For importers ยท Regulation (EU) 2024/2847

What the CRA requires of importers

Verified against the Official Journal text on

If you are established in the EU and place a product on the market that bears a non-EU maker's name or trademark, you are an importer under the CRA (Art. 3(16)). Your job is to verify, before placing the product on the market, that the manufacturer did its homework: conformity assessment done, technical documentation drawn up, CE marking affixed, and support-period information in place (Art. 19). You must only place compliant products, and pass vulnerability information up and down the chain (Art. 19(1), Art. 19(5)). Sell it under your own name or modify it substantially and you become the manufacturer instead (Art. 21).

Basis: Art. 3(16), Art. 19, Art. 21

Only place compliant products Art. 19(1), Art. 19(3)

An importer may place a product on the market only where it meets the essential cybersecurity requirements in Part I of Annex I and the manufacturer's processes meet the requirements in Part II (Art. 19(1)). This is the backstop duty: you cannot knowingly bring a non-compliant product into the EU, whoever built it.

If you consider or have reason to believe a product or the manufacturer's processes are not in conformity, you must not place it on the market until it is brought into conformity; where it presents a significant cybersecurity risk, you must inform the manufacturer and the market surveillance authorities (Art. 19(3)).

Verify the manufacturer did the work Art. 19(2), Art. 19(4)

Before placing the product on the market, you must check the manufacturer's compliance evidence (Art. 19(2)). This is a documentation-verification duty: you confirm the paperwork exists and the marking is present, and you must be able to produce the documents proving it. You also add your own contact details to the product, its packaging, or an accompanying document (Art. 19(4)).

  • The appropriate conformity assessment procedure has been carried out by the manufacturer. (Art. 19(2))
  • The manufacturer has drawn up the technical documentation. (Art. 19(2))
  • The product bears the CE marking and comes with the EU declaration of conformity and user information. (Art. 19(2))
  • The manufacturer met the identification, contact, and support-period duties (Art. 13(15), (16) and (19)). (Art. 19(2))

Vulnerability and record-keeping duties Art. 19(5), Art. 19(6), Art. 19(7), Art. 19(8)

On becoming aware of a vulnerability in the product, you must inform the manufacturer without undue delay; where the product presents a significant cybersecurity risk, you must immediately inform the market surveillance authorities of the Member States where you made it available (Art. 19(5)). If you find a product you placed is non-conforming, take corrective measures or arrange withdrawal or recall (Art. 19(5)).

You must keep a copy of the EU declaration of conformity available to authorities for at least ten years after placing on the market, or the support period if longer, and be able to make the technical documentation available on request (Art. 19(6), Art. 19(7)). If the manufacturer ceases operations, inform the authorities and, so far as possible, users (Art. 19(8)).

The own-brand and substantial-modification trap Art. 21, Art. 19(5)

The importer role is lighter than the manufacturer role, but it is easy to leave. If you place the product on the market under your own name or trademark, or you carry out a substantial modification, you are treated as the manufacturer and become subject to Articles 13 and 14 in full (Art. 21). At that point the reporting duty under Article 14 becomes yours; as a plain importer it does not, you inform the manufacturer and authorities instead.

What you must do

  • Only place products on the market that meet the essential cybersecurity requirements and whose manufacturer runs compliant vulnerability handling. (Art. 19(1))
  • Verify the conformity assessment was carried out, technical documentation exists, and the product bears the CE marking with required information. (Art. 19(2))
  • On becoming aware of a vulnerability in the product, inform the manufacturer without undue delay; where the product presents a significant cybersecurity risk, immediately inform the market surveillance authorities. (Art. 19(5))
  • Selling under your own name or trademark, or substantial modification, makes the manufacturer obligations yours. (Art. 21)

The dates that decide your planning

11 December 2027
The importer obligations apply from this date, alongside the manufacturer obligations they verify: conformity assessment, technical documentation, and CE marking. Reporting under Article 14 is a manufacturer duty, not an importer one, unless you become the manufacturer under Article 21. (Art. 71(2))

Frequently asked

Do importers have to report vulnerabilities to ENISA?

No. The Article 14 reporting duty (early warning, notification, final report via the single reporting platform) sits with the manufacturer. As an importer you inform the manufacturer of vulnerabilities without undue delay, and inform market surveillance authorities where there is a significant risk. (Art. 19(5), Art. 14)

What exactly must we check before placing a product on the market?

That the manufacturer carried out the conformity assessment and drew up the technical documentation, that the product bears the CE marking with the declaration of conformity and user information, and that the manufacturer met the identification, contact, and support-period duties. Keep proof you checked. (Art. 19(2))

When do the importer duties start?

The importer obligations apply from 11 December 2027, the same date the manufacturer obligations they depend on take effect. There is no earlier reporting trigger for importers, because Article 14 reporting is a manufacturer duty. (Art. 71(2))

When would we stop being an importer and become the manufacturer?

The moment you place the product on the market under your own name or trademark, or carry out a substantial modification. You are then treated as the manufacturer and subject to Articles 13 and 14 in full, including the reporting duty. (Art. 21)

Confirm your role, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes and tells you whether you are an importer, a distributor, or already treated as the manufacturer.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.