CRA Dossier
Article 14 Reporting beyond the Support Period
Ending a product's support period does not end your Cyber Resilience Act's Article 14 reporting duty. This dossier argues that duty only ends when your company does, tracing that position through the Regulation's text, the adopted European Commission guidance, and the wider EU product-safety framework.
Written for general counsel and compliance leads deciding whether a discontinued product's Cyber Resilience Act reporting duty has actually ended.
Why it matters
A support period ending is not the same as a Cyber Resilience Act reporting obligation ending. Article 14’s requirement to report an actively exploited vulnerability is triggered by awareness, carries no temporal clause in its text, and applies under Article 69(3) even to products placed on the market before the Regulation’s general application date. This is a class of products that is not subject to the CRA support-period requirements that apply from the Regulation’s general application date.
This dossier argues that the duty’s only real endpoint is the manufacturer’s own existence as a legal entity, and tests that position against the strongest counter-arguments, proportionality, and legal certainty. It also sets out what a compliant report can look like for an unsupported or discontinued product.
What is inside
- The textual case built from CRA Articles 3(20), 13(21), 13(23), 14(1) and 69(2)-(3), and from point 210 of the Commission’s adopted guidance.
- Why seven candidate limiters in the Regulation’s own text all fail to bound the Article 14 reporting duty.
- How the New Legislative Framework’s comparator regimes, the Blue Guide, the MDR, NIS2, DORA and GPSR, reinforce an unbounded reading, since none of them bounds reporting to a manufacturer-declared support period.
- Why Article 14 is an informational duty rather than a repair duty, and where the actual vulnerability-handling and repair obligations sit instead.
- How CRA Articles 54 and 57 let a market surveillance authority compel action on an unsupported product even where the manufacturer’s own duty has lapsed.
- Six operational recommendations, including how to draft a CRA post-support vulnerability report that limits exposure to an Article 57 order.
Who is it for
General Counsel and Compliance Leads deciding whether a discontinued product’s Cyber Resilience Act reporting duty has actually ended.