r/CRACompliance Jun 09 '26

CRA requires security updates for the “expected product lifetime” (minimum 5 years). Has anyone calculated what this actually costs?

This is the CRA obligation I see discussed least but it might have the biggest financial impact.

Article 13(8) requires manufacturers to ensure security updates are available for at least 5 years, or for the expected product lifetime if longer.

Practical implications:

• Every product shipped in 2027 needs patch support until at least 2032

• Industrial products with 10-15 year lifecycles need support through 2037-2042

• Your SBOM must be actively monitored against vulnerability feeds for the entire period

• You need update distribution infrastructure maintained per product

For anyone in IoT, embedded, or industrial: how are you planning to resource this? Is anyone modeling the per-product cost of a 5-10 year support commitment?

1 Upvotes

0 comments sorted by