FAQEUCyber Resilience Act

EU Cyber Resilience Act FAQ User Information and Transparency

Use this FAQ to identify the CRA information users must receive with products with digital elements: instructions, support-period dates, vulnerability reporting contacts, security-update guidance, and end-of-support notices.

Built for product, legal, UX, support, channel, and compliance teams preparing CRA-facing product pages, manuals, purchase flows, update notices, and support materials.

Author
Sorena AI
Published
Mar 10, 2026
Updated
Mar 10, 2026
Questions
17

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Mar 10, 2026
Updated Mar 10, 2026
Overview

The Cyber Resilience Act does not create a general duty to publish every internal security record. It does require concrete user-facing information: Annex II instructions, manufacturer and vulnerability contact details, support-period disclosures, update and decommissioning instructions, notices for exploited vulnerabilities or severe security incidents, and checks by importers and distributors before products reach EU users.

Search this module

Find a question or answer quickly

17 of 17 questions
Question 1

Does the CRA require products to come with user information and instructions?

Yes. Manufacturers must accompany products with digital elements with the information and instructions listed in Annex II, either on paper or electronically.

For a visitor reviewing a product page or manual, the practical test is simple: can a user identify the product, contact the manufacturer, report vulnerabilities, understand the intended secure use, install security updates, decommission the product securely, and see the security support period? If those answers are missing, the Annex II pack is incomplete.

Citations
Cyber Resilience Act

Article 13(18) requires manufacturers to provide Annex II information and instructions in paper or electronic form; Annex II lists the minimum user information.

Question 2

How clear and accessible do CRA user instructions need to be?

Article 13(18) requires the instructions to be clear, understandable, intelligible and legible. They must also be in a language easily understood by users and market surveillance authorities.

For online instructions, the manufacturer must keep them accessible, user-friendly, and available online for at least 10 years after the product is placed on the market or for the support period, whichever is longer. That makes a stable support page, versioned manual, or durable documentation URL more useful than a temporary campaign page.

Citations
Cyber Resilience Act

Article 13(18) covers clarity, language, electronic instructions, online accessibility, and the minimum online availability period.

Question 3

What must Annex II information include at minimum?

Annex II requires a practical user information set, not just legal boilerplate. It includes manufacturer identity and contact details; a vulnerability reporting point of contact and the coordinated vulnerability disclosure policy location; product name, type, and unique identification information; intended purpose, security environment, essential functionality, and security properties; significant cybersecurity risks from intended use or reasonably foreseeable misuse; the EU declaration of conformity address where applicable; technical security support and support end date; instructions for commissioning, secure use, updates, decommissioning, automatic-update opt-out, and integration; and SBOM access information if the manufacturer chooses to make the SBOM available to users.

A useful CRA-facing manual should turn those legal categories into product-specific instructions. For example, do not only say "install updates securely"; state where update notices appear, how to verify update authenticity, what happens if automatic updates are disabled, and what administrators should do before decommissioning.

Citations
Cyber Resilience Act

Annex II points 1-9 set the minimum information and instruction categories that must accompany products with digital elements.

Implementation support

Turn CRA user-information duties into product-ready content

Map Annex II fields, support-period wording, vulnerability contact details, update notices, and channel responsibilities into publishable product, support, and procurement materials.

Question 4

What manufacturer contact information must users see?

Users must be able to see the manufacturer's name, registered trade name or trademark, postal address, email address or other digital contact details, and, where applicable, website.

Article 13(16) puts that information on the product, packaging, or accompanying document. Annex II point 1 also makes it part of the user instructions. In practice, the product page, manual, package insert, and support site should not disagree about the responsible manufacturer contact.

Citations
Cyber Resilience Act

Article 13(16) and Annex II point 1 cover manufacturer identity, postal contact, digital contact, website where available, and language accessibility.

Question 5

What vulnerability contact must the CRA information provide?

Annex II requires the single point of contact where vulnerability information can be reported and received, and where the manufacturer's coordinated vulnerability disclosure policy can be found.

Recital 63 explains the practical quality bar: the contact should let users communicate directly and rapidly with the manufacturer, should be easily accessible, and should not rely exclusively on automated tools. A bare no-reply form or generic sales address is unlikely to be a good operational answer if it does not route vulnerability reports to people who can triage them.

Citations
Cyber Resilience Act

Annex II point 2 requires the vulnerability reporting contact and coordinated vulnerability disclosure policy location; Recital 63 explains direct and rapid user communication.

Question 6

Does the CRA require support-period disclosure before purchase?

Yes. Article 13(19) requires the end date of the support period to be clearly and understandably specified at the time of purchase, in an easily accessible manner, and at least by month and year.

Annex II point 7 separately requires the product to be accompanied by the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and to receive security updates. For ecommerce, procurement, and channel sales, that means the support end date should be visible before the buyer commits, not hidden inside post-purchase onboarding.

Citations
Cyber Resilience Act

Article 13(19) covers purchase-time support-period disclosure; Annex II point 7 covers security support type and support end date.

Question 7

Must users receive an end-of-support notice?

Yes, where technically feasible in light of the nature of the product. Article 13(19) requires manufacturers to display a notification to users informing them that the product has reached the end of its support period.

The notice should be tied to the product experience or an equivalent user communication channel where the product has no direct interface. Recital 56 says manufacturers should use a user interface or similar technical means where the product has one, and that notifications should be limited to what is necessary to ensure effective reception without harming the user experience.

Citations
Cyber Resilience Act

Article 13(19) requires technically feasible end-of-support user notifications; Recital 56 explains use of product interfaces and proportional notification design.

Question 8

What update information must users receive?

Annex II requires instructions on how security-relevant updates can be installed. It also requires instructions on how to turn off the default setting enabling automatic installation of security updates where that default setting exists.

Annex I adds two visitor-relevant points. First, where security updates are available to address identified security issues, they must be disseminated without delay and, except for the tailor-made business-user exception, free of charge. Second, those updates must be accompanied by advisory messages that give users relevant information, including potential action to take.

Citations
Cyber Resilience Act

Annex II point 8(c)-(e) covers update installation and automatic-update opt-out instructions; Annex I Part II point 8 covers security-update dissemination and advisory messages.

Question 9

Do CRA instructions need to cover secure decommissioning and data removal?

Yes. Annex II requires information on secure decommissioning of the product, including how user data can be securely removed.

That answer is especially important for connected products, appliances, industrial devices, gateways, and software accounts that may retain credentials, keys, logs, configuration, or user content. A useful instruction set should tell users what can be erased, what cannot be erased locally, what must be revoked in a cloud console, and how to confirm the product is no longer connected.

Citations
Cyber Resilience Act

Annex II point 8(d) requires secure decommissioning information, including how user data can be securely removed.

Question 10

When must users be informed about exploited vulnerabilities or severe security incidents?

After becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product, the manufacturer must inform impacted users and, where appropriate, all users. The notice must cover the vulnerability or incident and, where necessary, the risk mitigation and corrective measures users can deploy.

This is not the same as publishing every vulnerability detail to the whole internet. Article 14(8) is aimed at getting actionable information to impacted users. The CRA also says the information should be provided, where appropriate, in a structured, machine-readable format that is easily automatically processable.

Citations
Cyber Resilience Act

Article 14(8) requires user information after awareness of an actively exploited vulnerability or severe security incident and identifies the mitigation content users may need.

Question 11

Must fixed vulnerability information be publicly disclosed once a security update exists?

Yes, with an important timing qualification. Annex I Part II point 4 requires manufacturers, once a security update has been made available, to share and publicly disclose information about fixed vulnerabilities, including affected product identification, impact, severity, and clear remediation information.

The same point allows delayed public disclosure in duly justified cases where the manufacturer considers the security risks of publication to outweigh the security benefits, until users have had the possibility to apply the relevant patch. That makes patch availability, advisory wording, and customer notification timing part of the same transparency workflow.

Citations
Cyber Resilience Act

Annex I Part II point 4 covers public disclosure of fixed vulnerabilities and the justified-delay condition where publication risk outweighs security benefit.

Question 12

Do users have a right to the full CRA technical documentation or risk assessment?

No general user publication duty appears in these provisions. The CRA requires manufacturers to draw up technical documentation, keep it available for market surveillance authorities, and update it where appropriate. Annex VII lists user information and instructions as part of the technical documentation, but it does not turn the whole technical file into a public user document.

For user-facing transparency, focus on the specific disclosures the CRA does require: Annex II instructions, support-period information, vulnerability contact details, EU declaration access where applicable, security-update advisories, fixed-vulnerability disclosures, and Article 14(8) user notices.

Citations
Cyber Resilience Act

Articles 13(12)-(13), Article 31, and Annex VII cover technical documentation for conformity and authority access; Annex II identifies the user-facing instruction set.

Question 13

Does the CRA require access to the EU declaration of conformity?

Yes. The manufacturer must either accompany the product with a copy of the EU declaration of conformity or provide a simplified EU declaration of conformity.

If a simplified declaration is used, Article 13(20) requires the exact internet address where the full EU declaration can be accessed. Annex II point 6 also requires the internet address for the EU declaration of conformity where applicable.

Citations
Cyber Resilience Act

Article 13(20) covers full or simplified EU declarations; Annex II point 6 covers the declaration internet address where applicable.

Question 14

What must importers check before placing a product on the EU market?

Importers must check that the product bears CE marking, is accompanied by the EU declaration of conformity and Annex II user information in a language easily understood by users and market surveillance authorities, and that the manufacturer has met the CRA obligations on CE marking, manufacturer contact details, and support-period purchase disclosure.

Importers also have their own user-facing contact duty. They must indicate their name, registered trade name or trademark, postal address, email address or other digital contact, and website where applicable on the product, packaging, or accompanying document. The contact details must be in a language easily understood by users and market surveillance authorities.

Citations
Cyber Resilience Act

Article 19(2) covers importer pre-market checks for CE marking, declarations, Annex II information, and manufacturer disclosure obligations; Article 19(4) covers importer contact information.

Question 15

What must distributors check before making a product available?

Distributors must act with due care and verify that the product bears CE marking and that the manufacturer and importer have met specified transparency and document obligations, including manufacturer identification, Annex II user instructions, purchase-time support-period disclosure, EU declaration access, and importer contact details.

A distributor that knows, based on information it has, that the manufacturer has ceased operations and can no longer comply with the CRA must inform relevant market surveillance authorities without undue delay and, by any available means and to the extent possible, users of the products placed on the market.

Citations
Cyber Resilience Act

Article 20(1)-(2) covers distributor due care and verification duties; Article 20(6) covers user information where the manufacturer has ceased operations.

Question 16

When do importers or distributors become treated as manufacturers for these transparency duties?

An importer or distributor is treated as a manufacturer under the CRA when it places a product with digital elements on the market under its own name or trademark, or carries out a substantial modification of a product already placed on the market.

That matters for user information because the Article 13 and Article 14 duties then attach to that importer or distributor as the manufacturer-equivalent actor. Private-label products and materially modified products therefore need the same support-period, contact, vulnerability reporting, update, and user-notice planning as original manufacturer products.

Citations
Cyber Resilience Act

Article 21 makes importers or distributors subject to Articles 13 and 14 where they place products on the market under their name or trademark or substantially modify them.

Question 17

What should teams check before publishing CRA user information?

Check the product page, purchase flow, package, manual, support portal, release notes, vulnerability disclosure page, and update channel together. The same product identity, manufacturer contact, vulnerability contact, support end date, EU declaration location, and security-update instructions should be consistent across all of them.

Then check the risky-use content against the cybersecurity risk assessment. If secure use depends on conditions such as a protected network, trained administrator, supported integration pattern, enabled automatic updates, or timely patching, the user information should say so in language the expected user can act on.

Citations
Cyber Resilience Act

Article 13(18), Annex II points 4, 5, 7, and 8, and Article 14(8) ground the publication checklist for secure use, risk conditions, support, updates, and user notices.

European Commission CRA FAQs

Sections 4.1.4 and 4.1.5 explain that assumptions needed for secure installation, integration, and operation should be communicated to users.

Primary sources

References and citations

data.europa.eu
Referenced sections
  • Article 13(18), Annex II points 4, 5, 7, and 8, and Article 14(8) ground the publication checklist for secure use, risk conditions, support, updates, and user notices.
ec.europa.eu
Referenced sections
  • Sections 4.1.4 and 4.1.5 explain that assumptions needed for secure installation, integration, and operation should be communicated to users.
Related guides

Explore more topics

CRA Applicability Test for Products With Digital Elements
Check whether the EU Cyber Resilience Act applies to a hardware, software, firmware, open-source, or connected product before conformity planning.
CRA Article 14 Reporting Obligations for Vulnerabilities and Incidents
Article 14 guide to CRA reports for actively exploited vulnerabilities and severe product-security incidents, including deadlines, CSIRT routing, users, and evidence.
CRA Blue Guide Concepts FAQ | Placing on the Market, Making Available, Distance Sales
CRA FAQ explaining Blue Guide market-access concepts for products with digital elements: placing on the market, making available, imports, CE marking, operator roles, online sales, stock, and testing exceptions.
CRA CE Marking FAQ | Conformity Assessment, EU Declaration, Evidence
Practical CRA CE marking answers for products with digital elements: conformity assessment, EU declaration, technical documentation, standards, software placement, and launch evidence.
CRA Component Due Diligence FAQ | Third-Party Software, FOSS, SBOMs
Cyber Resilience Act FAQ on manufacturer due diligence for integrated components, third-party software, FOSS dependencies, SBOMs, vulnerability handling, and evidence records.
CRA Conformity Assessment and CE Marking
How to choose a Cyber Resilience Act conformity route, prepare technical documentation, issue the EU declaration of conformity, and affix CE marking.
CRA Conformity Assessment Routes FAQ | Module A, Module B+C, Module H, Important and Critical Products
Cyber Resilience Act FAQ on when manufacturers can use module A, when module B+C or module H is required, and how important and critical products affect the route.
CRA Cybersecurity Risk Assessment FAQ | Article 13, Annex I, Updates
CRA FAQ on Article 13 cybersecurity risk assessments, Annex I applicability, intended purpose, foreseeable use, technical documentation, and update evidence.
CRA deadlines and compliance calendar | EU Cyber Resilience Act
Track the Cyber Resilience Act entry into force, staged application dates, Article 14 reporting deadlines, transitional rules, and review dates.
CRA Declaration of Conformity FAQ | Annex V, Simplified Declaration, CE Marking
FAQ on the Cyber Resilience Act EU Declaration of Conformity: Annex V contents, simplified Annex VI wording, CE marking link, technical documentation, retention, updates, and operator duties.
CRA Economic Operators FAQ | Manufacturers, Importers, Distributors, Authorised Representatives
CRA FAQ on economic-operator roles: manufacturers, importers, distributors, authorised representatives, substantial modification, traceability, and evidence controls.
CRA Essential Cybersecurity Requirements FAQ | Annex I Part I and Part II
CRA FAQ on Annex I product cybersecurity requirements, vulnerability handling, secure-by-default design, risk assessment, documentation, lifecycle duties, and user information.
CRA Essential Cybersecurity Requirements in Annex I
A grounded guide to the Cyber Resilience Act Annex I requirements for product security, vulnerability handling, secure-by-design controls, documentation, and evidence.
CRA Hardware and Software Boundaries FAQ | Product Scope, Components, RDPS
FAQ on Cyber Resilience Act hardware and software boundaries: combined products, standalone software, source code, components, remote data processing, SaaS and market-placement changes.
CRA Harmonised Standards FAQ | Presumption of Conformity, Common Specifications
Cyber Resilience Act FAQ on how harmonised standards, common specifications, certification schemes, and OJ publication affect CRA conformity evidence.
CRA Important and Critical Products FAQ | Annex III, Annex IV, Conformity Assessment
FAQ on CRA important and critical products, Annex III and Annex IV classification, core functionality, and conformity assessment consequences.
CRA Integrated Components and Dependencies FAQ | Third-Party Software and SBOM Evidence
Cyber Resilience Act FAQ on integrated components, third-party software, remote data processing, SBOM-style evidence, upstream fixes, FOSS dependencies, and manufacturer responsibility.
CRA Interplay With EU Product Laws FAQ | RED, Machinery, Data Act
Grounded CRA FAQ on overlap with the Radio Equipment Directive, Machinery Regulation, GPSR, Data Act, exclusions, declarations, documentation, and existing certificates.
CRA Known Exploitable Vulnerabilities at Launch FAQ
FAQ for Cyber Resilience Act launch decisions: known exploitable vulnerabilities, CVEs, component flaws, secure-by-default settings, release gates, Article 14 reporting, and evidence.
CRA Legacy Products FAQ | Pre-11 December 2027 Products
Cyber Resilience Act FAQ on products placed on the market before 11 December 2027, Article 14 reporting, substantial modification, distributor stock, spare parts, and records.
CRA Manufacturer Obligations FAQ | Article 13, Annex I, CE Marking
FAQ for Cyber Resilience Act manufacturers covering Article 13 duties, risk assessment, Annex I, vulnerability handling, support periods, documentation, conformity assessment, reporting, CE marking, and evidence controls.
CRA Market Surveillance and Enforcement FAQ | Authorities, Corrective Action, Safeguards
Cyber Resilience Act FAQ on market-surveillance authorities, investigations, corrective action, withdrawal, recall, safeguards, sweeps, documentation access, and penalties.
CRA Module B+C FAQ | EU-Type Examination, Conformity to Type, Notified Bodies
CRA Module B+C FAQ explaining EU-type examination, conformity to type, notified-body evidence, production control, CE marking, declarations, and certificate changes.
CRA Module H FAQ | Full Quality Assurance, Notified Body Surveillance, CE Marking
CRA Module H FAQ explaining the full-quality-assurance route, notified-body assessment, quality-system scope, technical documentation, CE marking, declarations, and records.
CRA Notified Bodies FAQ | Scope, Modules B+C and H, Certificates
Practical CRA FAQ on when notified bodies are needed, how CRA bodies are designated, what their notified scope means, and how Module B+C and Module H assessments work.
CRA Open-Source Software FAQ | FOSS Scope, Stewards, Manufacturers
Cyber Resilience Act FAQ for free and open-source software: commercial activity, steward duties, manufacturer due diligence, vulnerability handling, public documentation, and user obligations.
CRA Over-the-Air Updates FAQ
Cyber Resilience Act FAQ on OTA updates, automatic security updates, secure update distribution, support-period evidence, and offline update paths.
CRA penalties and fines FAQ | Article 64 fine caps
FAQ on EU Cyber Resilience Act Article 64 penalties: maximum fine tiers, turnover caps, national enforcement, economic operators, reporting duties, and open-source steward carve-outs.
CRA Penalties and Fines: Article 64 Caps and Enforcement Context
Article 64 of the EU Cyber Resilience Act sets administrative fine ceilings for Annex I, manufacturer, reporting, economic-operator, notified-body, and information-request breaches.
CRA Product Families FAQ | Variants, Shared Assessments, Family Reuse, Conformity Scope
CRA FAQ on product families, variant grouping, shared technical documentation, conformity evidence, and when cybersecurity-relevant differences need separate assessment.
CRA Products with Digital Elements Scope | EU Cyber Resilience Act
Apply the EU Cyber Resilience Act scope test for software, hardware, remote data processing, components, open-source software, exclusions, and economic-operator roles.
CRA Products With Digital Elements Scope FAQ
EU Cyber Resilience Act FAQ on products with digital elements, software, firmware, remote data processing, components, exclusions, market placement, and CRA operator boundaries.
CRA Remote Data Processing Solutions FAQ | Product Scope, Cloud and Backend Boundaries
FAQ on how the EU Cyber Resilience Act treats remote data processing solutions, manufacturer-controlled backends, third-party cloud services, SaaS, risk assessment, documentation, and user information.
CRA Reporting Obligations FAQ | Article 14, CSIRTs, ENISA, User Notices
Cyber Resilience Act FAQ on Article 14 reporting for actively exploited vulnerabilities and severe incidents, including timing, CSIRT routing, ENISA access, user notices, and evidence.
CRA Requirements | Annex I, Manufacturer Duties and CE Evidence
Map Cyber Resilience Act requirements from Annex I to manufacturer duties, vulnerability handling, user information, technical documentation, declaration of conformity, and CE marking evidence.
CRA SBOM and Vulnerability Management Template
Build a CRA-ready SBOM and vulnerability handling record with component inventory, triage, remediation, disclosure, reporting, update, and technical documentation fields.
CRA Secure-by-Default FAQ | Default Configuration and Annex I Controls
Cyber Resilience Act FAQ on secure-by-default configuration, automatic security updates, attack surface reduction, authentication, data minimisation, user information, and tailor-made products.
CRA Security Updates vs Functionality Updates FAQ
Cyber Resilience Act FAQ on classifying security updates, functionality updates, support-period duties, automatic updates, user notices, and substantial-modification review.
CRA Substantial Modification FAQ | Updates, Repairs, Manufacturer Duties
Cyber Resilience Act FAQ on when software updates, repairs, spare parts, and post-market changes become substantial modifications and trigger CRA manufacturer, evidence, and conformity duties.
CRA Support Period FAQ | Expected Product Lifetime, Security Updates, User Information
Practical CRA FAQ on how manufacturers determine support periods, disclose support end dates, keep security updates available, and document support-period evidence.
CRA Tailor-Made Products FAQ | Bespoke Products, Market Placement, Evidence
FAQ on when a bespoke product may be treated as tailor-made under the EU Cyber Resilience Act, what the carve-out changes, and what manufacturers still need to document.
CRA Technical Documentation FAQ | Annex VII Evidence and Technical File
CRA FAQ explaining Annex VII technical documentation, risk assessment evidence, conformity assessment files, vulnerability handling records, product families, RDPS, language, and authority access.
CRA Transition Period FAQ | Entry Into Force, Application Dates, Reporting, Legacy Products
CRA FAQ on the transition period covering entry into force, 2026 reporting, 2027 application, legacy products, stock, customs timing, and software versions.
CRA Update Availability and Software Archives FAQ
FAQ on CRA security-update availability, support-period notices, optional public software archives, historical versions, and Article 13(10) software-version limits.
CRA vs RED Cybersecurity Delegated Act
Compare the EU Cyber Resilience Act with the RED cybersecurity delegated act for connected and radio equipment, including scope, timing, evidence, and transition treatment.
CRA vs UK PSTI Act | Cyber Resilience Act Comparison
Compare grounded EU Cyber Resilience Act duties with UK PSTI planning points, with UK legal details clearly marked for separate source review.
CRA Vulnerability Handling and Disclosure | Article 14 Reporting and Security Updates
How EU Cyber Resilience Act manufacturers should run vulnerability intake, remediation, coordinated disclosure, Article 14 reporting, secure updates, and evidence records.
CRA Vulnerability Handling FAQ | Support Periods, Components, Reporting
Practical CRA FAQ on vulnerability handling: SBOMs, remediation, coordinated disclosure, component issues, security updates, support periods, Article 14 reporting, and user notices.
Cyber Resilience Act Module A FAQ | Internal Production Control
FAQ on when CRA Module A internal production control is available, when it is blocked, and what documentation, testing, standards, and evidence it still requires.
EU CRA Compliance Program for Manufacturers and Economic Operators
Build a Cyber Resilience Act compliance program around product scope, Annex I security requirements, conformity assessment, technical documentation, vulnerability reporting, and market surveillance.
EU Cyber Resilience Act Checklist for Product Security and CE Marking
A CRA checklist for products with digital elements: scope, Annex I security controls, vulnerability handling, Article 14 reporting, technical documentation, conformity assessment, CE marking, and support-period evidence.
EU Cyber Resilience Act Core Functionality FAQ | CRA Product Classification
CRA FAQ on core functionality, product boundaries, remote data processing, integrated components, ancillary functions, and software changes that affect product classification.
EU Cyber Resilience Act FAQ
Direct CRA FAQ answers on scope, economic-operator roles, essential requirements, vulnerability reporting, conformity assessment, CE marking, support periods, and market surveillance.
EU Cyber Resilience Act Repairs and Spare Parts FAQ
CRA FAQ for repairs, spare parts, legacy products, security updates, substantial modification, and responsibility after product changes.
EU Cyber Resilience Act Technical Documentation and Audit File
Build an audit-ready CRA technical file around Article 31 and Annex VII: product scope, risk assessment, vulnerability handling, conformity evidence, testing, and retention.