CRA obligations for importers
An importer is an EU-established actor that places on the EU market a product with digital elements bearing the name or trademark of a person established outside the EU. An importer may place only products that meet the essential cybersecurity requirements and whose manufacturer’s processes meet the applicable CRA requirements.
1. Confirm your role
- We are established in the EU.
- We place the product on the EU market for the first time.
- The product bears the name or trademark of a person established outside the EU.
- We do not place it under our own name and have not substantially modified it.
If the last point is false, follow the manufacturer process: Manufacturer obligations.
2. Before placing the product on the market
Record the result and evidence for each model or clearly defined product family:
If a notified body was involved, verify the certificate, the body’s identity and whether its notified scope covers the procedure and product. Verify a notified body
3. Add the importer’s identification
State the following on the product, its packaging or an accompanying document:
- your name, registered trade name or registered trademark;
- postal address;
- email address or other digital contact; and
- where applicable, the website at which you can be contacted.
The contact details must be in a language easily understood by users and market-surveillance authorities.
4. Place / do not place decision
Do not place the product on the market if you consider or have reason to believe that the product or the manufacturer’s processes do not comply with the CRA. Release it only after conformity has been restored.
If the product presents a significant cybersecurity risk, inform the manufacturer and market-surveillance authorities. If you have reason to believe that it may present such a risk in light of non-technical risk factors, inform the market-surveillance authorities.
Suggested internal decision record: product/model and version; manufacturer; check date and reviewer; evidence and versions reviewed; deviations; decision; escalation recipient and date; release conditions.
5. If a problem is found after placement
- Immediately hold further placement or dispatch of affected versions while defining the scope.
- Immediately take the corrective measures necessary to restore conformity; withdraw or recall the product where appropriate.
- Inform the manufacturer without undue delay when you become aware of a vulnerability, using its published vulnerability contact.
- For a significant cybersecurity risk, immediately inform the market-surveillance authorities in every Member State where you made the product available. Give details, particularly of the non-compliance and corrective measures taken.
- Record affected models/versions/batches, the timeline, decisions, notifications and proof of corrective action.
- Confirm with the manufacturer whether it must submit an Article 14 report through the single reporting platform. The importer does not replace the manufacturer for that duty.
Handoffs: Report significant risk to market surveillance · Manufacturer vulnerability and incident duties · Corrective action, withdrawal and recall
6. Documents, records and cooperation
- Keep a copy of the EU declaration of conformity for at least ten years after the product was placed on the market or for the support period, whichever is longer.
- Ensure that the technical documentation can be made available to market surveillance on request.
- Following a reasoned request, provide all information and documentation necessary to demonstrate conformity of the product and manufacturer’s processes, in paper or electronic form and in a language easily understood by the authority.
- Cooperate, at the authority’s request, on measures to eliminate cybersecurity risks.
- For ten years, retain information identifying who supplied the product to you and, where available, to whom you supplied it.
- If you learn that the manufacturer has ceased operations and consequently cannot fulfil its CRA duties, inform the relevant authorities and, by any means available and to the extent possible, users.
Practical evidence pack
Before the first supply, obtain from the manufacturer and keep current at least: unique product and version identification; the EU declaration of conformity; evidence of the conformity route and any certificate; manufacturer and vulnerability-reporting contacts; Annex II user information; support end date; the security-update delivery method; an agreement to make technical documentation available to the authority; corrective-action/escalation contacts; and a country/customer map for rapid withdrawal or recall.