Independent information resource Product security · EU CRA
CRA importers and distributors / 02

What Must CRA Distributors Verify?

The due-care and verification checks distributors must perform under Article 20 before making CRA-covered products available on the Union market.

IN BRIEF

Distributor verification is narrower than importer verification but still needs a repeatable intake or release process. Distributors should check the required product and operator information, preserve supplier records and maintain escalation routes for non-conformity, vulnerabilities and significant cybersecurity risk.

01 / 08

Act With Due Care

Article 20 begins with a general due-care obligation. A distributor should therefore use a controlled process for CRA-covered products rather than assuming that compliance is solely the upstream supplier's concern.

02 / 08

Verify CE Marking

Before making the product available, verify that it bears CE marking. Missing CE marking should trigger a hold and supplier escalation rather than proceeding with ordinary sale.

03 / 08

Verify Specified Manufacturer Obligations

Article 20 points distributors to specified manufacturer duties covering product and manufacturer information, user information, support information and the declaration of conformity. The distributor should verify that the required materials have been provided.

04 / 08

Verify Importer Identification Where Applicable

Where an importer is involved, verify the Article 19(4) importer identification information. This helps preserve the EU supply-chain identity for products from non-EU manufacturers.

05 / 08

Do Not Reproduce the Manufacturer's Engineering Assessment

The distributor's role is verification and due care, not repeating the manufacturer's cybersecurity risk assessment or conformity assessment. The distributor should nevertheless react to obvious gaps or credible information indicating non-compliance.

06 / 08

Stop Supply When Non-Conformity Is Suspected

If the distributor considers or has reason to believe the product or manufacturer processes are not in conformity with Annex I, it must not make the product available until conformity has been restored.

07 / 08

Escalate Significant Cybersecurity Risk

Where the product presents a significant cybersecurity risk, the distributor has notification duties toward the manufacturer and relevant market surveillance authorities.

08 / 08

Maintain a Distributor Release Checklist

A practical checklist should record CE marking, required manufacturer and importer information, documents received, supplier identity, escalation decisions and the person approving release.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.