FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA User Information and Transparency

Must fixed vulnerability information be publicly disclosed once a security update exists?

Yes, with an important timing qualification. Annex I Part II point 4 requires manufacturers, once a security update has been made available, to share and publicly disclose information about fixed vulnerabilities, including affected product identification, impact, severity, and clear remediation information.

The same point allows delayed public disclosure in duly justified cases where the manufacturer considers the security risks of publication to outweigh the security benefits, until users have had the possibility to apply the relevant patch. That makes patch availability, advisory wording, and customer notification timing part of the same transparency workflow.

Citations
Cyber Resilience Act

Annex I Part II point 4 covers public disclosure of fixed vulnerabilities and the justified-delay condition where publication risk outweighs security benefit.

CRA User Information and Transparency

Do users have a right to the full CRA technical documentation or risk assessment?

No general user publication duty appears in these provisions. The CRA requires manufacturers to draw up technical documentation, keep it available for market surveillance authorities, and update it where appropriate. Annex VII lists user information and instructions as part of the technical documentation, but it does not turn the whole technical file into a public user document.

For user-facing transparency, focus on the specific disclosures the CRA does require: Annex II instructions, support-period information, vulnerability contact details, EU declaration access where applicable, security-update advisories, fixed-vulnerability disclosures, and Article 14(8) user notices.

Citations
Cyber Resilience Act

Articles 13(12)-(13), Article 31, and Annex VII cover technical documentation for conformity and authority access; Annex II identifies the user-facing instruction set.

CRA User Information and Transparency

Does the CRA require access to the EU declaration of conformity?

Yes. The manufacturer must either accompany the product with a copy of the EU declaration of conformity or provide a simplified EU declaration of conformity.

If a simplified declaration is used, Article 13(20) requires the exact internet address where the full EU declaration can be accessed. Annex II point 6 also requires the internet address for the EU declaration of conformity where applicable.

Citations
Cyber Resilience Act

Article 13(20) covers full or simplified EU declarations; Annex II point 6 covers the declaration internet address where applicable.

CRA User Information and Transparency

What must importers check before placing a product on the EU market?

Importers must check that the product bears CE marking, is accompanied by the EU declaration of conformity and Annex II user information in a language easily understood by users and market surveillance authorities, and that the manufacturer has met the CRA obligations on CE marking, manufacturer contact details, and support-period purchase disclosure.

Importers also have their own user-facing contact duty. They must indicate their name, registered trade name or trademark, postal address, email address or other digital contact, and website where applicable on the product, packaging, or accompanying document. The contact details must be in a language easily understood by users and market surveillance authorities.

Citations
Cyber Resilience Act

Article 19(2) covers importer pre-market checks for CE marking, declarations, Annex II information, and manufacturer disclosure obligations; Article 19(4) covers importer contact information.

CRA User Information and Transparency

What must distributors check before making a product available?

Distributors must act with due care and verify that the product bears CE marking and that the manufacturer and importer have met specified transparency and document obligations, including manufacturer identification, Annex II user instructions, purchase-time support-period disclosure, EU declaration access, and importer contact details.

A distributor that knows, based on information it has, that the manufacturer has ceased operations and can no longer comply with the CRA must inform relevant market surveillance authorities without undue delay and, by any available means and to the extent possible, users of the products placed on the market.

Citations
Cyber Resilience Act

Article 20(1)-(2) covers distributor due care and verification duties; Article 20(6) covers user information where the manufacturer has ceased operations.

CRA User Information and Transparency

When do importers or distributors become treated as manufacturers for these transparency duties?

An importer or distributor is treated as a manufacturer under the CRA when it places a product with digital elements on the market under its own name or trademark, or carries out a substantial modification of a product already placed on the market.

That matters for user information because the Article 13 and Article 14 duties then attach to that importer or distributor as the manufacturer-equivalent actor. Private-label products and materially modified products therefore need the same support-period, contact, vulnerability reporting, update, and user-notice planning as original manufacturer products.

Citations
Cyber Resilience Act

Article 21 makes importers or distributors subject to Articles 13 and 14 where they place products on the market under their name or trademark or substantially modify them.

CRA User Information and Transparency

What should teams check before publishing CRA user information?

Check the product page, purchase flow, package, manual, support portal, release notes, vulnerability disclosure page, and update channel together. The same product identity, manufacturer contact, vulnerability contact, support end date, EU declaration location, and security-update instructions should be consistent across all of them.

Then check the risky-use content against the cybersecurity risk assessment. If secure use depends on conditions such as a protected network, trained administrator, supported integration pattern, enabled automatic updates, or timely patching, the user information should say so in language the expected user can act on.

Citations
Cyber Resilience Act

Article 13(18), Annex II points 4, 5, 7, and 8, and Article 14(8) ground the publication checklist for secure use, risk conditions, support, updates, and user notices.

European Commission CRA FAQs

Sections 4.1.4 and 4.1.5 explain that assumptions needed for secure installation, integration, and operation should be communicated to users.

CRA Vulnerability Handling

What is the core CRA vulnerability-handling duty?

Manufacturers must ensure, when placing a product with digital elements on the market and throughout the support period, that vulnerabilities of the product, including its components, are handled effectively.

In practical terms, Article 13 and Annex I Part II require a process that can identify and document vulnerabilities, track components, remediate vulnerabilities without delay in light of the risk, test and review security regularly, run coordinated vulnerability disclosure, receive vulnerability reports, securely distribute updates, and provide security updates without delay when they are available.

Citations
Cyber Resilience Act

Article 13(8) and Annex I Part II establish the lifecycle vulnerability-handling obligation for products and integrated components.

European Commission CRA FAQs

FAQ sections 4.1.3 and 4.3 explain that Annex I Part II vulnerability-handling requirements apply throughout the support period.

CRA Vulnerability Handling

Does the CRA require manufacturers to patch every vulnerability?

No. The Commission FAQ explains that the CRA does not require a patch for every vulnerability discovered during the support period.

The manufacturer must determine whether the vulnerability is relevant to the product, assess the risk, and put an appropriate remedy in place without delay. Depending on the risk and exploitability, that remedy may be an immediate patch, a mitigation, disabling an affected function, configuration guidance, user advice, documentation updates, or removal in a later regular release.

Citations
Cyber Resilience Act

Annex I Part II point 2 requires vulnerabilities to be addressed and remediated without delay in relation to the risks posed.

CRA Vulnerability Handling

What should a CRA vulnerability record contain?

A useful vulnerability record should connect the legal duty to engineering evidence. It should identify the affected product and version, affected component or dependency where relevant, discovery source, exploitability assessment, risk and severity, affected user population, remediation decision, security update or mitigation, user advisory text, disclosure timing, and whether Article 14 reporting was assessed.

The record should also show whether the cybersecurity risk assessment and technical documentation were updated. Article 13(7) requires systematic documentation of relevant cybersecurity aspects, including vulnerabilities the manufacturer becomes aware of and relevant third-party information.

Citations
Cyber Resilience Act

Article 13(7), Annex VII, and Annex I Part II require documentation of vulnerabilities, vulnerability-handling processes, SBOM information, disclosure policy, reporting contact, update distribution, and test reports.

CRA Vulnerability Handling

How does the CRA use SBOMs and dependency awareness?

Annex I Part II requires manufacturers to identify and document vulnerabilities and components, including a software bill of materials in a commonly used and machine-readable format covering at least top-level dependencies.

The CRA does not make every SBOM public by default. Annex II says that if the manufacturer decides to make the SBOM available to the user, the user information must say where it can be accessed. Annex VII separately lists the SBOM as part of technical documentation where applicable and available to market surveillance authorities when needed to check compliance.

Citations
Cyber Resilience Act

Annex I Part II point 1, Annex II point 9, Article 13(24)-(25), and Annex VII describe SBOM content, user-access information, and authority access.

CRA Vulnerability Handling

Do CRA vulnerability-handling duties cover third-party and open-source components?

Yes. The vulnerability-handling obligations apply to the product in its entirety, including integrated components.

When a manufacturer identifies a vulnerability in an integrated component, including an open-source component, Article 13(6) requires the manufacturer to report it to the person or entity manufacturing or maintaining the component, address and remediate it in the manufacturer's own product, and share relevant code or documentation if the manufacturer developed a software or hardware modification to address the component vulnerability.

Citations
Cyber Resilience Act

Article 13(5)-(6), Article 13(8), and recital 34 connect component due diligence with vulnerability handling and upstream reporting.

European Commission CRA FAQs

FAQ sections 4.3.6 and 4.3.7 explain that integrated component issues remain part of the finished product manufacturer's vulnerability-handling duty.

CRA Vulnerability Handling

When is upstream reporting or fix sharing not required for a component issue?

The Commission's March 2026 draft guidance narrows Article 13(6) upstream reporting to vulnerabilities that exist in the integrated component itself, and only for the component version actually integrated. It does not require upstream reporting for vulnerabilities created only by the manufacturer's integration with its own code or other components.

The same draft guidance says upstream reporting is not required where the component no longer has a maintainer, or where the manufacturer maintains an independent fork and no longer relies on the original maintainer for new versions or security fixes. If the manufacturer still synchronises with upstream for new versions or fixes, that is not treated as an independent fork for this purpose.

Citations
Cyber Resilience Act

Article 13(6) is the statutory basis for upstream component vulnerability reporting and fix sharing.

CRA Vulnerability Handling

Must the upstream maintainer accept a security fix shared under the CRA?

No. The draft Commission guidance says the CRA does not require a manufacturer to ensure that its fix is accepted or integrated by the component maintainer.

Where appropriate, the manufacturer should share the fix in a machine-readable way, such as a merge request, and for open-source components should share it in a way compatible with the component's licence and the maintainer's contribution guidelines. But the finished-product manufacturer may still choose another suitable mitigation for its own product.

Citations
CRA Vulnerability Handling

How long do CRA vulnerability-handling obligations last?

They last for the support period determined by the manufacturer under Article 13(8). The support period must reflect the time the product is expected to be in use, considering reasonable user expectations, product nature and intended purpose, relevant Union law on product lifetime, comparable products, the operating environment, core third-party component support periods, and relevant ADCO or Commission guidance.

The support period is at least five years unless the product is expected to be in use for less than five years, in which case the support period corresponds to the expected use time. The end date, including at least month and year, must be clearly and understandably specified at purchase in an easily accessible way.

Citations
Cyber Resilience Act

Article 3(20), Article 13(8), Article 13(19), and recitals 59-60 define the support period and the criteria for setting it.

Page 53 of 58