Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Regulation (EU) 2024/2847

CRA Article 13 what the Regulation requires of manufacturers

Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements.
Article 13 · Read it on EUR-Lex

Article 13 is the backbone obligation: it makes the manufacturer responsible for security at the point the product is placed on the market and throughout the support period that follows.

It requires a documented cybersecurity risk assessment, kept updated during the support period, and effective vulnerability handling that explicitly extends to the product's components — which is where the Annex I SBOM obligation earns its keep.

The support period is not fixed by the Regulation. Manufacturers determine it to reflect how long the product is reasonably expected to be in use, taking into account user expectations, the nature of the product, and what comparable products on the market offer.

What it actually requires

Risk assessment
Must be documented and updated as appropriate during the support period. It is not a one-time exercise at launch.
Components are in scope
Vulnerability handling covers the product "including its components" — third-party and open-source dependencies are your responsibility, not your supplier's alone.
Support period
Determined by the manufacturer to reflect expected time in use, informed by reasonable user expectations, the nature of the product, and support periods offered for similar products.
Duration of duty
Obligations run from placing on the market and continue for the whole support period, not just at conformity assessment.

Dates that apply

DateWhat applies
11 December 2027Article 13 obligations apply in full.
10 December 2024The Regulation entered into force.

The rest of the CRA

Producing the Annex I SBOM and tracking which listed vulnerabilities actually affect your product is what O3 generates automatically, in CycloneDX or SPDX. Book a demo.

FAQ

Common
questions.

Everything teams ask before rolling this out. Still stuck? Reach our team.

  • Article 13 requires manufacturers to carry out and document a cybersecurity risk assessment, keep it updated during the support period, and ensure that vulnerabilities in the product and its components are handled effectively in line with the Annex I essential cybersecurity requirements — from the point the product is placed on the market and throughout the support period.
  • The Regulation does not set a fixed length. Manufacturers determine the support period so that it reflects how long the product is expected to be in use, taking into account reasonable user expectations, the nature of the product, and the support periods offered for comparable products by other manufacturers.
  • Yes. The obligation covers vulnerabilities of the product "including its components", so third-party and open-source dependencies fall within the manufacturer's vulnerability-handling duty. Article 24 sets separate, lighter obligations for open-source software stewards.