<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">
CRA Support-Period Custody

Back your CRA support period with verified custody.

From December 2027, CRA Article 13 obliges every product sold in the EU to carry five years of security updates and vulnerability handling. Support-Period Custody holds all your critical software assets in verified escrow, so your support promise is kept no matter what.

Verified custody — not a promise on file.
The five-year support period clock starts the day you enter the EU market, and your duty to provide patches in that time is non-transferable. Support-Period Custody makes that obligation roadmap-proof — holding everything a future patch needs.
badge-cra CRA
solutions_badge_dora DORA
badge-nis2 NIS2
badge-iso-27001-v2 ISO 27001
solutions-ffiec FFIEC
One custody deposit for the support-continuity evidence any major framework expects.
The old way

Not all suppliers will last till the end of your support period

The CRA makes you declare an end-of-support date and handle vulnerabilities until you reach it. Most manufacturers back that with a repository, a build server, and the assumption their team and suppliers will still be here in year four. Often they are not.

With nothing backing the commitment, that is a request you cannot meet. A failed support period turns into a breach of an essential requirement, carrying fines up to €15 million or 2.5% of worldwide annual turnover.

The support promise on file
Declared support period PDF
Ends · 11 Mar 2033
Unbacked
Declared once, never verified — so no one knows if a future patch is possible.
cra-sbom-escrow-team-meeting-800
Why we built it

The vault your support promise can rely on

For over a decade, Codekeeper has held the source code, third-party components, and build environments behind thousands of critical systems in immutable vaults. A deposit held independently survives a ransomware event, a breach, or your own insolvency — the moments a private repository does not.
10+
years managing escrow
3 500+
companies protected
ISO 27001
certified
24 hrs
to go live

Everything a future patch needs, in one deposit

Each capability closes a gap the repository-and-build-server approach leaves open.

Source and component custody

Full source code plus every third-party and open-source component, deposited daily, so future you has what day-one you shipped.

Build environment included

Toolchains, build scripts, and configurations deposited with the code, so the product can still be compiled years after release.

Verified rebuildability

A Certified rebuild compiles the product from the deposit, proving the stored source code and build environment are complete enough to produce a security update.

Immutable, encrypted vault

Deposits held in AES256/512 encrypted, tamper-proof storage, independent of your own systems, so a breach or ransomware on your side never reaches them.

CRA retention, handled

Every shipped security update kept reissuable for 10 years under Article 13(9), and your technical file and Declaration of Conformity retained under Article 31.

Continuity release framework

If you cease support, production, or trading, the escrow agreement triggers and releases the deposit to the parties named to keep the product patched.

How it works

How Support-Period Custody works

In review
AC
Atlas Gateway Product
BL
11 Mar 2033 End of support
AgreementSource + build env
Last deposit2 days ago
Active
NV
Orbit Sensor Product
FB
02 Sep 2032 End of support
AgreementFirmware + toolchain
Last depositToday

1. Declare your products

List each product with its end-of-support date, then connect the repositories and build systems behind it, so everything required for future patches is included.

Products
3 in support · last verified today
Software Resilience Certificate
Software Resilience
Certificate
Passed

2. Codekeeper syncs and verifies

Codekeeper deposits your source, components, and build environment daily, then verifies each product still compiles from what is stored.

Certified tier seal
Codekeeper Software Resilience Certificate
ProviderAcme Cloud Ltd
TierCertified
Recovery testPassed · 14 Jun 2026
Valid to14 Jun 2027
Authorized · Codekeeper
Verified

3. You hold the proof

Every product carries a Software Resilience Certificate that stays current for its whole support period — ready whenever a notified body or buyer asks.

Live in 24 hours, with no ongoing work on your side. From there, every deposit stays current and verified against its support period.

Book a demo

These companies’ systems are protected, compliant, and resilient.

They made the decision. They built their resilience. They have peace of mind. You can too.
icon-google
icon-g2
“We’ve had a great experience with CodeKeeper. The setup process was smooth, and the team made everything very straightforward. Knowing our critical software assets are securely protected gives us real peace of mind. Their support has been responsive and professional, and the overall service has been reliable and easy to work with. Highly recommended.”
testimonial-circle-j

Jordan Adler

“We worked with Codekeeper as our escrow provider for major enterprise deployments and found them to be extremely professional, responsive, and flexible throughout.
I'd highly recommend Codekeeper. They clearly understand the realities of working with growing tech businesses and enterprise customers alike.”
testimonial-circle-r

Ross Kilshaw

I found Codekeeper's solution excellent for what I need. I scheduled a demo to better understand the possibilities. Very easy! It was a clear and straightforward meeting, focused exactly on what I needed. Excellent service!
testimonial-circle-t

Thiago Mendes

Airbus partner logo in muted style
Bayer partner logo in muted style
EU Parliament partner logo in muted style
General Motors partner logo in muted style
Intuit partner logo in muted style
Nestle partner logo in muted style
Pepsico partner logo in muted style
Pfizer partner logo in muted style
Framework mapping

Overlapping support duties, one solution

The CRA is not the only framework making continued support a legal duty. Plus, your regulated buyers carry matching obligations and push them onto you through contracts, too. One verified custody deposit answers both.
badge-cra
CRA — Article 13(8) and 13(9) Security updates across the declared support period, kept available 10 years after release.
solutions-dora
DORA — Article 30(2)(f) Exit strategies and a transition period keeping the service running if you stop supporting it
badge-nis2
NIS2 — Article 21(2)(e) Secure ongoing system maintenance, including vulnerability handling.
solutions-ffiec
FFIEC — Outsourcing Technology Services Escrow, named as the continued operation control when a provider fails.
badge-iso-27001-v2
ISO 27001 — A.5.30 ICT readiness to keep critical software supported when a supplier cannot.
If you are the buyer, requiring Support-Period Custody of a critical supplier turns a contract clause into a control your auditor can inspect.
What's at stake

How your support-obligation audit goes is up to you

Without Support-Period Custody

  • A component supplier folds or a toolchain dies, the product will not rebuild — but the duty to patch does not fold with it.
  • The product is withdrawn, recalled, or barred from the EU market while you scramble to reconstruct a build environment already lost.
  • Financial-sector deals lost because you cannot offer the exit strategy and transition period their contracts must contain.
€15M or 2.5% of worldwide annual turnover, whichever is higher, if you cannot produce a patch during a routine review.
Article 13(9) — every update must stay reissuable for 10 years after its release. Lose a build environment, and the exposure outlives the product.

With Support-Period Custody

  • Every declared support period is backed by a verified, rebuildable deposit — so you can compile and ship a patch at any time.
  • When a supplier fails or a toolchain moves on, the deposit still holds what the rebuild needs, and obligation stays deliverable.
  • When a reviewer asks whether you can still patch the product, a current Software Resilience Certificate proves you can.
  • Your technical file, Declaration of Conformity, and every shipped update stay retained and reissuable across the full CRA window.
  • If you cease trading, customers keep a patchable product and your successors inherit what they need to carry the obligation.
Sample

Page through a verified support-period report

The sample Software Resilience Report shows a product’s deposit, its verification result, and the certified SBOM behind it — the proof you would hand a notified body or a buyer.
Verification result
Software Resilience Certificate
Certified tier seal
Codekeeper Software Resilience Report
ProductAcme Cloud Ltd
TierCertified
SBOM verifiedComplete · 14 Jun 2026
Components1,284 · CycloneDX
Verified
Get the sample support-period report

We’ll email the sample support-period report to you.

Your CRA support period is a five-year promise. Prove you can keep it.

A support period binds you long after your roadmap has moved on. Put custody in place now, and the commitment holds through whatever the next five years bring — regardless of what happens to your suppliers, software dependencies, or team.

Frequently asked questions

What is the CRA support period?
The CRA support period is the time during which a manufacturer must handle vulnerabilities and provide security updates for a product with digital elements. Under Article 13(8) of Regulation (EU) 2024/2847 it must be at least five years, unless the product is expected to be in use for less, and it starts when the product is first placed on the EU market, not when a customer buys it. The end date must be stated at the point of sale.
What is Support-Period Custody?
Support-Period Custody is escrowed, verified storage of everything needed to keep a product patchable across its declared support period: source code, third-party components, the build environment, and the CRA technical file, with certificates proving the product can still be rebuilt. Codekeeper holds it independently, so the obligation survives changes to your team, your suppliers, and your company priorities.
Can a manufacturer transfer the CRA support obligation to a component supplier?
No. A manufacturer cannot transfer the CRA support obligation to a component supplier. Under Article 13, the maker of the final product stays responsible for the security of every component, including open-source and third-party code, for the whole support period. A supplier failing upstream does not reduce what you owe your users, which is why independent custody of what you need to patch matters.
How is this different from keeping our own repositories and backups?
Support-Period Custody differs from your own repositories and backups because a repository proves the code exists today, while custody proves an independent party holds it, that it rebuilds into a patchable product, and that your customers keep access if you stop trading. Those are the things a notified body, an auditor, or a buyer checks about a five-year commitment, and a private backup cannot evidence them.
How long must security updates stay available under the CRA?
Under the CRA, each security update must stay available for at least 10 years after it is released, or for the remainder of the support period if that is longer, under Article 13(9). Technical documentation and the EU Declaration of Conformity carry a similar retention duty under Article 31. Custody keeps every shipped update and the technical file reissuable across those windows.
When does the CRA support-period obligation start to apply?
The CRA support-period obligation applies from December 11, 2027, when the Regulation reaches full application. Products placed on the EU market from that date carry the support period, the security-update duty, and the CE-marking and technical-documentation requirements that go with them. The Regulation is already in force, so the time to put custody in place is before that date.
Which regulations does CRA Support-Period Custody support?
Support-Period Custody supports the CRA most directly, covering the support-period duty under Article 13 and technical-file retention under Article 13(13). The same deposit serves as continuity evidence under DORA Article 30, secure-maintenance evidence under NIS2 Article 21(2)(e), ICT readiness under ISO 27001 A.5.30, and the vendor-failure contingency FFIEC examiners look for.
Is the CRA support period five years or ten years?
The CRA support period is at least five years, and the ten-year figures cover two separate duties that outlast it. Article 13(8) sets the support period at a minimum of five years, or longer where the product is expected to be in use for longer. Article 13(9) then requires every security update you issue to stay available for ten years after release, or the rest of the support period if that runs longer. Article 13(13) requires your technical documentation and EU declaration of conformity retained for ten years after the product is placed on the market, on the same whichever-is-longer basis.