CRA obligations for distributors
A distributor is a supply-chain actor other than the manufacturer or importer that makes a product with digital elements available on the EU market without affecting its properties. When making a product available, it must act with due care in relation to the CRA requirements.
1. Confirm your role
- A manufacturer or importer has already placed the product on the EU market.
- We further supply it for distribution or use in the course of a commercial activity, whether for payment or free of charge.
- We do not affect the product’s properties.
- We do not place it under our own name/trademark and have not substantially modified it.
If you obtain the product directly from a person outside the EU and place it on the EU market, check the importer process. If the last point is false, follow Manufacturer obligations.
2. Before making the product available
Record the result for each model or clearly defined product family:
A distributor check is not a new conformity assessment or a technical product audit. Due care nevertheless means that you cannot ignore obvious deficiencies, warnings, vulnerabilities or information available to you as a professional operator.
3. Make available / do not make available decision
Do not make the product available if, on the basis of information in your possession, you consider or have reason to believe that the product or the manufacturer’s processes do not meet the essential requirements in Annex I. Resume supply only after conformity has been secured.
If the product poses a significant cybersecurity risk, inform the manufacturer and market-surveillance authorities without undue delay.
Suggested internal record: product/model/version; supplier; check date and reviewer; evidence; deficiencies; stop-sale/release decision; notifications sent; corrective-action result.
4. If a problem is found after supply
- Stop further sale or supply of affected versions and identify affected stock and customers.
- Make sure that the corrective measures necessary to restore conformity of the product or manufacturer’s processes are taken; withdraw or recall the product where appropriate.
- Inform the manufacturer without undue delay when you become aware of a vulnerability.
- For a significant cybersecurity risk, immediately inform the market-surveillance authorities in every Member State where you made the product available. Give details, particularly of the non-compliance and corrective measures taken.
- Cooperate with the manufacturer, importer and authority; retain decisions, communications and proof that corrective action was completed.
- Confirm who will contact affected users and who will address any Article 14 manufacturer reporting duty.
Handoffs: Manufacturer vulnerability contact · Importer process · Report significant risk to market surveillance · Corrective action, withdrawal and recall
5. Authority information and traceability
- Following a reasoned request from a market-surveillance authority, provide all information and documentation necessary to demonstrate conformity of the product and manufacturer’s processes, in paper or electronic form and in a language easily understood by the authority.
- At its request, cooperate on measures to eliminate the cybersecurity risks of products you made available.
- For ten years, retain information identifying the actor that supplied the product to you and, where available, the actors to whom you supplied it.
- If information available to you shows that the manufacturer has ceased operations and consequently cannot fulfil its CRA duties, inform the relevant authorities without undue delay and, by any means available and to the extent possible, users.
Practical control pack
For each product or model, maintain: product/version identification; a photo or record of CE and mandatory identification details; the EU declaration of conformity or its exact address; current user information and instructions; support end date; supplier and customer traceability; manufacturer and importer contacts; the intake-check result; and any complaint, vulnerability, stop-sale and corrective-action records.