Component-level deposits
Every third-party and open-source component you integrate is deposited in full, together with the supplier documentation describing what that component does.
From 11 December 2027, the CRA’s Article 13(5) holds you responsible for every component you integrate with, even unmaintained open-source ones. Third-Party Component Escrow deposits each with its supplier docs — kept current and verified for your support period.
Registries delete versions, projects are abandoned, suppliers stop shipping. Once a component exists nowhere upstream, you cannot reproduce it — or patch the product it shipped in. Failing Article 13 costs up to €15 million.
Every third-party and open-source component you integrate is deposited in full, together with the supplier documentation describing what that component does.
Deposits are held in AES256/512 encrypted, tamper-proof storage outside your infrastructure, so a breach, corruption, or deletion on your systems cannot reach the components.
Codekeeper syncs component changes from your connected repositories and cloud platforms across 50+ integrations, so every release you ship has its components captured and current.
Each deposit is stored as its own dated version, and you set how many to retain, so a four-year-old product draws the components that shipped inside it.
Verification confirms your deposited components are present, complete, and structurally sound, and your Software Resilience Certificate records what was checked and when.
Codekeeper can approach each component supplier for the integration and security documentation the CRA obliges them to provide, and deposit what they return as a dated record.
Setup is live in 24 hours. After that, every component deposit updates on its own schedule, and Codekeeper confirms what is held long before a market surveillance authority asks to see it.
You list the third-party and open-source components integrated into each product, and connect the repositories and cloud platforms they are pulled into.
Each component is deposited with its documentation, every change stored as a dated version, and the deposit verified against what your product contains.
On a reasoned request under Article 13(22), you draw the exact deposit version they need, with its Software Resilience Certificate.
Set up in a day. From there, the deposit stays current on its own.
Book a demoJordan Adler
Ross Kilshaw
Thiago Mendes
We’ll email the sample component escrow report to you.