Giving a supplier responsibility for product design does not by itself transfer the CRA manufacturer role. The parties need to map the real product arrangement against the Regulation, ensure the manufacturer can perform its cybersecurity risk assessment and conformity duties, and establish reliable flows for technical evidence, vulnerabilities and updates.
ODM Is Not a Defined CRA Economic-Operator Role
ODM is not a defined CRA economic-operator role. The term generally describes a commercial arrangement in which a supplier performs substantial design and development work, but the CRA does not assign obligations merely from that label. The actual manufacturer, importer, distributor and other roles must be determined from the statutory definitions and the facts of the product arrangement.
Designing the Product Does Not Alone Decide Manufacturer Status
An ODM supplier may design and manufacture a product, but Article 3 also recognises a person that has the product designed or developed and markets it under its own name or trademark. The legal manufacturer can therefore be the brand owner in an appropriate arrangement even though the ODM performs most of the technical design work.
The Brand Owner Needs Real Compliance Capability
Where the brand owner is the CRA manufacturer, it needs more than a contractual statement assigning that title. Article 13 requires the manufacturer to perform its own CRA obligations, including a cybersecurity risk assessment, Annex I implementation, due diligence for integrated components, vulnerability handling, technical documentation and the applicable conformity assessment.
The Cybersecurity Risk Assessment Cannot Be Outsourced as a Legal Conclusion
An ODM can supply threat information, architecture details, test results and engineering analysis, but the manufacturer remains responsible for ensuring that the cybersecurity risk assessment required by Article 13 is performed and documented for the marketed product. The manufacturer needs enough knowledge of the design to understand the risks and the controls relied upon.
Technical Documentation Needs Supplier Evidence
Where the ODM controls detailed product design, significant parts of the evidence needed for CRA technical documentation may originate with that supplier. The commercial arrangement should therefore ensure continuing access to architecture information, relevant testing, component data, design decisions and other evidence needed to establish and maintain conformity.
Conformity Assessment Follows the CRA Manufacturer Role
The applicable conformity assessment concerns the marketed product and the entity carrying manufacturer responsibility. An ODM can perform testing or provide evidence, but the manufacturer must ensure the appropriate conformity assessment procedure is completed and that the resulting EU declaration of conformity and CE marking accurately reflect the product's CRA status.
Vulnerability Handling Requires ODM Cooperation
An ODM may control source code, firmware, hardware design or other information needed to investigate vulnerabilities. The manufacturer therefore needs a vulnerability handling process that reaches the ODM quickly, identifies affected versions, enables root-cause analysis and supports timely remediation and security updates during the support period.
Product Changes Need Manufacturer Visibility
An ODM should not make security-relevant design, component or software changes without a mechanism for the manufacturer to assess their compliance effect. Article 13 requires manufacturers to take account of changes in development, production, design and product characteristics. Change-control obligations should therefore be reflected in the operational relationship.
The ODM Can Have Separate Responsibilities for Its Own Products
An ODM supplier can simultaneously have a different CRA role for another product or for a separately marketed component. The parties should avoid treating one relationship label as a company-wide legal classification. CRA roles should be assigned product by product and supply path by supply path.
Use the Supplier Contract to Secure Evidence and Cooperation
A supplier contract should support access to cybersecurity evidence, vulnerability information, testing, security updates, component changes and regulatory cooperation. The supplier contract can allocate operational responsibilities, but the statutory manufacturer role remains determined by the CRA and the factual market arrangement.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.