Cell Register
Standards ยท CRA

EU Cyber Resilience Act

Rendered on every connected asset as what to ask the supplier; informational, the owner owes no clause. The register cites 2 of its 24 clauses, behind 1 finding: end of support or unpatched, and on the obligation rows of every asset it reaches. Binds manufacturers, importers and distributors of products with digital elements; never the owner using them.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page.

Clauses cited

2 of 24
CRA Art. 13 and Annex I Manufacturer obligations and essential requirements (Article 13 + Annex I)

Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) Article 13(8) documented support period (default 5 years, adjustable per product lifecycle and category) during which security updates are provided free of charge, automatically by default, and separately from feature updates; (4) Article 13(12) information and instructions to users (Annex II); (5) Article 13(15)-(16) cooperation with market surveillance. Annex I Part I sets the essential cybersecurity requirements (secure by default, secure communication, data minimisation, access control, no exploitable known vulnerabilities at time of placing on the market, etc.). Annex I Part II sets the vulnerability handling requirements (vulnerability disclosure policy, SBOM availability where relevant, security updates throughout the support period, coordination on disclosed vulnerabilities).

Evidence an auditor accepts: Cybersecurity risk assessment per Article 13(2) for each PDE; Third-party component due-diligence file per Article 13(6) including SBOM and FOSS-component analysis; Documented support period per Article 13(8) communicated to users and tracked operationally
Common gap: No documented support period or support-period shorter than the product's reasonably expected lifecycle
Source framework: EU Cyber Resilience Act
CRA Art. 69, 70, 71 Transitional provisions, evaluation and entry into force (Articles 69-71)

Article 69 sets the transitional provisions: PDEs placed on the market before 11 December 2027 are subject to the Regulation only where they are subject to a substantial modification after that date. Article 70 requires the Commission to evaluate and report on the Regulation by 11 December 2030 and every 4 years thereafter. Article 71 sets the entry into force (twentieth day after publication in OJ - 10 December 2024) and the application dates: most provisions apply from 11 December 2027 (36-month transition); the Article 14 reporting regime applies earlier from 11 September 2026; the notified-body provisions apply earlier from 11 June 2026.

Evidence an auditor accepts: Compliance calendar covering the staggered application dates: 10 Dec 2024 entry into force, 11 Jun 2026 notified-body provisions, 11 Sep 2026 Article 14 reporting, 11 Dec 2027 main obligations; Substantial-modification policy aligned with the Article 69 grandfathering boundary
Common gap: Compliance plan that treats 11 December 2027 as the only date
Source framework: EU Cyber Resilience Act

See which clauses your list engages

Paste the list and every asset names the clauses behind it, filtered to the regimes that apply to you. Eight assets free, no account.

Build my cell register