Back to Knowledge Base
Knowledge Base · post-launch

Post-launch compliance : obligations don't stop at CE marking

28 February 2026 7 min read CRA

Vulnerability handling, incident reporting, substantial-modification triggers, and when a readiness attestation should be re-issued.

Compliance is a lifecycle, not a launch

CE marking is a milestone, not the finish line. Several EU regimes impose continuing duties for as long as the product is supported and on the market. Treating compliance as a one-off launch task is the most common — and most expensive — mistake.

Continuing duties

  • Vulnerability handling and security updates throughout the support period.
  • Reporting of actively exploited vulnerabilities and significant incidents within regulatory deadlines.
  • Monitoring changes in the threat landscape that affect your product.

Substantial modifications

A significant change to a product can re-open conformity: the modified product may need to be re-assessed. Define what counts as a substantial modification for your product and wire it into your release process.

When to refresh your attestation

A readiness attestation represents a point in time. After a substantial modification, a material change in evidence, or a notable improvement in readiness, refresh it so what you present matches what you ship.

This is an educational explainer. For the canonical regulation reference, see the dedicated CRA page — or run an assessment to see how it applies to your product.