In order to ensure that products with digital elements are secure both at the time of their placing on the market as well as during the time the product with digital elements is expected to be in use, it is necessary to lay down essential cybersecurity requirements for vulnerability handling and essential cybersecurity requirements relating to the properties of products with digital elements. While manufacturers should comply with all essential cybersecurity requirements related to vulnerability handling throughout the support period, they should determine which other essential cybersecurity requirements related to the product properties are relevant for the type of product with digital elements concerned. For that purpose, manufacturers should undertake an assessment of the cybersecurity risks associated with a product with digital elements to identify relevant risks and relevant essential cybersecurity requirements in order to make available their products with digital elements without known exploitable vulnerabilities that might have an impact on the security of those products and to appropriately apply suitable harmonised standards, common specifications or European or international standards.
Recital 54
Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026
Quick Answer for Manufacturers
Recital 54 explains why vulnerability handling is essential: products must be secure not only at the time of placing on the market but throughout their expected use period. This is the basis for the obligation of continuous vulnerability handling under Annex I Part II.
This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.
Common Manufacturer Questions
Why is security at placing on the market not enough?
New vulnerabilities are constantly discovered. A product that is secure in 2026 may be exploitable in 2028. The CRA obliges manufacturers to close this gap through continuous vulnerability handling.
What must a vulnerability handling process include?
Identification and documentation of vulnerabilities, remediation through security updates, user notification, coordinated disclosure. See Annex I Part II for details.
How long must the process be maintained?
Throughout the expected product lifecycle. For industrial goods this often means 10-15 years; for consumer electronics typically 3-7 years, depending on market reality and the manufacturer's declaration.
Related Articles
(1)This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex