A contractor can perform development tasks, testing and remediation work, but CRA obligations continue to follow the legal manufacturer. Outsourcing arrangements should therefore give the manufacturer sufficient technical visibility, evidence rights, vulnerability cooperation and change control to perform its statutory responsibilities throughout the product lifecycle.
Outsourcing Development Does Not Remove Manufacturer Responsibility
Outsourcing development does not remove manufacturer responsibility where the commissioning company remains the CRA manufacturer. Article 3 expressly includes a person that has the product designed, developed or manufactured and then markets the resulting product under its name or trademark. A manufacturer cannot therefore assume that using an external development agency transfers its statutory CRA role.
The Contractor and Manufacturer Perform Different Functions
A contractor can design architecture, write software, manufacture hardware, test security controls or maintain components without automatically becoming the manufacturer of the customer's product. The CRA role analysis should distinguish the party performing technical work from the legal entity responsible for the marketed product.
The Cybersecurity Risk Assessment Remains a Manufacturer Obligation
Article 13 requires the manufacturer to perform and document a cybersecurity risk assessment and to take it into account throughout planning, design, development, production, delivery and maintenance. Contractors can contribute threat analysis and technical evidence, but the manufacturer remains responsible for ensuring that the cybersecurity risk assessment exists and properly informs the marketed product.
Outsourced Engineering Must Support Annex I Compliance
The manufacturer must ensure that the product is designed, developed and produced in accordance with the applicable essential cybersecurity requirements in Annex I. Where external engineers control parts of the architecture or codebase, development requirements and acceptance criteria should give the manufacturer enough assurance that those outsourced elements support Annex I compliance.
The Manufacturer Needs Durable Technical Documentation Rights
Outsourcing can create evidence risk when the contractor controls architecture records, test evidence or component information. The manufacturer still needs the technical documentation required by Article 31 and Annex VII. Contracts and working practices should therefore preserve access to the evidence needed before market placement and throughout the period for which the manufacturer must support compliance and authority requests.
Conformity Assessment Cannot Be Treated as the Contractor's Problem
A contractor may perform testing or prepare conformity inputs, but the manufacturer remains responsible for ensuring the applicable conformity assessment is carried out for the product it places on the market. The EU declaration of conformity and CE marking ultimately need to correspond to the manufacturer's legal responsibility for that product.
The Support Period Requires Long-Term Supplier Planning
Manufacturer responsibilities continue during the support period even where the original development team was external. The manufacturer should therefore plan how source code, build systems, signing materials, architecture knowledge and remediation capability will remain available if the contractor relationship changes or ends.
Vulnerability Handling Must Work Across Organisational Boundaries
Outsourced development can place critical debugging and remediation knowledge outside the manufacturer's organisation. The vulnerability handling process should define how reports reach the contractor, how affected versions are identified, how fixes are developed and tested, and how security updates reach supported users without unnecessary delay.
Article 14 Reporting Still Belongs to the Manufacturer
Where Article 14 applies, the manufacturer has the CRA reporting obligation for actively exploited vulnerabilities and severe incidents affecting product security. A contractor can provide detection, investigation and evidence support, but contractual allocation does not by itself replace the manufacturer as the reporting party under Article 14.
Changes by the Contractor Need Product Governance
Manufacturers need visibility into changes made by outsourced development teams because changes in design, dependencies, features and production processes can affect cybersecurity risk and conformity. Release governance should require security-relevant changes to be documented and reviewed before the resulting product version is commercially released.
Contractual Allocation Should Support the Statutory Role
Contractual allocation can define development standards, evidence ownership, vulnerability response times, update obligations, audit rights, component disclosure, change control and transition assistance. Those arrangements are valuable operational controls, but the manufacturer remains responsible for the CRA obligations attached to its statutory role.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.