R2847)
Article 14 reporting applies to the existing catalogue from 11 September 2026. The support period does not. Keeping those two apart saves a lot of unnecessary work on legacy releases.
Orientation, not legal advice. Verify against the official text before relying on any item.