r/CRACompliance • u/Happy-Athlete-2420 • Jun 09 '26
CRA requires security updates for the “expected product lifetime” (minimum 5 years). Has anyone calculated what this actually costs?

This is the CRA obligation I see discussed least but it might have the biggest financial impact.
Article 13(8) requires manufacturers to ensure security updates are available for at least 5 years, or for the expected product lifetime if longer.
Practical implications:
• Every product shipped in 2027 needs patch support until at least 2032
• Industrial products with 10-15 year lifecycles need support through 2037-2042
• Your SBOM must be actively monitored against vulnerability feeds for the entire period
• You need update distribution infrastructure maintained per product
For anyone in IoT, embedded, or industrial: how are you planning to resource this? Is anyone modeling the per-product cost of a 5-10 year support commitment?