Independent information resource Product security · EU CRA
CRA economic operators / 11

CRA Responsibilities When Development Is Outsourced

Understand Cyber Resilience Act responsibilities when software or hardware development is outsourced, including manufacturer status, risk assessment, Annex I, documentation, conformity, support and vulnerability handling.

IN BRIEF

A contractor can perform development tasks, testing and remediation work, but CRA obligations continue to follow the legal manufacturer. Outsourcing arrangements should therefore give the manufacturer sufficient technical visibility, evidence rights, vulnerability cooperation and change control to perform its statutory responsibilities throughout the product lifecycle.

01 / 11

Outsourcing Development Does Not Remove Manufacturer Responsibility

Outsourcing development does not remove manufacturer responsibility where the commissioning company remains the CRA manufacturer. Article 3 expressly includes a person that has the product designed, developed or manufactured and then markets the resulting product under its name or trademark. A manufacturer cannot therefore assume that using an external development agency transfers its statutory CRA role.

02 / 11

The Contractor and Manufacturer Perform Different Functions

A contractor can design architecture, write software, manufacture hardware, test security controls or maintain components without automatically becoming the manufacturer of the customer's product. The CRA role analysis should distinguish the party performing technical work from the legal entity responsible for the marketed product.

03 / 11

The Cybersecurity Risk Assessment Remains a Manufacturer Obligation

Article 13 requires the manufacturer to perform and document a cybersecurity risk assessment and to take it into account throughout planning, design, development, production, delivery and maintenance. Contractors can contribute threat analysis and technical evidence, but the manufacturer remains responsible for ensuring that the cybersecurity risk assessment exists and properly informs the marketed product.

04 / 11

Outsourced Engineering Must Support Annex I Compliance

The manufacturer must ensure that the product is designed, developed and produced in accordance with the applicable essential cybersecurity requirements in Annex I. Where external engineers control parts of the architecture or codebase, development requirements and acceptance criteria should give the manufacturer enough assurance that those outsourced elements support Annex I compliance.

05 / 11

The Manufacturer Needs Durable Technical Documentation Rights

Outsourcing can create evidence risk when the contractor controls architecture records, test evidence or component information. The manufacturer still needs the technical documentation required by Article 31 and Annex VII. Contracts and working practices should therefore preserve access to the evidence needed before market placement and throughout the period for which the manufacturer must support compliance and authority requests.

06 / 11

Conformity Assessment Cannot Be Treated as the Contractor's Problem

A contractor may perform testing or prepare conformity inputs, but the manufacturer remains responsible for ensuring the applicable conformity assessment is carried out for the product it places on the market. The EU declaration of conformity and CE marking ultimately need to correspond to the manufacturer's legal responsibility for that product.

07 / 11

The Support Period Requires Long-Term Supplier Planning

Manufacturer responsibilities continue during the support period even where the original development team was external. The manufacturer should therefore plan how source code, build systems, signing materials, architecture knowledge and remediation capability will remain available if the contractor relationship changes or ends.

08 / 11

Vulnerability Handling Must Work Across Organisational Boundaries

Outsourced development can place critical debugging and remediation knowledge outside the manufacturer's organisation. The vulnerability handling process should define how reports reach the contractor, how affected versions are identified, how fixes are developed and tested, and how security updates reach supported users without unnecessary delay.

09 / 11

Article 14 Reporting Still Belongs to the Manufacturer

Where Article 14 applies, the manufacturer has the CRA reporting obligation for actively exploited vulnerabilities and severe incidents affecting product security. A contractor can provide detection, investigation and evidence support, but contractual allocation does not by itself replace the manufacturer as the reporting party under Article 14.

10 / 11

Changes by the Contractor Need Product Governance

Manufacturers need visibility into changes made by outsourced development teams because changes in design, dependencies, features and production processes can affect cybersecurity risk and conformity. Release governance should require security-relevant changes to be documented and reviewed before the resulting product version is commercially released.

11 / 11

Contractual Allocation Should Support the Statutory Role

Contractual allocation can define development standards, evidence ownership, vulnerability response times, update obligations, audit rights, component disclosure, change control and transition assistance. Those arrangements are valuable operational controls, but the manufacturer remains responsible for the CRA obligations attached to its statutory role.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.