[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:what-the-cra-asks-of-importers-and-distributors":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","what-the-cra-asks-of-importers-and-distributors","What the CRA asks of importers and distributors, and when it makes them the manufacturer","If you resell software or devices into the EU rather than build them, Articles 19 and 20 of the Cyber Resilience Act give you a checklist to run before the product goes on sale, a duty to pass vulnerabilities to the manufacturer, a duty to tell authorities about significant risks, and ten years of record-keeping. Article 21 turns you into the manufacturer the moment you sell under your own brand or substantially modify the product. The obligations, from the text.","2026-09-11","\nThe Cyber Resilience Act, Regulation (EU) 2024\u002F2847, does not stop at the manufacturer. Everyone in the chain between the manufacturer and the user has obligations, and for a reseller they are more than a formality: an importer or distributor who puts a non-compliant product on the EU market is the one the market surveillance authority finds first. Articles 19 and 20 set the duties, and Article 21 says when a reseller stops being a reseller.\n\nTwo definitions first. An **importer** places on the EU market a product from a manufacturer established outside the Union. A **distributor** makes a product available on the market that an importer or manufacturer has already placed there: a reseller, a retailer, a systems integrator selling boxed software. The CRA's duties for each are similar in shape and differ in depth.\n\n## The importer: Article 19\n\n**Only compliant products.** Article 19(1): importers place on the market only products that meet Annex I Part I, and whose manufacturer's processes meet Part II.\n\n**A checklist before placing on the market.** Article 19(2): the importer ensures that the manufacturer has carried out the appropriate conformity assessment (Article 32), has drawn up the technical documentation, that the product bears the CE marking and comes with the EU declaration of conformity and the Annex II user information in a language users and authorities understand, and that the manufacturer has met Article 13(15), (16) and (19): identification on the product, the vulnerability contact, and the support period's end date shown at purchase. The importer must be able to produce documents proving each point.\n\n**Stop, and tell.** Article 19(3): an importer who considers or has reason to believe the product or the manufacturer's processes are not in conformity does not place it on the market until they are; where the product presents a significant cybersecurity risk, the importer informs the manufacturer and the market surveillance authorities.\n\n**Name on the product.** Article 19(4): the importer's name, registered trade name or trademark and contact details go on the product, its packaging or an accompanying document.\n\n**After the sale.** Article 19(5): corrective measures, withdrawal or recall where a product placed on the market turns out non-compliant; any vulnerability the importer becomes aware of is passed to the manufacturer without undue delay; a significant cybersecurity risk is reported immediately to the authorities of every member state where the product was made available.\n\n**Ten years of records.** Article 19(6): a copy of the EU declaration of conformity kept for the market surveillance authorities, and the technical documentation obtainable on request, for at least ten years after placing on the market or for the support period, whichever is longer. Article 19(7): full information and documentation to an authority on a reasoned request, in a language it understands.\n\n**If the manufacturer disappears.** Article 19(8): an importer who becomes aware that the manufacturer has ceased operations and can no longer comply informs the authorities and, as far as possible, the users.\n\n## The distributor: Article 20\n\n**Due care.** Article 20(1).\n\n**A shorter checklist.** Article 20(2): the distributor verifies that the product bears the CE marking and that the manufacturer and importer have met their identification, contact, user-information, support-period and declaration duties (Article 13(15), (16), (18), (19) and (20) and Article 19(4)) and have provided the necessary documents.\n\n**Stop, and tell.** Article 20(3): where the distributor considers or has reason to believe, on the basis of information in its possession, that the product or processes do not conform to Annex I, it does not make the product available until they do, and reports a significant cybersecurity risk to the manufacturer and the authorities.\n\n**After the sale.** Article 20(4): makes sure corrective measures, withdrawal or recall are taken; passes vulnerabilities to the manufacturer without undue delay; reports a significant cybersecurity risk to the authorities of the member states concerned. Article 20(5): information and documentation to an authority on a reasoned request. Article 20(6): the same duty as the importer if the manufacturer ceases operations.\n\nThe distributor's standard is \"on the basis of information in its possession\": a reseller is not required to audit the product, but is required to act on what it knows.\n\n## When the reseller becomes the manufacturer: Article 21\n\n\"An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.\"\n\nTwo ways in. **Your name or trademark on the product**: white-labelling a device or rebranding software makes you the manufacturer of that product, with the whole of Article 13 (the [22 requirements](\u002Farticles\u002Fcra-annex-i-the-22-essential-requirements-as-a-checklist), the [technical file](\u002Farticles\u002Fwhat-goes-in-the-cra-technical-file-annex-vii-point-by-point), the [support period](\u002Farticles\u002Fhow-long-is-the-cra-support-period), the [CE mark](\u002Farticles\u002Fdoes-software-need-a-ce-mark-under-the-cra)) and Article 14 reporting. **A substantial modification**: changing a product already on the market in a way that affects its conformity or its intended purpose. A reseller that adds its own firmware, or integrates the product into a bundle that changes what it does, has usually crossed the line.\n\n## Where the penalties sit\n\nArticles 18 to 23, the chain obligations, are in the second penalty tier of Article 64(3): up to EUR 10 000 000 or 2% of worldwide annual turnover. The reseller that has become a manufacturer under Article 21 is in the first tier for Articles 13 and 14. [The tiers, and who applies them](\u002Farticles\u002Fcyber-resilience-act-penalties).\n\n## What to put in place\n\nA per-product intake record: the manufacturer's declaration of conformity, the CE mark's location, the Annex II user information in the right language, the support period end date, and the date the importer checked each. A route for vulnerabilities reported by customers to reach the manufacturer, dated. A decision, written down, on whether anything you do to the product (branding, bundling, modification) makes you its manufacturer under Article 21. And a record retained for ten years or the support period. [The distribution pack](\u002Fcyber-resilience-act\u002Fimporters-and-distributors) drafts those records for one product; the dates on them are what an authority reads.\n\n## Sources\n\n- Regulation (EU) 2024\u002F2847, Article 3(16) and (17) for the definitions, Article 19(1) to (8), Article 20(1) to (6), Article 21 (quoted), Article 64(3). Read from the Official Journal text on EUR-Lex on 11 September 2026.\n\nThis is not legal advice. Articles 19 to 21 are two pages; the paragraph references are there so a reseller can read its own list.\n",1789383985471]