EU Cyber Resilience Act
CRA - Manufacturer Obligations and Essential Requirements (Ch II Section 1)

EU Cyber Resilience Act CRA-Art.13_AnnexI: Manufacturer obligations and essential requirements (Article 13 + Annex I)

Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) Article 13(8) documented support period (default 5 years, adjustable per product lifecycle and category) during which security updates are provided free of charge, automatically by default, and separately from feature updates; (4) Article 13(12) information and instructions to users (Annex II); (5) Article 13(15)-(16) cooperation with market surveillance. Annex I Part I sets the essential cybersecurity requirements (secure by default, secure communication, data minimisation, access control, no exploitable known vulnerabilities at time of placing on the market, etc.). Annex I Part II sets the vulnerability handling requirements (vulnerability disclosure policy, SBOM availability where relevant, security updates throughout the support period, coordination on disclosed vulnerabilities).

Other controls in CRA - Manufacturer Obligations and Essential Requirements (Ch II Section 1)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.