Plan your support period
The CRA requires manufacturers to set a support period that reflects how long the product is expected to be in use, counted from when it is placed on the market. Five years is the default; it may be shorter where the expected use is shorter, and should be longer where it is longer. Enter your dates to see your support and retention deadlines, and to flag any component that goes End-of-Life too soon.
Your key dependencies and their End-of-Life dates live in your software bill of materials. Rather than entering them by hand, the Vulnerability Analyzer reads your SBOM and identifies component End-of-Life automatically; feed those dates back in here to check them against your support period.
A component whose End-of-Life falls before your support period ends will leave you maintaining unsupported software; plan a replacement or an extended-support arrangement before then. Indicative only; not legal advice. Verify against Article 13(8), (9) and (13) and Article 31(3) of Regulation (EU) 2024/2847.
A substantial modification (a change that alters the product's cybersecurity risk beyond what your risk assessment covered) means reassessing the support period against the same criteria; it does not automatically reset or extend it. The Commission guidance explains how the support period and substantial modifications interact.
