What is Article 13?
Article 13 is one of the most important articles in the CRA for manufacturers. It outlines the complete set of obligations that apply when you design, develop, produce, and sell products with digital elements in the EU market.
Who is a "Manufacturer"?
Under CRA, a manufacturer is any natural or legal person who:
- Develops or produces a product with digital elements, OR
- Has such a product designed or produced, AND
- Markets it under their own name or trademark
This includes software developers, hardware makers, and white-label products.
Manufacturer Obligations Under Article 13
Article 13 contains 25 paragraphs. Below are the core obligations — a few closely related duties from neighbouring articles (ENISA reporting under Article 14, authorised representatives under Article 18) are also included and clearly marked as such.
Meet Essential Requirements
Summary:
"When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I."
What This Means:
Before selling in the EU, your product must meet all applicable security requirements from Annex I Part I (product security) and Annex I Part II (vulnerability handling).
Conduct Risk Assessment
Summary:
"For the purpose of complying with paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases..."
What This Means:
You must perform a formal cybersecurity risk assessment and use it to drive security decisions throughout the entire product lifecycle.
Prepare Technical Documentation
Summary:
"Before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 31."
What This Means:
You need complete technical documentation describing how your product meets CRA requirements. This includes design docs, test results, and security architecture.
Conduct Conformity Assessment
Summary:
"They shall carry out the chosen conformity assessment procedures as referred to in Article 32 or have them carried out."
What This Means:
You must formally assess and document conformity. The procedure depends on your product classification—self-assessment (Module A) or third-party (Notified Body).
Conformity Assessment Guide →Draw Up EU Declaration of Conformity
Summary:
"...manufacturers shall draw up the EU declaration of conformity in accordance with Article 28 and affix the CE marking in accordance with Article 30."
What This Means:
You must create a formal declaration stating your product complies with CRA, and apply the CE marking to the product.
Keep Documentation for 10 Years
Summary:
"Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer."
What This Means:
Maintain all compliance records for at least 10 years — longer if your declared support period runs past that. Market surveillance authorities may request them at any time.
Handle Vulnerabilities Throughout Support Period
Summary:
"Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I."
What This Means:
You must actively manage vulnerabilities for at least 5 years from placing the product on market. However, if the product's expected lifetime is less than 5 years, provide updates for that shorter period instead. This includes patching, testing, and notifying users of security issues.
Vulnerability Management Guide →Report Vulnerabilities to ENISA (separate article)
Summary:
"A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator... and to ENISA... an early warning notification... within 24 hours..."
What This Means:
This duty is imposed by Article 14, not Article 13 — it's included here because it follows directly from the obligations above. If a vulnerability in your product is being actively exploited, you must notify the CSIRT designated as coordinator and ENISA within 24 hours (early warning), 72 hours (full details), and a final report within 14 days of a fix being available.
Article 14 Reporting Guide →Appoint Authorized Representative (if needed) (separate article)
Summary:
"A manufacturer may, by a written mandate, appoint an authorised representative."
What This Means:
This is an Article 18 obligation, not Article 13 — included here as a related duty. Appointing an authorised representative is optional under Article 18(1) itself, but in practice manufacturers established outside the EU need one so market surveillance authorities have an EU-based point of contact. Note that Article 18(2) excludes several core Article 13 obligations (13(1)-(11), 13(12) first subparagraph, and 13(14)) from what can be delegated to the representative — the manufacturer keeps those duties regardless.
When Do These Obligations Apply?
Preparation Phase
Start implementing SDL, SBOM generation, and vulnerability handling processes
Reporting Obligations Start
Article 14(1)-(2) - ENISA/CSIRT vulnerability reporting becomes mandatory
Full Application
All Article 13 obligations apply to products placed on market
Related CRA Articles
Start Your Compliance Journey
Take our free assessment to understand your obligations and get a personalized roadmap.