Manufacturer, importer, distributor: who carries which CRA obligations?

The Regulation does not reason by company size but by economic role. The same company can be a manufacturer for one product and a distributor for another — and the obligations differ.

Four roles, four regimes

The role is determined product by product, based on what you do with that product on the Union market. It is not a property of the company.

Manufacturer

You design, develop or have the product manufactured, and you place it on the market under your own name or trademark. This is the role that carries most of the obligations.

Importer

You place on the Union market a product manufactured outside it. You do not redo the manufacturer's work, but you must verify that it was done.

Distributor

You make the product available on the market without being the manufacturer or the importer. Your obligations are duties of care.

Open-source software steward

You provide sustained support to the development of open-source software intended for commercial use, without directly profiting from it. The Regulation applies a specific, lighter regime to you (Art. 24).

Obligations, role by role

This is the table the assessment engine applies: each obligation carries the article or annex it derives from, and the deadline at which it becomes enforceable.

Manufacturer

ObligationDeadlineSource
Cybersecurity risk assessment
Carry out and document the product's risk assessment, kept up to date throughout the lifecycle.
By Dec. 2027Annex I
Essential security requirements
Design, develop and produce the product in accordance with the essential cybersecurity requirements.
By Dec. 2027Annex I
Vulnerability handling
Set up a vulnerability management process (identification, remediation, coordinated disclosure).
By Dec. 2027Annex I
Software bill of materials (SBOM)
Establish and maintain an SBOM covering at least the top-level dependencies.
By Dec. 2027Annex I
Technical documentation
Compile the technical documentation demonstrating conformity, before placing on the market.
By Dec. 2027Annex VII
Conformity assessment
Carry out the conformity assessment applicable to the product's class.
By Dec. 2027Art. 32
CE marking and EU declaration
Draw up the EU declaration of conformity and affix the CE marking.
By Dec. 2027Art. 13
24 h / 72 h notification
Notify the CSIRT and ENISA of any actively exploited vulnerability or severe incident (early warning 24 h, notification 72 h).
By Sept. 2026Art. 14
Support period and updates
Provide security updates during the defined support period and make it public.
OngoingArt. 13

Importer

ObligationDeadlineSource
Verify the conformity assessment
Ensure the manufacturer has carried out the conformity assessment and established the technical documentation.
By Dec. 2027Art. 19
Verify CE marking and documentation
Check the presence of the CE marking, the EU declaration and the required instructions.
By Dec. 2027Art. 19
Cooperation and information
Inform the manufacturer and authorities of risks, and cooperate on corrective measures.
OngoingArt. 19

Distributor

ObligationDeadlineSource
Verify CE marking and instructions
Check the presence of the CE marking and instructions before making the product available.
By Dec. 2027Art. 20
Due care
Act with due care; do not make available a product presumed non-compliant.
OngoingArt. 20
Information in case of risk
Inform the manufacturer/importer and authorities in case of a risk or established non-compliance.
OngoingArt. 20

Open-source software steward

ObligationDeadlineSource
Coordinated disclosure policy
Put in place a coordinated vulnerability disclosure policy.
OngoingArt. 24
Reporting of exploited vulnerabilities
Cooperate and report actively exploited vulnerabilities where applicable.
By Sept. 2026Art. 14
Cybersecurity documentation
Document the product's cybersecurity aspects in a verifiable manner.
By Dec. 2027Art. 24

What this changes in practice

The costliest difference is the one between manufacturer and distributor. The manufacturer must produce the evidence: risk assessment, security-by-design requirements, software bill of materials, vulnerability handling process, technical documentation, EU declaration of conformity. The distributor must check that this evidence exists and react when it is missing.

The classic mistake in an industrial SME is to think of oneself as a mere integrator while the product reaches the customer under one's own brand. The role follows from how the product is actually placed on the market, not from what the contract is called.

What if I hold several roles?

That is common: you manufacture one range and distribute a partner's. Each product is then treated separately, under the regime matching the role you hold for it.

Frequently asked questions

Am I the manufacturer if a subcontractor produces the goods?

Yes. Outsourcing production does not transfer the role: whoever places the product on the market under their own name or trademark is the manufacturer within the meaning of the Regulation, and carries the corresponding obligations.

Must an importer compile the technical documentation?

No, but before placing the product on the market the importer must make sure the manufacturer has drawn it up, that the conformity assessment procedure has been carried out and that the CE marking is affixed (Art. 19).

What should a distributor do on discovering a problem?

The distributor acts with due care (Art. 20): it does not make available a product it knows to be non-compliant, and it informs the manufacturer and the market surveillance authorities when it becomes aware of a vulnerability.

Do obligations depend on company size?

No. The economic role and the product class determine the obligations, not headcount. An SME placing a product on the market under its own brand is a manufacturer, with the obligations that entails.

Source: Regulation (EU) 2024/2847, Articles 13, 19, 20 and 24.

Identify your role and your obligations

The assessment asks what you do with the product, derives your role, and lists the matching obligations with their deadline and source.

Start the free assessment

Understanding the CRA, topic by topic

FirmVox is a compliance assistance tool. It is not legal advice and does not replace consulting the official text or qualified counsel.

CRA: manufacturer, importer and distributor obligations — FirmVox