Independent information resource Product security · EU CRA
CRA economic operators / 03

CRA Obligations for Distributors

Understand Cyber Resilience Act distributor obligations, including due care, CE marking checks, manufacturer and importer verification, non-conformity, vulnerabilities, corrective measures and market-surveillance cooperation.

IN BRIEF

Distributors do not carry the manufacturer's full product-development obligations, but they are not passive resellers. They act as a compliance checkpoint before making a product available and retain post-market duties when non-conformity, vulnerabilities, significant cybersecurity risks or manufacturer cessation become known.

01 / 11

The CRA Defines Distributor Separately From Importer

Article 3 defines a distributor as a natural or legal person in the supply chain, other than the manufacturer or importer, that makes a product with digital elements available on the Union market without affecting its properties. This distinguishes ordinary downstream supply from the importer role, which concerns an EU-established person placing on the market a product bearing the identity of a person established outside the Union.

02 / 11

Distributors Must Act With Due Care

Article 20 requires distributors to act with due care in relation to CRA requirements when making products with digital elements available on the market. Due care does not mean reproducing the manufacturer's engineering and conformity work. It means operating a supply process that checks the required product evidence and reacts appropriately where information indicates that the product or the manufacturer's processes may not comply.

03 / 11

CE Marking Must Be Verified Before Supply

Before making a product available on the Union market, the distributor must verify that the product bears the required CE marking. The CRA also requires the distributor to verify that the manufacturer and importer have complied with specified identification, information, declaration and support-period obligations and have provided the necessary documents to the distributor. A distributor should therefore have a repeatable release or intake check for each product line.

04 / 11

Manufacturer and Importer Information Must Be Present

The Article 20 verification duty reaches specified manufacturer and importer obligations. This includes checking the required manufacturer identification and contact information, user information and instructions, support-period information and the relevant conformity declaration, together with importer identification where an importer is involved. Missing supply-chain identity information should be treated as a compliance issue rather than a minor packaging defect.

05 / 11

A Suspected Non-Compliant Product Must Not Be Made Available

Where the distributor considers or has reason to believe, based on information in its possession, that the product or the manufacturer's processes do not conform to the essential cybersecurity requirements in Annex I, The distributor must not make the product available until conformity has been restored. Where the product poses a significant cybersecurity risk, the distributor must also inform the manufacturer and market surveillance authorities without undue delay.

06 / 11

Post-Market Non-Conformity Creates Corrective Duties

If a distributor learns after supply that a product or the manufacturer's processes are non-compliant, it must make sure the necessary corrective measures are taken. Depending on the circumstances, those measures can include bringing the product or processes into conformity, withdrawing the product or recalling it. Distributor compliance therefore continues after the sales transaction.

07 / 11

Vulnerabilities Must Be Reported to the Manufacturer

Article 20 expressly requires distributors that become aware of a vulnerability in a product with digital elements to inform the manufacturer without undue delay. The distributor is not substituted for the manufacturer in the Article 14 reporting process merely because it receives the vulnerability information first. Its immediate role is to ensure that the manufacturer receives the information and that any additional distributor obligations are followed.

08 / 11

Significant Cybersecurity Risk Requires Authority Notification

Where a product presents a significant cybersecurity risk, distributors must immediately inform the market surveillance authorities of the Member States in which they made the product available. The information should include details of the non-compliance and corrective measures taken. Distributor incident and product-escalation procedures should therefore include a legal route for determining when market surveillance notification is required.

09 / 11

Distributors Must Cooperate With Market Surveillance Authorities

Following a reasoned request, a distributor must provide the information and documentation needed to demonstrate conformity of the product and the manufacturer's processes with the CRA. It must also cooperate with market surveillance authorities on measures taken to eliminate cybersecurity risks posed by products it made available on the market. Product and supplier records therefore need to remain accessible after sale.

10 / 11

Manufacturer Cessation Also Creates a Distributor Duty

If a distributor becomes aware, based on information in its possession, that the manufacturer has ceased operations and can no longer comply with CRA obligations, Article 20 requires the distributor to inform the relevant market surveillance authorities without undue delay and, by available means and to the extent possible, affected users. Supplier-continuity monitoring is therefore relevant to CRA distributor readiness.

11 / 11

Own-Brand Supply or Substantial Modification Changes the Role

Article 21 provides an important boundary. A distributor is considered the manufacturer where it places a product with digital elements on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market. In that situation the operator becomes subject to Articles 13 and 14 rather than remaining only within the distributor obligations of Article 20.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.