Loading the latest actively exploited vulnerabilities…Powered by Achilles

CRA Dossier

Article 14 Reporting beyond the Support Period

by Daniel Thompson-Yvetot

Ending a product's support period does not end your Cyber Resilience Act's Article 14 reporting duty. This dossier argues that duty only ends when your company does, tracing that position through the Regulation's text, the adopted European Commission guidance, and the wider EU product-safety framework.

← Back to shop

Written for general counsel and compliance leads deciding whether a discontinued product's Cyber Resilience Act reporting duty has actually ended.

Why it matters

A support period ending is not the same as a Cyber Resilience Act reporting obligation ending. Article 14’s requirement to report an actively exploited vulnerability is triggered by awareness, carries no temporal clause in its text, and applies under Article 69(3) even to products placed on the market before the Regulation’s general application date. This is a class of products that is not subject to the CRA support-period requirements that apply from the Regulation’s general application date.

This dossier argues that the duty’s only real endpoint is the manufacturer’s own existence as a legal entity, and tests that position against the strongest counter-arguments, proportionality, and legal certainty. It also sets out what a compliant report can look like for an unsupported or discontinued product.

What is inside

  • The textual case built from CRA Articles 3(20), 13(21), 13(23), 14(1) and 69(2)-(3), and from point 210 of the Commission’s adopted guidance.
  • Why seven candidate limiters in the Regulation’s own text all fail to bound the Article 14 reporting duty.
  • How the New Legislative Framework’s comparator regimes, the Blue Guide, the MDR, NIS2, DORA and GPSR, reinforce an unbounded reading, since none of them bounds reporting to a manufacturer-declared support period.
  • Why Article 14 is an informational duty rather than a repair duty, and where the actual vulnerability-handling and repair obligations sit instead.
  • How CRA Articles 54 and 57 let a market surveillance authority compel action on an unsupported product even where the manufacturer’s own duty has lapsed.
  • Six operational recommendations, including how to draft a CRA post-support vulnerability report that limits exposure to an Article 57 order.

Who is it for

General Counsel and Compliance Leads deciding whether a discontinued product’s Cyber Resilience Act reporting duty has actually ended.

Continue exploring CRA compliance

Explore our related dossiers for practical analysis of other Cyber Resilience Act requirements and compliance topics.

Explore related dossiers

If you need advice tailored to your product, reporting process or compliance obligations, our CRA experts can help you identify the appropriate next steps.

Contact a CRA expert