Scope
Manufacturer, importer or distributor: which CRA role is yours
Published . Reviewed against Regulation (EU) 2024/2847, OJ L, 20.11.2024.
The Cyber Resilience Act does not ask what your company calls itself. It asks what you do with a product with digital elements when it reaches the Union market, and it sorts you into one of three roles. The role decides the duties, and the duties decide almost everything else.
Three definitions, read them in order
“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge” (Art. 3, point (13), 'manufacturer', CELEX 32024R2847)
“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union” (Art. 3, point (16), 'importer', CELEX 32024R2847)
“a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties” (Art. 3, point (17), 'distributor', CELEX 32024R2847)
Read together, the three definitions are a decision tree. Does the product carry your name or trademark? You are the manufacturer. Does it carry a non-EU party's name and are you the one first placing it on the Union market? You are the importer. Are you neither, and do you pass the product on without affecting its properties? You are the distributor.
The test is the name on the product, not the work behind it
“Has products with digital elements designed, developed or manufactured” is doing the heavy lifting in Article 3(13). You can outsource every line of code, own no build system and employ no engineers, and still be the manufacturer, because you market the result under your name.
The clause also says “whether for payment, monetisation or free of charge”. A free tier, an ad-funded app and a giveaway installer are all marketed products. Price is not the test.
What a manufacturer owes
The manufacturer carries the substantive requirements: the essential cybersecurity requirements in Annex I, vulnerability handling under Article 13, technical documentation, the software bill of materials, the declared support period, conformity assessment and CE marking from 11 December 2027, and the Article 14 reporting duties from 11 September 2026. Article 14 is titled “Reporting obligations of manufacturers” and no other role files under it directly.
What an importer owes
The importer is a gatekeeper, not an author. Article 19 makes that concrete.
“place on the market only products with digital elements that comply with the essential cybersecurity requirements” (Art. 19, importer obligations, CELEX 32024R2847)
The importer checks that the manufacturer did the work: the conformity assessment procedure was carried out, the technical documentation exists, the CE marking is there. The importer also has to be findable.
“Importers shall indicate their name, registered trade name or registered trademark” (Art. 19, importer identification, CELEX 32024R2847)
And the importer has two information duties of its own.
“Upon becoming aware of a vulnerability in the product with digital elements, importers shall inform the manufacturer without undue delay about that vulnerability” (Art. 19(5), CELEX 32024R2847)
“where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market” (Art. 19(5), CELEX 32024R2847)
What a distributor owes
The distributor standard is due care, and it is stated at that level of generality.
“act with due care in relation to the requirements set out in this Regulation” (Art. 20, distributor obligations, CELEX 32024R2847)
In practice that means verifying the CE marking is present and the required documentation accompanies the product before passing it on. The two information duties mirror the importer's.
“Upon becoming aware of a vulnerability in the product with digital elements, distributors shall inform the manufacturer without undue delay about that vulnerability” (Art. 20(4), CELEX 32024R2847)
“where the product with digital elements presents a significant cybersecurity risk, distributors shall immediately inform the market surveillance authorities of the Member States” (Art. 20(4), CELEX 32024R2847)
The three roles side by side
| Role | The test | Core duties |
|---|---|---|
| Manufacturer | Markets the product under its own name or trademark, whether developed in house or on order, paid or free (Art. 3(13)) | Annex I essential requirements, Art. 13 vulnerability handling, technical documentation, SBOM, support period, conformity assessment, CE marking, Art. 14 reporting |
| Importer | Established in the Union, places on the Union market a product bearing a non-EU party's name or trademark (Art. 3(16)) | Place only compliant products on the market, verify conformity assessment and documentation, indicate own name, inform the manufacturer of vulnerabilities, inform market surveillance authorities of significant risk (Art. 19) |
| Distributor | In the supply chain, neither manufacturer nor importer, makes the product available without affecting its properties (Art. 3(17)) | Act with due care, check CE marking and documentation, inform the manufacturer of vulnerabilities, inform market surveillance authorities of significant risk (Art. 20) |
Rebranding and white-labelling change your role
This is the clause resellers miss.
“An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.” (Art. 21, CELEX 32024R2847)
Two triggers, either one is enough. Put your logo on someone else's software and sell it as yours, and you own vulnerability handling and the reporting clock for it. Modify a product already on the market in a way that affects its conformity with the Annex I essential requirements, or that changes the intended purpose it was assessed for, and the same thing happens.
White-label deals are where this bites hardest, because the commercial arrangement usually says the upstream vendor handles security. The Regulation does not read your contract. It reads the name on the product.
Open-source stewards are a fourth category
Recital 18 of the CRA carves out contribution, and Article 3 names a separate role for organised stewardship.
This Regulation “does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility” (recital 18, CELEX 32024R2847)
“a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products” (Art. 3, point (14), 'open-source software steward', CELEX 32024R2847)
A steward's duty is lighter than a manufacturer's and it is a documentation duty.
“Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.” (Art. 24(1), CELEX 32024R2847)
The line that decides between steward and manufacturer is commercial activity: open-source software supplied for distribution or use in the course of a commercial activity is treated like any other product on the market. The hinge is Art. 3(22), “making available on the market”, which requires supply in the course of a commercial activity. Recital 18 states that free and open-source software not monetised by its manufacturer is not supplied in the course of one, and recital 15 lists what can make supply commercial: a price, paid support beyond the recovery of actual costs, an intention to monetise, a personal-data condition, or donations exceeding costs.
Article 64 sets the fine brackets by obligation, not by role. Breaches of the Annex I essential requirements and of Articles 13 and 14 sit in the highest bracket (Art. 64(2)); the importer and distributor obligations of Articles 19 and 20 sit in the next one (Art. 64(3)); and a third bracket covers incorrect, incomplete or misleading information supplied to notified bodies and market surveillance authorities (Art. 64(4)). Each is a ceiling: the euro figure, or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher. That is the structure of the law, stated neutrally, not a forecast about your company.
Orientation, not legal advice. Verify against the official text before relying on any item.