Back to Blog
Smart HomeIoTIndustrial ComponentsCRA ComplianceCyber Resilience ActEnd of LifeVulnerability Management

CRA Friday Facts: Product End-of-Life Is Not the Finish Line

Discontinuing a product does not get you out of the CRA. Information duties, documentation retention, and secure data deletion guidance carry on.

June 5, 2026
10 min read
Maximilian Heck

"With product end-of-life we are out of this topic. EOL is EOL." I hear this regularly from manufacturers that have built their product to be CRA-compliant and believe the duty is done once the product is taken off the market. That is wrong. The EU Cyber Resilience Act does not end with the last serial number, and not even with the end of security support. It accompanies manufacturers well beyond the moment of discontinuation.

Important upfront: these requirements apply to products placed on the market after 11 December 2027. For legacy products placed on the market before that date, the CRA does not apply in principle, unless a substantial modification is made to the product.

Smart home gateway sitting next to a cardboard box labeled End of Life, with a wall calendar showing a circled date in the background

What does "product discontinuation" mean in the CRA context?

Many manufacturers have understood that the CRA brings ongoing duties during the use phase. Vulnerabilities must be monitored, security updates provided, and actively exploited flaws reported to ENISA (the EU Agency for Cybersecurity). That much is known.

What is less known: product discontinuation, meaning the formal end of security support and ceasing of further development, does not simply end those duties. Instead, it triggers its own obligations, which are explicitly anchored in the CRA.

"Placing on the market" refers to the first actual availability of a product on the EU market. This moment starts the regulatory clock. The clock does not stop when discontinuation happens. There is an important distinction to keep in mind: CRA duties do not end with the sales stop, the date from which the product is no longer offered. What matters is the declared support period, which must be communicated to buyers. Anyone who discontinues a product without having clearly defined and communicated this period has never met an obligation that begins already at the point of sale. For an overview of the basic CRA structure, see our CRA guide.

Why discontinuation is not the finish line

The misconception arises from understandable logic: if we no longer offer the product, we cannot be responsible for new problems. The CRA sees it differently, and for good reasons.

Discontinued products do not vanish immediately. They keep running in households, production plants, and infrastructure, often for years. Users who no longer receive software updates, but also do not know that support has ended, are left unprotected. Products with un-deleted personal data quietly change owners. Technical documentation needed in market surveillance proceedings is no longer findable.

Three concrete obligations continue past discontinuation, and all three are anchored in the CRA.

The consequences of poor compliance are described in our article on CRA penalties and fines.

Myth vs. fact

Myth: A manufacturer's obligations end with product discontinuation or sales stop.

Fact: Obligations continue until the end of the declared support period. Buyers must know at the point of sale until when the manufacturer provides security updates. Technical documentation and the EU declaration of conformity must be retained for at least ten years, or as long as the declared support period lasts, whichever is longer. On top of that comes the duty to describe in the product documentation how users can permanently delete their personal data before disposal. All of this applies regardless of whether and when the product is taken off the market.

Concrete consequences for manufacturers

1. Communicate the support period at the point of purchase. Article 13 CRA obliges manufacturers to inform buyers at the moment of purchase until when security updates will be provided, month and year. This is not voluntary information, but an explicit legal obligation. Anyone selling a product without this information already breaches the CRA at the point of sale, regardless of how well vulnerability management is set up otherwise. The challenge behind it: anyone marketing a product must have decided in advance how long they intend to support it. EOL planning therefore does not begin shortly before discontinuation, it begins at product design. For more on lifecycle requirements, see the vulnerability management guide.

2. Retain technical documentation and the declaration of conformity correctly. Technical documentation and the EU declaration of conformity must be retained for at least ten years, or as long as the declared support period lasts, whichever is longer. A product with 15 years of support therefore needs not ten but fifteen years of archiving. The ten-year mark is the minimum requirement for shorter support periods, not a blanket solution. Market surveillance authorities can also check long after discontinuation whether a product met CRA requirements at the moment it was placed on the market. Those who delete documentation too early or stop maintaining it after the EOL decision risk having no defensible evidence in a proceeding. For more on CE marking and conformity assessment, see CRA conformity assessment.

3. Provide user documentation with guidance for secure data deletion. Annex II CRA explicitly requires that user documentation contains instructions for secure decommissioning. This must include guidance on how users can permanently and securely delete stored personal data before they pass on, sell, or dispose of the device. This documentation must be in place from the start, not created at the moment of discontinuation. If it is missing, there is a concrete documentation gap, not a grey area. For more on SBOM duties and data classification, see our SBOM guide for IoT manufacturers.

4. On full business termination, inform authorities and users in advance. For the case where a company fully ceases operations, Article 13 CRA contains its own duty. The competent market surveillance authorities must be informed in advance, and, as far as possible, also the users of the affected products. This duty applies regardless of whether the product is still within active support or already discontinued. Anyone winding down a company or fully discontinuing a product line must create clarity on this point as well, before operations end.

Practical example: the discontinued smart home gateway

A mid-sized manufacturer launches a smart home gateway in early 2028. At launch it communicates: security updates until December 2032. The product sells well but is discontinued for commercial reasons in 2030. Sales stop. Devices already with customers continue to run, many of them for another two to three years.

What must the manufacturer keep in mind? First, they acted correctly at sale. Buyers knew at the moment of purchase until when support would be provided. The 2030 sales stop changes nothing about that. The support obligation continues, as communicated, until December 2032. Second, technical documentation and the declaration of conformity must be retained at least until December 2037, ten years after the declared end of support, since that period is longer than ten years from the last sale. Third, the user documentation must, from the start, explain how Wi-Fi credentials, linked cloud accounts, and stored automation rules can be permanently deleted before disposal. If any of these elements is missing, the manufacturer has not fully met the CRA.

What does this mean for your CRA roadmap?

The end-of-life obligations are not isolated requirements. They are part of the full CRA conformity process, which kicks in over two stages.

From 11 September 2026, the reporting duties of the CRA apply. Manufacturers must report actively exploited vulnerabilities and severe security incidents to ENISA. Anyone discontinuing a product during this phase must at the same time ensure that user communication around the EOL announcement is correct.

From 11 December 2027, the CRA applies in full. Products placed on the market after that date must meet all requirements, including the full documentation for secure decommissioning.

Anyone setting up product planning today should think through the entire lifecycle, from development through use phase, discontinuation, and beyond. A detailed overview of deadlines and recommended actions is available in our CRA compliance roadmap.

Frequently asked questions

Does the EOL information duty also apply to B2B products? Yes. The CRA does not fundamentally distinguish between B2B and B2C for user information duties. Commercial users of connected products must also be informed in good time about the end of security support, so they can make informed decisions about continued operation or replacement.

What if the product has no local data storage but data sits in the manufacturer's cloud? Then the user documentation must explain how the user can delete their cloud data or remove the account fully. The manufacturer is responsible for making sure that this path exists and is clearly described.

How far in advance must I inform users before product discontinuation? The CRA does not set a rigid deadline but names the criterion of timeliness. EU guidance suggests that users must have enough time to make an informed decision about how to handle the device. What that means concretely depends on the type of product and its typical usage duration. In doubt: earlier is better.

Do I have to retrofit older products with decommissioning guidance? For products placed on the market after 11 December 2027, the duty applies mandatorily. For legacy products it depends on the individual case, in particular whether substantial modifications have been made to the product that triggered a renewed conformity assessment.

How long exactly do I have to retain documentation? At least ten years after the last placing on the market, or as long as the declared support period lasts, whichever is longer. For a product with 15 years of support that means at least 15 years. The ten-year rule only applies if the support period is shorter. The clock starts at the last placing on the market of the product, not at discontinuation.

Do I have to keep documentation even if the product never had a security incident? Yes. The retention duty applies regardless of incidents. Market surveillance authorities can verify at any time whether a product met the requirements at the moment it was placed on the market. The evidence only holds with complete documentation.

Conclusion

Product discontinuation is not a regulatory finish line. The duties begin earlier than many think, buyers must know at the moment of purchase until when security updates will be provided. They end later than many expect, documentation must be retained at least ten years or across the entire support period, whichever is longer. Between the two sits the duty to provide guidance for secure data deletion, and in the extreme case, on full business termination, also the duty to inform authorities and users in advance. These are not interpretive questions, they are explicit requirements from Article 13 and Annex II CRA.

Anyone wanting to systematically assess their CRA compliance status, including the requirements across the full product lifecycle up to discontinuation, can do so in a structured way with the free CRA compliance assessment from Kunnus, before the deadline tips from planning into practice.


Every Friday I debunk a CRA myth here.

Share:

Friday Facts weekly in your inbox

A CRA fact-check every Friday. A few minutes to read, zero myths.

Which newsletters do you want?

Continue Reading

Ready to tackle CRA compliance?

Kunnus gives manufacturers of every size the tools to achieve full CRA compliance — from SBOM management to ENISA reporting, in one platform.