Manufacturers carry the heaviest load. They must assess cybersecurity risks, determine which Annex I Part I requirements are relevant, justify non applicability, exercise due diligence when integrating components, determine and disclose a support period, draw up technical documentation, complete conformity assessment, and issue the declaration before affixing the CE marking.
They also need a single point of contact for vulnerability communication, user instructions under Annex II, corrective action procedures, and cooperation with authorities.