Cyber Resilience Act

Consumer

Legal definition Art. 3(18) CRA

“a natural person who acts for purposes which are outside that person’s trade, business, craft or profession”
Regulation (EU) 2024/2847, Art. 3(18) CRA

A consumer under the Cyber Resilience Act (CRA) is a natural person acting for private purposes. Article 3(18) looks only at the purpose a person acts for, not at who that person is. Someone buying a connected camera for their own living room acts as a consumer. Someone buying the same camera for the company does not.

The term describes a role, not a permanent characteristic. The same person can be a procurement lead at work and a consumer at home.

The counterpart is the economic operator

Obligations under the CRA always fall on an Economic operator. Article 3(12) covers the manufacturer, the authorised representative, the importer, the distributor and any other person subject to obligations relating to the manufacture of products with digital elements or to making them available on the market.

On the consumer the CRA imposes nothing. Consumers appear only as the protected side, and even that at surprisingly few points.

Obligations do not hang on the consumer

The essential cybersecurity requirements in Annex I apply to every Product with digital elements placed on the market. Whether the buyer acts privately or professionally makes no difference. A purely industrial product must meet the same requirements as a household appliance.

Nor are the information duties cut to consumers. Annex II is headed Information and instructions to the user, and the CRA nowhere defines the user. That notion is wider than the consumer, since it covers anyone who operates the product, whatever the purpose. The same holds for the support period, which under Article 13(8) runs for at least five years unless the product is expected to be in use for a shorter time.

Where the term actually decides something

In the enacting terms the consumer surfaces at only a handful of places. Those few repay close reading.

  • Article 30(1). For products in the form of software, the CE marking is affixed either to the EU declaration of conformity or on the website accompanying the software product. In the latter case, the relevant section of that website must be easily and directly accessible to consumers.
  • Article 52(11). Market surveillance authorities have to tell consumers where to submit complaints about possible non-compliance, and how to reach the mechanisms for reporting vulnerabilities, incidents and cyber threats.
  • Article 65. Infringements by economic operators that harm, or may harm, the collective interests of consumers fall under Directive (EU) 2020/1828 on representative actions. Article 67 inserts the CRA into Annex I to that Directive as point 69, and recital 124 gives 11 December 2027 as the starting date.
  • Involvement. Consumer associations are among the stakeholders the Commission consults under Article 9(1). Under Article 52(12), market surveillance authorities have to facilitate, where relevant, cooperation with relevant stakeholders, including consumer organisations.

Consumer products in Annex III

One further effect is indirect and concerns product classification. Annex III lists several class I categories that in practice occur only in a private setting:

  • smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
  • internet connected toys covered by Directive 2009/48/EC that have social interactive or location tracking features
  • personal wearables with a health monitoring purpose to which Regulation (EU) 2017/745 or (EU) 2017/746 does not apply, or wearables intended for use by and for children

Classification follows the function, not the target group. In practice it still means that typical consumer products count as Important products with digital elements. Recital 10 names toys and baby monitoring systems as consumer products intended for vulnerable consumers, and holds that consumer products in this category should undergo a stricter conformity assessment procedure. What binds is Article 32(2): for class I, the internal control procedure remains available only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial are applied in full. Otherwise the route runs through EU type-examination followed by conformity to type, or through full quality assurance.

What this means in practice

For implementation work the question “do we sell to consumers?” is rarely decisive. The answer changes neither the Annex I requirements nor the documentation. It bears on three points: where the CE marking goes when the product is pure software, exposure to representative actions, and, for the Annex III categories, the route through conformity assessment.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.