Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Identify your role under the CRA

Last updated:

Start with the product and the activity

Do not assess the role only at company level. Record:

Then apply the tests below. More than one role may apply.

Am I a manufacturer?

You are likely a manufacturer if you:

A manufacturer may be a natural or legal person. The product may be supplied for payment, monetised in another way or supplied free of charge. Outsourcing development does not transfer the manufacturer’s responsibility to the contractor.

Next: classify the product, perform the cybersecurity risk assessment, meet the essential requirements, choose a permitted conformity route, prepare documentation, handle vulnerabilities and prepare for reporting. Go to Manufacturer obligations, Product classification, Conformity assessment and CRA reporting.

Am I an authorised representative?

You are an authorised representative if you are established in the EU and a manufacturer has appointed you in writing to act on its behalf for specified tasks.

The written mandate determines the tasks. It must permit at least keeping the EU declaration of conformity and technical documentation available to market-surveillance authorities for the required period, providing information and documents following a reasoned request, and cooperating on action to eliminate cybersecurity risks.

The mandate cannot include the manufacturer obligations in Article 13(1)–(11), the first subparagraph of Article 13(12), or Article 13(14). Appointing a representative therefore does not remove the manufacturer’s own responsibility.

Next: maintain the signed mandate, product/version scope, required records, authority contact and a process for escalating requests to the manufacturer.

Am I an importer?

You are likely an importer if you are established in the EU, first place a product with digital elements on the EU market, and the product bears the name or trademark of a person established outside the EU.

Before placement, the importer verifies in particular the manufacturer’s compliance with relevant requirements, the correct conformity assessment, technical documentation, CE marking, EU declaration of conformity, user information and instructions, support period, and identification details. The importer also adds its own contact details as required by the CRA. If there is reason to believe the product is non-compliant or presents a significant cybersecurity risk, it must not be placed on the market until the issue is resolved.

Warning: if you rebrand the product under your own name or trademark, or substantially modify it, Article 21 treats you as its manufacturer and Articles 13 and 14 apply.

Next: go to Importer obligations and use the pre-placement checklist.

Am I a distributor?

You are likely a distributor if you are a person in the supply chain other than the manufacturer or importer, make the product available on the EU market, and do so without affecting its properties.

A distributor acts with due care and verifies before supply, in particular, CE marking, required documents and user information, the support period, and manufacturer and importer identification. Where it has reason to believe the product is non-compliant, it must not make the product available until conformity is restored.

Warning: own branding or a substantial modification converts the distributor into a manufacturer for CRA purposes.

Next: go to Distributor obligations and use the pre-supply checklist.

Am I an open-source software steward?

Assess this role for each FOSS project. An open-source software steward can only be a legal person other than a manufacturer that systematically provides sustained support for the development of specific FOSS intended for commercial activities and ensures its viability, without itself placing that FOSS on the market within the meaning of the CRA.

Merely hosting many unrelated repositories or contributing once does not automatically make a person the steward of every project. Governing a project, managing releases or infrastructure, or providing engineering resources may constitute sustained support.

Next: go to Open source and the CRA and assess Article 24 duties, including reporting according to the support provided.

Am I only a contributor or component user?

A person who only contributes source code to FOSS that is not under their responsibility does not become a manufacturer or steward for that reason alone. Technical permission to commit does not necessarily establish primary control over development, releases and distribution.

If you integrate FOSS into your own marketed product, you are responsible for the compliance of your resulting product. Manufacturers must exercise due diligence when integrating third-party components, including FOSS, and follow the vulnerability-related duties in Article 13(5) and (6).

One company, several roles

Record roles by product and activity. For example:

An internal role register should record: product/version, brand, design owner, CRA manufacturer, manufacturer establishment, importer, distributors, representative and mandate, FOSS steward, placement date, modifications and the substantial-modification conclusion.

When does my role change to manufacturer?

Own name or trademark

An importer or distributor placing a product on the market under its own name or trademark is treated as the manufacturer under Article 21. A contract under which the original manufacturer continues technical support does not by itself change that statutory role.

Substantial modification

A substantial modification is a change after placement on the market that affects conformity with the essential cybersecurity requirements in Part I of Annex I or changes the intended purpose for which the product was assessed.

An importer or distributor making such a change becomes the manufacturer under Article 21. Another natural or legal person that substantially modifies the product and then makes it available on the market is treated as a manufacturer under Article 22. Under Article 22, Articles 13 and 14 apply to the modified part, or to the whole product when the modification affects the cybersecurity of the whole product.

Not every repair or update is substantial. The Commission’s non-binding 2026 guidance explains that:

Assess and document every change before distribution. For a third-party-assessed product, also check whether the notified body must be informed and a new conformity assessment is required.

Quick role flow

  1. Does the product bear my name or trademark when placed on the market?

    • Yes: likely manufacturer.
    • No: continue.
  2. Am I established in the EU and first placing on the EU market a product branded by a non-EU person?

    • Yes: likely importer.
    • No: continue.
  3. Do I further supply an unchanged product in the supply chain?

    • Yes: likely distributor.
    • No: continue.
  4. Do I act in the EU under a manufacturer’s written mandate?

    Yes: authorised representative within the mandate.

  5. As a legal person, do I publish specific non-monetised FOSS and systematically support its development and viability for commercial use?

    Yes: assess open-source software steward status.

  6. Have I substantially modified a product and made it available on the market?

    Yes: manufacturer obligations under Article 21 or 22.

  7. Do I perform several of these activities?

    Record every role separately; obligations may accumulate.