Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA obligations for importers

Last updated:

CRA obligations for importers

An importer is an EU-established actor that places on the EU market a product with digital elements bearing the name or trademark of a person established outside the EU. An importer may place only products that meet the essential cybersecurity requirements and whose manufacturer’s processes meet the applicable CRA requirements.

1. Confirm your role

If the last point is false, follow the manufacturer process: Manufacturer obligations.

2. Before placing the product on the market

Record the result and evidence for each model or clearly defined product family:

If a notified body was involved, verify the certificate, the body’s identity and whether its notified scope covers the procedure and product. Verify a notified body

3. Add the importer’s identification

State the following on the product, its packaging or an accompanying document:

The contact details must be in a language easily understood by users and market-surveillance authorities.

4. Place / do not place decision

Do not place the product on the market if you consider or have reason to believe that the product or the manufacturer’s processes do not comply with the CRA. Release it only after conformity has been restored.

If the product presents a significant cybersecurity risk, inform the manufacturer and market-surveillance authorities. If you have reason to believe that it may present such a risk in light of non-technical risk factors, inform the market-surveillance authorities.

Suggested internal decision record: product/model and version; manufacturer; check date and reviewer; evidence and versions reviewed; deviations; decision; escalation recipient and date; release conditions.

5. If a problem is found after placement

  1. Immediately hold further placement or dispatch of affected versions while defining the scope.
  2. Immediately take the corrective measures necessary to restore conformity; withdraw or recall the product where appropriate.
  3. Inform the manufacturer without undue delay when you become aware of a vulnerability, using its published vulnerability contact.
  4. For a significant cybersecurity risk, immediately inform the market-surveillance authorities in every Member State where you made the product available. Give details, particularly of the non-compliance and corrective measures taken.
  5. Record affected models/versions/batches, the timeline, decisions, notifications and proof of corrective action.
  6. Confirm with the manufacturer whether it must submit an Article 14 report through the single reporting platform. The importer does not replace the manufacturer for that duty.

Handoffs: Report significant risk to market surveillance · Manufacturer vulnerability and incident duties · Corrective action, withdrawal and recall

6. Documents, records and cooperation

Practical evidence pack

Before the first supply, obtain from the manufacturer and keep current at least: unique product and version identification; the EU declaration of conformity; evidence of the conformity route and any certificate; manufacturer and vulnerability-reporting contacts; Annex II user information; support end date; the security-update delivery method; an agreement to make technical documentation available to the authority; corrective-action/escalation contacts; and a country/customer map for rapid withdrawal or recall.