Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA obligations for distributors

Last updated:

CRA obligations for distributors

A distributor is a supply-chain actor other than the manufacturer or importer that makes a product with digital elements available on the EU market without affecting its properties. When making a product available, it must act with due care in relation to the CRA requirements.

1. Confirm your role

If you obtain the product directly from a person outside the EU and place it on the EU market, check the importer process. If the last point is false, follow Manufacturer obligations.

2. Before making the product available

Record the result for each model or clearly defined product family:

A distributor check is not a new conformity assessment or a technical product audit. Due care nevertheless means that you cannot ignore obvious deficiencies, warnings, vulnerabilities or information available to you as a professional operator.

3. Make available / do not make available decision

Do not make the product available if, on the basis of information in your possession, you consider or have reason to believe that the product or the manufacturer’s processes do not meet the essential requirements in Annex I. Resume supply only after conformity has been secured.

If the product poses a significant cybersecurity risk, inform the manufacturer and market-surveillance authorities without undue delay.

Suggested internal record: product/model/version; supplier; check date and reviewer; evidence; deficiencies; stop-sale/release decision; notifications sent; corrective-action result.

4. If a problem is found after supply

  1. Stop further sale or supply of affected versions and identify affected stock and customers.
  2. Make sure that the corrective measures necessary to restore conformity of the product or manufacturer’s processes are taken; withdraw or recall the product where appropriate.
  3. Inform the manufacturer without undue delay when you become aware of a vulnerability.
  4. For a significant cybersecurity risk, immediately inform the market-surveillance authorities in every Member State where you made the product available. Give details, particularly of the non-compliance and corrective measures taken.
  5. Cooperate with the manufacturer, importer and authority; retain decisions, communications and proof that corrective action was completed.
  6. Confirm who will contact affected users and who will address any Article 14 manufacturer reporting duty.

Handoffs: Manufacturer vulnerability contact · Importer process · Report significant risk to market surveillance · Corrective action, withdrawal and recall

5. Authority information and traceability

Practical control pack

For each product or model, maintain: product/version identification; a photo or record of CE and mandatory identification details; the EU declaration of conformity or its exact address; current user information and instructions; support end date; supplier and customer traceability; manufacturer and importer contacts; the intake-check result; and any complaint, vulnerability, stop-sale and corrective-action records.