FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Economic Operators

When do the CRA operator obligations for authorised representatives, importers and distributors start applying?

As a rule, they apply from 11 December 2027.

That is the CRA's general application date for the main economic-operator obligations in Chapter II. Earlier application dates in Article 71 concern other parts of the Regulation, such as notified bodies and reporting obligations, not the ordinary importer, distributor and authorised representative obligations as such.

Citations
CRA Economic Operators

If a third-country manufacturer sells directly to an EU end user, must there still be an EU-based responsible operator?

Yes.

The CRA FAQ explains that a product with digital elements can be placed on the Union market only if there is an economic operator established in the Union performing the Article 4 tasks under Regulation (EU) 2019/1020. In direct third-country sales there may be no traditional importer in the usual commercial sense, but that does not remove the requirement. Depending on the setup, the role can be fulfilled by an authorised representative or, if none exists, a fulfilment service provider established in the Union.

CRA Economic Operators

Does a distributor have to keep its own 10-year copy of the declaration of conformity like an importer does?

No, not as a general CRA retention duty.

Under the CRA, the explicit long-term declaration-retention duty is imposed on manufacturers, authorised representatives within their mandate, and importers. Distributors must verify before making the product available that the required marking and documentation obligations have been met, and they must provide necessary information and documentation to authorities further to a reasoned request, but Article 20 does not impose the same express 10-year copy-retention duty on distributors that Article 19(6) imposes on importers.

Citations
CRA Economic Operators

Must importers and distributors redo the manufacturer's full CRA assessment themselves?

No.

Importers and distributors have real due-care and verification duties, but the CRA does not turn them into second manufacturers by default. Importers must check that the manufacturer has carried out the conformity assessment, drawn up the technical documentation, affixed the CE marking, and supplied the required declaration and Annex II information. Distributors must verify the marking and the listed documentation and traceability elements before making the product available. Those roles must react when they have reason to believe there is non-compliance, but they are not required by Articles 19 or 20 to repeat the manufacturer's risk assessment or conformity assessment from scratch.

Citations
CRA Economic Operators

Can an authorised representative become the importer if it actually supplies the product in the Union?

Yes.

The Blue Guide explains that an authorised representative of a third-country manufacturer is no longer acting merely as an authorised representative if it supplies the product to a distributor or directly to a consumer within the Union. In that case it becomes the importer and is subject to the importer's obligations.

CRA Economic Operators

Are distributors required to bring into CRA compliance products that were already placed on the market before 11 December 2027?

No, unless they substantially modify them.

The Commission FAQ says products with digital elements placed on the market before 11 December 2027 are not subject to the CRA requirements, apart from the earlier reporting obligation timing rules, unless they are substantially modified. A distributor is therefore not required to retrofit those pre-application products into CRA compliance merely because it continues making them available on or after 11 December 2027.

Citations
Cyber Resilience Act

Article 69(2)-(3) preserves the general transition rule for products placed before 11 December 2027 while applying Article 14 reporting to earlier products; Article 71 sets the application dates.

CRA Economic Operators

What evidence controls should teams keep to prove the right CRA operator did the right work?

Keep evidence by product and by operator role, not only in a generic CRA folder. The record should show who placed the product on the market, who made it available, whether a non-EU manufacturer has an EU-established Article 4 operator, and whether any importer, distributor or other person triggered manufacturer status by branding the product or substantially modifying it.

For the manufacturer role, keep the EU declaration of conformity, technical documentation, conformity-assessment record, cybersecurity risk assessment, support-period statement, Annex II user information, vulnerability-handling process, and Article 14 reporting evidence. For an authorised representative, keep the signed mandate, the declaration and technical-documentation custody record, authority-request log, and any task limits showing which Article 13 duties remain with the manufacturer.

For importers, keep the pre-placement check that the manufacturer completed conformity assessment, technical documentation, CE marking, declaration, Annex II information and required contact details; keep the importer's own contact details, manufacturer access assurance, declaration copy retention control, and escalation records for non-conformity, vulnerabilities or significant cybersecurity risk. For distributors, keep the due-care check before making the product available, evidence that required documents were supplied, traceability records for suppliers and recipients, and logs of corrective actions, withdrawal, recall, authority cooperation or manufacturer-cessation notices.

Citations
CRA Essential Cybersecurity Requirements

What are the CRA's Essential Cybersecurity Requirements?

The CRA splits the Essential Cybersecurity Requirements into two parts:

- Part I of Annex I covers the cybersecurity properties the product itself must have

- Part II of Annex I covers the vulnerability-handling processes the manufacturer must put in place

A useful compliance map links each applicable Part I outcome and each Part II process to a product control, an owner, test or review evidence, the affected product versions, and the technical-documentation record. The SBOM records at least the top-level software dependencies for component and vulnerability handling. A Part I requirement treated as not applicable still needs the Article 13(4) justification.

Citations
Cyber Resilience Act

Article 6 ties market availability to Annex I conformity; Annex I separates product properties from vulnerability-handling requirements.

CRA Essential Cybersecurity Requirements

Do products with digital elements need to comply with both Part I and Part II of Annex I?

Yes.

Under Article 6, products may only be made available on the market where the product meets the Part I requirements and the manufacturer's processes comply with the Part II requirements.

Citations
Cyber Resilience Act

Article 6 and Article 13(1) require the product and the manufacturer's processes to meet Annex I before the product is placed on the market.

CRA Essential Cybersecurity Requirements

Do Part I and Part II work in exactly the same way over time?

No.

Part I focuses on the product as placed on the market. Part II contains vulnerability-handling obligations that manufacturers must comply with when the product is placed on the market and throughout the support period.

Citations
Cyber Resilience Act

Article 13 and Annex I support the distinction between product properties at market placement and vulnerability handling during the support period.

CRA Essential Cybersecurity Requirements

Does the CRA prescribe one fixed technical checklist or one mandatory methodology for meeting the Essential Cybersecurity Requirements?

No.

The requirements are objective-oriented and technology-neutral. The CRA does not mandate one specific cybersecurity risk-assessment methodology. Manufacturers can choose their methodology, but it must support identifying, evaluating and treating the relevant risks and documenting how the essential requirements are met.

Citations
Cyber Resilience Act

Article 13 requires a cybersecurity risk assessment but does not impose one named risk-assessment method.

CRA Essential Cybersecurity Requirements

Are all Annex I requirements mandatory for every product in exactly the same way?

Not in exactly the same way.

For Part II, manufacturers need to comply with the vulnerability-handling requirements throughout the support period. For Part I, Article 13(3) requires the manufacturer to determine through the cybersecurity risk assessment which point (2) requirements are applicable to the product and how they are implemented. If a specific Part I requirement is not applicable, Article 13(4) requires a clear justification in the technical documentation.

Citations
Cyber Resilience Act

Article 13(3)-(4) requires manufacturers to identify applicable Part I requirements and justify non-applicability in the technical documentation.

CRA Essential Cybersecurity Requirements

What does Annex I Part I, point (1) mean under the Cyber Resilience Act?

It is the general product-level requirement to ensure an appropriate level of cybersecurity based on the risks.

The Commission's March 2026 draft guidance explains that this point is meant to catch additional cybersecurity risks identified by the risk assessment that are not otherwise adequately addressed by the other specific Part I requirements. In most cases, complying with the other applicable Part I requirements will also satisfy point (1), but if additional relevant risks remain, the manufacturer still has to address them at product level.

Citations
Cyber Resilience Act

Annex I Part I point (1) is the general product-level cybersecurity outcome, applied through the Article 13 risk assessment.

CRA Essential Cybersecurity Requirements

Does the CRA require products to be free from all vulnerabilities?

No.

The CRA does not require a product to be free from all vulnerabilities. For placement on the market, the relevant product requirement is that, on the basis of the cybersecurity risk assessment and where applicable, the product is made available without known exploitable vulnerabilities. After placement on the market, the manufacturer must address and remediate relevant vulnerabilities without delay in line with Part II of Annex I.

Citations
Cyber Resilience Act

Annex I Part I point (2)(a) addresses known exploitable vulnerabilities at market placement; Part II point (2) addresses later vulnerability remediation.

CRA Essential Cybersecurity Requirements

Can a manufacturer rely on its own risk appetite, product strategy or cost constraints to leave cybersecurity risks untreated?

No.

The Commission's March 2026 draft guidance says residual cybersecurity risk is assessed against the CRA's regulatory threshold, not against the manufacturer's internal risk tolerance, commercial strategy or cost preferences. If identified risks are not adequately addressed, the product cannot simply be placed on the market anyway.

Citations
Cyber Resilience Act

Article 13 and Annex I Part I point (1) make risk-based cybersecurity a regulatory product requirement, not only an internal risk-acceptance exercise.

Page 10 of 58