Independent information resource Product security · EU CRA
CRA economic operators / 14

When Does an EU Importer Assume Additional CRA Responsibilities?

Understand the normal Article 19 duties of an EU importer and when own-brand supply, substantial modification, an authorised-representative mandate or manufacturer cessation creates additional Cyber Resilience Act responsibilities.

IN BRIEF

Importer responsibility has several layers. Article 19 supplies the baseline importer duties. Article 21 can escalate the importer into the manufacturer role. A separate Article 18 mandate can add authorised-representative tasks, while Article 19 itself creates additional action when non-conformity, significant cybersecurity risk, vulnerabilities or manufacturer cessation become known.

01 / 10

Article 19 Is the Importer's Baseline CRA Role

An EU importer does not need an unusual event before CRA duties arise. Once the Article 3 importer definition is satisfied, Article 19 already requires the importer to place only compliant products on the market, perform specified pre-market checks, provide importer identification, respond to non-conformity and vulnerabilities, retain conformity evidence and cooperate with market surveillance authorities.

02 / 10

Article 21 Can Escalate the Importer Into the Manufacturer Role

The most significant increase in responsibility occurs under Article 21. An importer is considered to be a manufacturer and becomes subject to Articles 13 and 14 where it places a product with digital elements on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market.

03 / 10

Own-Brand Market Placement Creates Manufacturer Duties

An importer that removes the original manufacturer's market identity and places the product on the Union market under the importer's own name or trademark cannot remain only an Article 19 importer. Article 21 makes that operator the manufacturer for CRA purposes, bringing the product cybersecurity lifecycle, conformity and reporting obligations in Articles 13 and 14.

04 / 10

Substantial Modification Creates the Same Role Escalation

Article 21 also applies where the importer carries out a substantial modification of a product with digital elements already placed on the market. The importer should therefore assess significant product, software, firmware and intended-purpose changes before supplying the changed product. A substantial modification can convert the importer into the manufacturer.

05 / 10

Becoming Manufacturer Is More Than an Extra Verification Check

Once Article 21 applies, the importer is subject to Articles 13 and 14. This is materially different from adding another importer checklist item. The operator must be capable of performing the manufacturer obligations relevant to the product, including cybersecurity risk assessment, Annex I compliance, vulnerability handling, technical documentation, conformity assessment, support-period obligations, corrective action and Article 14 reporting.

06 / 10

An Authorised-Representative Mandate Is a Separate Source of Duties

An importer can also receive a written mandate to act as an authorised representative if the parties structure the arrangement accordingly. Article 18 duties arise from that mandate and remain legally distinct from the Article 19 importer role. Acting in both capacities does not automatically make the importer the manufacturer unless Article 21 or another manufacturer rule applies.

07 / 10

Non-Conformity Can Trigger Immediate Additional Action

Article 19 requires an importer that knows or has reason to believe an already marketed product is non-compliant to take the corrective measures necessary to bring it into conformity or, where appropriate, withdraw or recall it. The importer's responsibility therefore increases operationally when evidence of non-conformity emerges even though the legal role can remain importer.

08 / 10

A Vulnerability Creates an Importer Notification Duty

When an importer becomes aware of a vulnerability in the product, Article 19 requires it to inform the manufacturer without undue delay. Where the product presents a significant cybersecurity risk, the importer also has immediate market-surveillance notification duties. These duties do not require the importer to have become the manufacturer.

09 / 10

Manufacturer Cessation Creates a Specific Article 19 Duty

Where the importer becomes aware that the manufacturer has ceased operations and can no longer comply with the CRA, Article 19 requires the importer to inform the relevant market surveillance authorities and, by available means and to the extent possible, users of the products it placed on the market. This is an additional importer duty but does not by itself state that the importer becomes the manufacturer.

10 / 10

Importers Should Maintain Role-Escalation Triggers

An importer should maintain explicit review triggers for own-brand launches, white-label arrangements, major customisation, substantial modifications, authorised-representative mandates, significant cybersecurity risks and manufacturer cessation. Each trigger should identify whether the result is an additional Article 19 action, a separate Article 18 role or full manufacturer status under Article 21.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.