Regulation (EU) 2024/2847
CRA Article 13 — what the Regulation requires of manufacturers
“Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements.”
Article 13 is the backbone obligation: it makes the manufacturer responsible for security at the point the product is placed on the market and throughout the support period that follows.
It requires a documented cybersecurity risk assessment, kept updated during the support period, and effective vulnerability handling that explicitly extends to the product's components — which is where the Annex I SBOM obligation earns its keep.
The support period is not fixed by the Regulation. Manufacturers determine it to reflect how long the product is reasonably expected to be in use, taking into account user expectations, the nature of the product, and what comparable products on the market offer.
What it actually requires
- Risk assessment
- Must be documented and updated as appropriate during the support period. It is not a one-time exercise at launch.
- Components are in scope
- Vulnerability handling covers the product "including its components" — third-party and open-source dependencies are your responsibility, not your supplier's alone.
- Support period
- Determined by the manufacturer to reflect expected time in use, informed by reasonable user expectations, the nature of the product, and support periods offered for similar products.
- Duration of duty
- Obligations run from placing on the market and continue for the whole support period, not just at conformity assessment.
Dates that apply
| Date | What applies |
|---|---|
| 11 December 2027 | Article 13 obligations apply in full. |
| 10 December 2024 | The Regulation entered into force. |
The rest of the CRA
- CRA Annex I: the SBOM Requirement in Full
- CRA Article 14: the 24-Hour Reporting Clock
- CRA Deadlines: Every Date That Applies
- EU Cyber Resilience Act — full compliance overview
Producing the Annex I SBOM and tracking which listed vulnerabilities actually affect your product is what O3 generates automatically, in CycloneDX or SPDX. Book a demo.