← Back to insights

“Five Years of Security Support.” When Does the CRA Support Period Actually End?

Test a Cyber Resilience Act support-period claim against expected use, technical documentation, market-placement evidence and the published end date.

A CRA support-period receipt aligns expected product use, component support, technical evidence and the customer-visible end date
#Cyber Resilience Act#Support Period#Vulnerability Handling#Product Security#Connected Products

Signals to watch

  • A connected product is approaching an EU launch and marketing says five years of security support without a documented expected-use assessment
  • Core third-party components reach end of support before the product claim, while the remediation and replacement owner is unresolved
  • The declared support end date cannot be reconciled across technical documentation, purchase information, packaging and the update channel

“Five years” is not a complete Cyber Resilience Act support-period claim. Under Article 13(8), the manufacturer must determine a period that reflects how long the product with digital elements is expected to be used. It is generally at least five years, shorter only when expected use is shorter, and longer when the product is reasonably expected to remain in use longer. The claim needs a rationale, a product event and a visible end date.

That makes the topic relevant to a product-security maintenance or CRA compliance provider’s business-development lead reading authorised connected-product, embedded-software and security Telegram groups. A named launch, a support claim and a broken evidence chain can indicate implementation work. A generic debate about whether five years is enough cannot. If the discussion is seen after packaging and purchase screens are locked, correcting the end-date evidence becomes more expensive and may miss the maintenance architecture decision.

First question: is five years the floor, an exception or the wrong number?

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, requires manufacturers to handle vulnerabilities effectively when placing a product with digital elements on the market and throughout its support period.

Article 13(8) says manufacturers determine the period by considering expected use, reasonable user expectations, product nature and intended purpose, and relevant Union law. They may also consider comparable products, availability of the operating environment, support periods of integrated third-party components that provide core functions, and relevant guidance. The factors must be applied proportionately.

The same paragraph sets the floor: at least five years. If the product is expected to be used for less than five years, the support period corresponds to the expected use time. The recitals give a temporary contact-tracing application as an example of a potentially shorter life. Hardware, network devices, operating systems and industrial products can reasonably be used longer and therefore require longer support.

The correct sales question is not “Can your team provide five years?” It is “What product and use assessment produced this period, and which evidence shows it starts and ends where the organisation claims?”

Second question: which event anchors the receipt?

Consider this illustrative composite message; it is not a customer claim:

“EU launch next spring. Security updates guaranteed for five years. Chip vendor ends patches in 2030 and the box artwork needs the support date this month.”

The fragment contains an EU launch, a five-year claim, a component dependency and a packaging event. It omits the exact product, intended purpose, expected-use assessment, market-placement date, final chip, operating environment, update channel and support end month.

The support-period receipt needs at least these dates:

  1. Determination date: when the manufacturer approved the expected-use analysis and support period.
  2. Placement record: the market-placement event for the product version and the applicability analysis.
  3. Support end date: at least the month and year presented to the purchaser.
  4. Component end dates: core dependencies that may fail before the product promise.
  5. Update evidence window: releases, vulnerability intake and remediation records during the declared period.

The regulation does not define the support period as “five years after the first group message” or “five years after development starts.” The product’s technical and market records must support the calculation used.

Third question: can the component chain honour the promise?

Article 13(8) expressly allows the manufacturer to consider support periods of integrated components providing core functions. That does not let the manufacturer copy the shortest component date and stop. It means the product plan must address what happens when a core component ends support before users reasonably stop using the product.

A useful evidence file names the component, function, supplier support end, replacement or mitigation route, update-distribution path and accountable owner. For open-source components, an upstream maintenance date and the manufacturer’s own supported fork are different facts. For hardware, a component may remain available while vulnerability fixes have stopped.

The CRA reporting-workflow request deals with actively exploited vulnerabilities and severe incidents; it does not answer how long the product must receive vulnerability handling. The secure-software attestation evidence request concerns a US federal delivery claim, not an EU product support period. Pricing and access options describe TOP Prospect’s discovery product.

TOP Prospect can surface and group relevant fragments from Telegram groups a user deliberately connects and is authorised to access, retaining original text, source, time, summary and ranking reasons for human review. It cannot determine product lifetime, inspect technical documentation, promise updates, publish the support date or declare CRA conformity.

Fourth question: does the customer see the same end date?

Article 13(19) requires the support-period end date, including at least month and year, to be specified clearly and understandably at purchase in an easily accessible manner and, where applicable, on the product, packaging or by digital means. Where technically feasible, the manufacturer must notify users when the product reaches the end of its support period.

The evidence chain should compare the approved support receipt with the web product page, purchase flow, packaging or device surface, instructions and update service. If one says March 2033 and another says “five years from activation,” the inconsistency is the project.

Article 13(18) separately requires user information and instructions to remain available for at least 10 years after placement or for the support period, whichever is longer. Do not confuse the availability of instructions with the vulnerability-handling support period itself.

Fifth question: is the team using the correct application date?

Article 71 says the CRA generally applies from 11 December 2027. Article 14 reporting obligations apply earlier, from 11 September 2026, and the conformity-assessment-body provisions apply from 11 June 2026. A team preparing a 2028 launch should build Article 13 evidence now. A message in August 2026 should not claim that the Article 13 support-period duty is already generally applicable merely because the Article 14 reporting date is close.

This date distinction is commercially useful. It separates a real readiness project from an inaccurate “deadline next month” claim.

The support-period receipt

The original contribution is a one-page receipt with six fields:

FieldProof
ProductExact version, intended purpose and market route
Expected useUser expectations, product nature, operating environment and applicable law
PeriodApproved start and end logic, including any shorter-than-five-year justification
ComponentsCore dependency support dates and mitigation owner
PublicationMonth/year shown at purchase and on applicable surfaces
MaintenanceVulnerability intake, updates, disclosure and end-of-support notification route

When those fields reconcile, a maintenance provider can scope engineering, component replacement, update delivery or evidence operations. When they do not, the first deliverable is a dated gap analysis—not a five-year support guarantee.

Key facts

  • The CRA generally applies from 11 December 2027; Article 14 reporting applies from 11 September 2026.
  • Article 13(8) requires effective vulnerability handling during the support period.
  • The support period reflects expected product use and is generally at least five years.
  • A shorter period is possible where expected use is shorter; products expected to remain in use longer need a longer period.
  • The technical documentation must contain the information used to determine the period.
  • Article 13(19) requires at least the support end month and year to be clearly available at purchase and on applicable product, packaging or digital surfaces.

FAQ

Does the CRA require exactly five years of support for every product?

No. The support period is generally at least five years, but where the product is expected to be used for less than five years it corresponds to that expected use; products expected to be used longer require a period reflecting that longer use.

What factors determine the support period?

Article 13(8) names expected use, reasonable user expectations, product nature and intended purpose, relevant Union law, similar products, operating-environment availability, core-component support periods and relevant guidance, applied proportionately.

Where must the support end date appear?

Article 13(19) requires at least the month and year to be clearly and understandably specified at purchase in an easily accessible way and, where applicable, on the product, packaging or by digital means.

Are the Article 13 support-period duties already generally applicable in August 2026?

No. The Regulation generally applies from 11 December 2027. Article 14 reporting applies earlier from 11 September 2026, but that earlier date should not be misapplied to the Article 13 support-period duties.

The strongest demand Signal is not “CRA says five years.” It is a product preparing for market with a support claim that its technical documentation, component plan and purchaser-facing date cannot yet prove.

Frequently asked questions

Does the CRA require exactly five years of support for every product?

No. The support period is generally at least five years, but where the product is expected to be used for less than five years it corresponds to that expected use; products expected to be used longer require a period reflecting that longer use.

What factors determine the support period?

Article 13(8) names expected use, reasonable user expectations, product nature and intended purpose, relevant Union law, similar products, operating-environment availability, core-component support periods and relevant guidance, applied proportionately.

Where must the support end date appear?

Article 13(19) requires at least the month and year to be clearly and understandably specified at purchase in an easily accessible way and, where applicable, on the product, packaging or by digital means.

Are the Article 13 support-period duties already generally applicable in August 2026?

No. The Regulation generally applies from 11 December 2027. Article 14 reporting applies earlier from 11 September 2026, but that earlier date should not be misapplied to the Article 13 support-period duties.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage