Vulnerability handling, incident reporting, substantial-modification triggers, and when a readiness attestation should be re-issued.
Compliance is a lifecycle, not a launch
CE marking is a milestone, not the finish line. Several EU regimes impose continuing duties for as long as the product is supported and on the market. Treating compliance as a one-off launch task is the most common — and most expensive — mistake.
Continuing duties
- Vulnerability handling and security updates throughout the support period.
- Reporting of actively exploited vulnerabilities and significant incidents within regulatory deadlines.
- Monitoring changes in the threat landscape that affect your product.
Substantial modifications
A significant change to a product can re-open conformity: the modified product may need to be re-assessed. Define what counts as a substantial modification for your product and wire it into your release process.
When to refresh your attestation
A readiness attestation represents a point in time. After a substantial modification, a material change in evidence, or a notable improvement in readiness, refresh it so what you present matches what you ship.
This is an educational explainer. For the canonical regulation reference, see the dedicated CRA page — or run an assessment to see how it applies to your product.