CRA responsibilities follow the legal role an organisation performs in relation to a specific product. Manufacturers own the main cybersecurity lifecycle and conformity duties. Importers verify products entering the Union market from non-EU manufacturers. Distributors perform due-care and verification duties when making products available. Authorised representatives act only within a written mandate, and own-brand supply or substantial modification can shift manufacturer responsibilities to another operator.
Economic Operator Is a Defined CRA Term
Article 3 defines an economic operator as the manufacturer, authorised representative, importer, distributor or another natural or legal person subject to obligations concerning the manufacture of products with digital elements or their making available on the market under the Regulation. This means CRA role analysis should be performed product by product. A company can act as manufacturer for one product, importer for another and distributor for another depending on how each product is developed, branded and supplied.
The Manufacturer Carries the Main Product Responsibility
Article 13 places the central CRA lifecycle responsibilities on the manufacturer. The manufacturer must ensure that the product is designed, developed and produced in accordance with the applicable essential cybersecurity requirements, perform and document a cybersecurity risk assessment, exercise due diligence when integrating third-party components, handle vulnerabilities during the support period, prepare technical documentation and complete the applicable conformity assessment. Article 14 also gives manufacturers the CRA reporting duties for actively exploited vulnerabilities and severe incidents.
An Authorised Representative Does Not Replace the Manufacturer
Article 18 allows a manufacturer to appoint an authorised representative established in the Union through a written mandate. The representative can perform specified tasks such as keeping conformity documentation available, responding to reasoned authority requests and cooperating with market surveillance authorities. However, core manufacturer obligations listed in Article 18 cannot be delegated through that mandate. Appointment of an authorised representative therefore does not transfer the manufacturer's underlying design and product-security responsibility.
The Importer Is the EU Entry-Point Operator for a Non-EU Manufacturer
The CRA defines an importer as a person established in the Union who places on the market a product with digital elements bearing the name or trademark of a person established outside the Union. Article 19 requires importers to place only compliant products on the market and to verify key manufacturer conformity steps, documentation, CE marking, declarations, product information and manufacturer identification before market placement.
A Distributor Has a Different Supply-Chain Position
A distributor is a person in the supply chain, other than the manufacturer or importer, that makes a product with digital elements available on the Union market without affecting its properties. Article 20 requires distributors to act with due care and verify specified product and economic-operator information before making the product available. Their role is different from the importer because they do not perform the first Union-market placement of a product bearing a non-EU manufacturer's identity.
Importers and Distributors Can Become Manufacturers
Article 21 prevents operators from avoiding manufacturer responsibility through commercial labels. An importer or distributor is considered the manufacturer for CRA purposes where it places a product with digital elements on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market. In that situation Articles 13 and 14 apply to that operator as manufacturer.
Other Persons Can Also Assume Manufacturer Obligations
Article 22 extends the manufacturer concept beyond the ordinary manufacturer, importer and distributor roles. Another natural or legal person that carries out a substantial modification and makes the modified product available on the market is considered a manufacturer for CRA purposes. Depending on the cybersecurity effect of the modification, the obligations can apply to the affected part of the product or to the product as a whole.
Economic Operators Need Supply-Chain Traceability
Article 23 requires economic operators, on request, to identify economic operators that supplied them with a product with digital elements and, where available, those to whom they supplied the product. That information must be available for ten years after supply in each direction. Role mapping should therefore be connected to product and supply-chain records rather than maintained only as a legal memo.
Market Surveillance Can Reach the Whole Supply Chain
CRA market surveillance is not limited to manufacturers. Authorities can request information, assess products and require cooperation from relevant economic operators. Importers and distributors also have their own duties to respond to non-conformity, significant cybersecurity risk and manufacturer cessation. Companies should therefore define authority-response ownership for every CRA role they perform.
Map Roles Before Assigning Compliance Work
A practical CRA role map should identify the marketed product, entity whose name or trademark appears on it, development owner, non-EU manufacturer where relevant, EU importer, distributors, authorised representative and any person making a substantial modification. Record the legal basis for each role and link it to the corresponding product evidence and operational duties. This prevents engineering teams from assuming that the software developer is always the manufacturer or procurement teams from assuming that an importer is merely a reseller.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.