Manufacturer, importer, distributor: who carries which CRA obligations?
The Regulation does not reason by company size but by economic role. The same company can be a manufacturer for one product and a distributor for another — and the obligations differ.
Four roles, four regimes
The role is determined product by product, based on what you do with that product on the Union market. It is not a property of the company.
Manufacturer
You design, develop or have the product manufactured, and you place it on the market under your own name or trademark. This is the role that carries most of the obligations.
Importer
You place on the Union market a product manufactured outside it. You do not redo the manufacturer's work, but you must verify that it was done.
Distributor
You make the product available on the market without being the manufacturer or the importer. Your obligations are duties of care.
Open-source software steward
You provide sustained support to the development of open-source software intended for commercial use, without directly profiting from it. The Regulation applies a specific, lighter regime to you (Art. 24).
Obligations, role by role
This is the table the assessment engine applies: each obligation carries the article or annex it derives from, and the deadline at which it becomes enforceable.
Manufacturer
| Obligation | Deadline | Source |
|---|---|---|
| Cybersecurity risk assessment Carry out and document the product's risk assessment, kept up to date throughout the lifecycle. | By Dec. 2027 | Annex I |
| Essential security requirements Design, develop and produce the product in accordance with the essential cybersecurity requirements. | By Dec. 2027 | Annex I |
| Vulnerability handling Set up a vulnerability management process (identification, remediation, coordinated disclosure). | By Dec. 2027 | Annex I |
| Software bill of materials (SBOM) Establish and maintain an SBOM covering at least the top-level dependencies. | By Dec. 2027 | Annex I |
| Technical documentation Compile the technical documentation demonstrating conformity, before placing on the market. | By Dec. 2027 | Annex VII |
| Conformity assessment Carry out the conformity assessment applicable to the product's class. | By Dec. 2027 | Art. 32 |
| CE marking and EU declaration Draw up the EU declaration of conformity and affix the CE marking. | By Dec. 2027 | Art. 13 |
| 24 h / 72 h notification Notify the CSIRT and ENISA of any actively exploited vulnerability or severe incident (early warning 24 h, notification 72 h). | By Sept. 2026 | Art. 14 |
| Support period and updates Provide security updates during the defined support period and make it public. | Ongoing | Art. 13 |
Importer
| Obligation | Deadline | Source |
|---|---|---|
| Verify the conformity assessment Ensure the manufacturer has carried out the conformity assessment and established the technical documentation. | By Dec. 2027 | Art. 19 |
| Verify CE marking and documentation Check the presence of the CE marking, the EU declaration and the required instructions. | By Dec. 2027 | Art. 19 |
| Cooperation and information Inform the manufacturer and authorities of risks, and cooperate on corrective measures. | Ongoing | Art. 19 |
Distributor
| Obligation | Deadline | Source |
|---|---|---|
| Verify CE marking and instructions Check the presence of the CE marking and instructions before making the product available. | By Dec. 2027 | Art. 20 |
| Due care Act with due care; do not make available a product presumed non-compliant. | Ongoing | Art. 20 |
| Information in case of risk Inform the manufacturer/importer and authorities in case of a risk or established non-compliance. | Ongoing | Art. 20 |
Open-source software steward
| Obligation | Deadline | Source |
|---|---|---|
| Coordinated disclosure policy Put in place a coordinated vulnerability disclosure policy. | Ongoing | Art. 24 |
| Reporting of exploited vulnerabilities Cooperate and report actively exploited vulnerabilities where applicable. | By Sept. 2026 | Art. 14 |
| Cybersecurity documentation Document the product's cybersecurity aspects in a verifiable manner. | By Dec. 2027 | Art. 24 |
What this changes in practice
The costliest difference is the one between manufacturer and distributor. The manufacturer must produce the evidence: risk assessment, security-by-design requirements, software bill of materials, vulnerability handling process, technical documentation, EU declaration of conformity. The distributor must check that this evidence exists and react when it is missing.
The classic mistake in an industrial SME is to think of oneself as a mere integrator while the product reaches the customer under one's own brand. The role follows from how the product is actually placed on the market, not from what the contract is called.
What if I hold several roles?
That is common: you manufacture one range and distribute a partner's. Each product is then treated separately, under the regime matching the role you hold for it.
Frequently asked questions
Am I the manufacturer if a subcontractor produces the goods?
Yes. Outsourcing production does not transfer the role: whoever places the product on the market under their own name or trademark is the manufacturer within the meaning of the Regulation, and carries the corresponding obligations.
Must an importer compile the technical documentation?
No, but before placing the product on the market the importer must make sure the manufacturer has drawn it up, that the conformity assessment procedure has been carried out and that the CE marking is affixed (Art. 19).
What should a distributor do on discovering a problem?
The distributor acts with due care (Art. 20): it does not make available a product it knows to be non-compliant, and it informs the manufacturer and the market surveillance authorities when it becomes aware of a vulnerability.
Do obligations depend on company size?
No. The economic role and the product class determine the obligations, not headcount. An SME placing a product on the market under its own brand is a manufacturer, with the obligations that entails.
Source: Regulation (EU) 2024/2847, Articles 13, 19, 20 and 24.