Start with the product and the activity
Do not assess the role only at company level. Record:
- the exact product, variant and version;
- the name or trademark under which it is placed on the market;
- who designed, developed or manufactured it, and for whom;
- who first makes it available on the EU market;
- where the person whose name or trademark the product bears is established;
- who supplies it further and whether its properties are changed;
- whether anyone changed its intended purpose or cybersecurity risk after placement;
- for FOSS, who publishes it, controls releases, monetises it and ensures sustained viability.
Then apply the tests below. More than one role may apply.
Am I a manufacturer?
You are likely a manufacturer if you:
- develop or manufacture the product and market it under your name or trademark;
- have it designed, developed or manufactured and market it under your name or trademark;
- place it on the market as a private-label or white-label product under your brand, even when another supplier did the technical work;
- publish it as FOSS under your name or trademark and monetise its supply;
- are an importer or distributor but place it on the market under your own name or trademark; or
- substantially modify it under Article 21 or 22 of the CRA.
A manufacturer may be a natural or legal person. The product may be supplied for payment, monetised in another way or supplied free of charge. Outsourcing development does not transfer the manufacturer’s responsibility to the contractor.
Next: classify the product, perform the cybersecurity risk assessment, meet the essential requirements, choose a permitted conformity route, prepare documentation, handle vulnerabilities and prepare for reporting. Go to Manufacturer obligations, Product classification, Conformity assessment and CRA reporting.
Am I an authorised representative?
You are an authorised representative if you are established in the EU and a manufacturer has appointed you in writing to act on its behalf for specified tasks.
The written mandate determines the tasks. It must permit at least keeping the EU declaration of conformity and technical documentation available to market-surveillance authorities for the required period, providing information and documents following a reasoned request, and cooperating on action to eliminate cybersecurity risks.
The mandate cannot include the manufacturer obligations in Article 13(1)–(11), the first subparagraph of Article 13(12), or Article 13(14). Appointing a representative therefore does not remove the manufacturer’s own responsibility.
Next: maintain the signed mandate, product/version scope, required records, authority contact and a process for escalating requests to the manufacturer.
Am I an importer?
You are likely an importer if you are established in the EU, first place a product with digital elements on the EU market, and the product bears the name or trademark of a person established outside the EU.
Before placement, the importer verifies in particular the manufacturer’s compliance with relevant requirements, the correct conformity assessment, technical documentation, CE marking, EU declaration of conformity, user information and instructions, support period, and identification details. The importer also adds its own contact details as required by the CRA. If there is reason to believe the product is non-compliant or presents a significant cybersecurity risk, it must not be placed on the market until the issue is resolved.
Warning: if you rebrand the product under your own name or trademark, or substantially modify it, Article 21 treats you as its manufacturer and Articles 13 and 14 apply.
Next: go to Importer obligations and use the pre-placement checklist.
Am I a distributor?
You are likely a distributor if you are a person in the supply chain other than the manufacturer or importer, make the product available on the EU market, and do so without affecting its properties.
A distributor acts with due care and verifies before supply, in particular, CE marking, required documents and user information, the support period, and manufacturer and importer identification. Where it has reason to believe the product is non-compliant, it must not make the product available until conformity is restored.
Warning: own branding or a substantial modification converts the distributor into a manufacturer for CRA purposes.
Next: go to Distributor obligations and use the pre-supply checklist.
Am I an open-source software steward?
Assess this role for each FOSS project. An open-source software steward can only be a legal person other than a manufacturer that systematically provides sustained support for the development of specific FOSS intended for commercial activities and ensures its viability, without itself placing that FOSS on the market within the meaning of the CRA.
Merely hosting many unrelated repositories or contributing once does not automatically make a person the steward of every project. Governing a project, managing releases or infrastructure, or providing engineering resources may constitute sustained support.
Next: go to Open source and the CRA and assess Article 24 duties, including reporting according to the support provided.
Am I only a contributor or component user?
A person who only contributes source code to FOSS that is not under their responsibility does not become a manufacturer or steward for that reason alone. Technical permission to commit does not necessarily establish primary control over development, releases and distribution.
If you integrate FOSS into your own marketed product, you are responsible for the compliance of your resulting product. Manufacturers must exercise due diligence when integrating third-party components, including FOSS, and follow the vulnerability-related duties in Article 13(5) and (6).
One company, several roles
Record roles by product and activity. For example:
- a company can manufacture its branded app, import a non-EU manufacturer’s router and distribute another manufacturer’s devices;
- a foundation can steward a non-monetised community edition and manufacture a separate paid edition;
- a company manufacturing a finished product that integrates a third-party library does not thereby manufacture that standalone library, but it remains responsible for the integration and finished product;
- a distributor remains a distributor for an unchanged product but becomes a manufacturer when it applies its own brand or makes a substantial modification;
- a contract developer may supply services to a manufacturer without placing the resulting product on the market under its own name. If it separately markets a component under its own brand, it may manufacture that component.
An internal role register should record: product/version, brand, design owner, CRA manufacturer, manufacturer establishment, importer, distributors, representative and mandate, FOSS steward, placement date, modifications and the substantial-modification conclusion.
When does my role change to manufacturer?
Own name or trademark
An importer or distributor placing a product on the market under its own name or trademark is treated as the manufacturer under Article 21. A contract under which the original manufacturer continues technical support does not by itself change that statutory role.
Substantial modification
A substantial modification is a change after placement on the market that affects conformity with the essential cybersecurity requirements in Part I of Annex I or changes the intended purpose for which the product was assessed.
An importer or distributor making such a change becomes the manufacturer under Article 21. Another natural or legal person that substantially modifies the product and then makes it available on the market is treated as a manufacturer under Article 22. Under Article 22, Articles 13 and 14 apply to the modified part, or to the whole product when the modification affects the cybersecurity of the whole product.
Not every repair or update is substantial. The Commission’s non-binding 2026 guidance explains that:
- replacing a defective part or maintaining a product without changing purpose, conformity or risk profile will generally not be substantial;
- a security update solely reducing risk, without changing purpose or adding new risks, will generally not be substantial;
- even a small feature can be substantial if it creates a new or increased cybersecurity risk that was not assessed;
- a feature changing a product from passive monitoring to device control is likely to change its intended purpose;
- a feature already covered by the original risk assessment may not be substantial if it does not change the risk profile or implementation of requirements.
Assess and document every change before distribution. For a third-party-assessed product, also check whether the notified body must be informed and a new conformity assessment is required.
Quick role flow
-
Does the product bear my name or trademark when placed on the market?
- Yes: likely manufacturer.
- No: continue.
-
Am I established in the EU and first placing on the EU market a product branded by a non-EU person?
- Yes: likely importer.
- No: continue.
-
Do I further supply an unchanged product in the supply chain?
- Yes: likely distributor.
- No: continue.
-
Do I act in the EU under a manufacturer’s written mandate?
Yes: authorised representative within the mandate.
-
As a legal person, do I publish specific non-monetised FOSS and systematically support its development and viability for commercial use?
Yes: assess open-source software steward status.
-
Have I substantially modified a product and made it available on the market?
Yes: manufacturer obligations under Article 21 or 22.
-
Do I perform several of these activities?
Record every role separately; obligations may accumulate.