For agencies ยท Regulation (EU) 2024/2847

What the CRA means for agencies that build and resell software

Verified against the Official Journal text on

It depends on how you supply the software, and the line is easy to cross. If you develop software, or have it developed, and supply it under your own name or trademark, you are the manufacturer under the CRA and carry the manufacturer obligations, whether you charge for it or give it away (Art. 3(13)). Putting your brand on someone else's product, or substantially modifying a product already on the market, pulls the same obligations onto you (Art. 21, Art. 22). Bespoke software built for a single client and supplied commercially is still supplied on the market, so treat it as in scope.

Basis: Art. 3(13), Art. 21, Art. 22, Art. 3(22)

Judgment call: Whether one-off delivery to a single business client is "making available on the market" is not spelled out; the definition in Art. 3(22) is broad enough to catch it, so the prudent reading is in scope.

Building under your own name makes you the manufacturer Art. 3(13)

The CRA defines a manufacturer as anyone who develops or manufactures a product, or has it designed, developed, or manufactured, and then markets it under its own name or trademark, whether for payment, monetisation, or free of charge (Art. 3(13)). An agency that writes an app for a client and ships it under the agency brand fits that definition squarely.

The "has it developed" wording matters for agencies that subcontract. Outsourcing the actual coding does not move manufacturer status to the subcontractor if you are the one putting the product on the market under your name. The obligations follow the name on the product, not the keyboard it was typed on.

White-labelling and substantial modification carry the same weight Art. 21, Art. 22, Art. 3(30)

If you take another company's product and place it on the EU market under your own name or trademark, you are treated as the manufacturer and become subject to Articles 13 and 14, even though you did not build it (Art. 21). This is the classic white-label trap: a reseller badge turns into a full manufacturer obligation set.

The same applies if you substantially modify a product already on the market and then make it available (Art. 22). A substantial modification is a change after placing on the market that affects compliance with the essential cybersecurity requirements or changes the intended purpose the product was assessed for (Art. 3(30)). Reskinning is unlikely to qualify; re-architecting or bolting on new connected features may well.

Bespoke, single-client software Art. 3(22), Recital 64, Annex I Part I, Annex I Part II (8)

There is no carve-out for custom work. "Making available on the market" means supplying a product for distribution or use in the course of a commercial activity, whether paid or free (Art. 3(22)). Delivering a tailored system to one business client for their use is supply in the course of business, so the sensible default is that it is in scope and you are its manufacturer.

The CRA does leave one narrow door. Its recitals let a manufacturer deviate from the essential requirements for tailor-made products fitted to a particular purpose for a particular business user, where both sides have explicitly agreed a different set of contractual terms (Recital 64). This is a limited relief on the requirements, not an exit from scope, and it should be papered carefully.

Judgment call: The tailor-made deviation appears in Recital 64 and in carve-outs within Annex I (Part I and Part II (8)) for products made to order for a business user; its exact reach is untested. Treat it as a documented, negotiated exception, not a blanket exemption for custom builds.

Reselling without touching the product is lighter Art. 20, Art. 21

If you resell or distribute a product without changing it and without putting your own brand on it, you are a distributor, not a manufacturer, and you carry the lighter due-care duties instead (Art. 20). The moment you rebrand it or modify it substantially, you flip back into the manufacturer obligations, so the safe habit is to know which hat you wear on each engagement.

What you must do

  • For products you supply under your own name: design, develop, and produce them to the essential cybersecurity requirements, and run vulnerability handling with a coordinated vulnerability disclosure policy. (Art. 13(1), Art. 13(8), Annex I)
  • Draw up technical documentation, carry out the conformity assessment, affix the CE marking, and report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 13(12), Art. 14, Art. 31, Art. 32)
  • Decide, per engagement, whether you are the manufacturer (own-name or substantial modification) or a distributor (resale unchanged), because the obligation set differs sharply. (Art. 3(13), Art. 20, Art. 21)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We only write code, the client ships it under their name. Are we the manufacturer?

Usually not. The manufacturer obligations attach to whoever markets the product under its own name or trademark. If the client places it on the market under their brand, they are the manufacturer; you are the developer they had it made by. Confirm this in the contract so responsibility is unambiguous. (Art. 3(13))

We resell a vendor tool under our own brand. Does the CRA reach us?

Yes. Placing a product on the market under your own name or trademark makes you a manufacturer under the CRA, subject to Articles 13 and 14, even though the vendor built it. Reselling it unchanged under the vendor brand keeps you in the lighter distributor role instead. (Art. 21, Art. 20)

Is custom software we build for one client exempt?

No. There is no exemption for bespoke work; supplying it commercially is making it available on the market. A narrow recital lets you agree deviations from some requirements for tailor-made products for a specific business user, but that is a negotiated exception, not a way out of scope. (Art. 3(22), Recital 64)

When do these duties bite?

Reporting duties for actively exploited vulnerabilities and severe incidents start 11 September 2026. The full obligations, including conformity assessment and CE marking, apply from 11 December 2027. (Art. 71(2))

Work out your role on this project, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes and tells you whether you are the manufacturer, an importer, or a distributor for a given product.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.