Cyber Resilience Act
Consumer
Legal definition Art. 3(18) CRA
“a natural person who acts for purposes which are outside that person’s trade, business, craft or profession”
A consumer under the Cyber Resilience Act (CRA) is a natural person acting for private purposes. Article 3(18) looks only at the purpose a person acts for, not at who that person is. Someone buying a connected camera for their own living room acts as a consumer. Someone buying the same camera for the company does not.
The term describes a role, not a permanent characteristic. The same person can be a procurement lead at work and a consumer at home.
The counterpart is the economic operator
Obligations under the CRA always fall on an Economic operator. Article 3(12) covers the manufacturer, the authorised representative, the importer, the distributor and any other person subject to obligations relating to the manufacture of products with digital elements or to making them available on the market.
On the consumer the CRA imposes nothing. Consumers appear only as the protected side, and even that at surprisingly few points.
Obligations do not hang on the consumer
The essential cybersecurity requirements in Annex I apply to every Product with digital elements placed on the market. Whether the buyer acts privately or professionally makes no difference. A purely industrial product must meet the same requirements as a household appliance.
Nor are the information duties cut to consumers. Annex II is headed Information and instructions to the user, and the CRA nowhere defines the user. That notion is wider than the consumer, since it covers anyone who operates the product, whatever the purpose. The same holds for the support period, which under Article 13(8) runs for at least five years unless the product is expected to be in use for a shorter time.
Where the term actually decides something
In the enacting terms the consumer surfaces at only a handful of places. Those few repay close reading.
- Article 30(1). For products in the form of software, the CE marking is affixed either to the EU declaration of conformity or on the website accompanying the software product. In the latter case, the relevant section of that website must be easily and directly accessible to consumers.
- Article 52(11). Market surveillance authorities have to tell consumers where to submit complaints about possible non-compliance, and how to reach the mechanisms for reporting vulnerabilities, incidents and cyber threats.
- Article 65. Infringements by economic operators that harm, or may harm, the collective interests of consumers fall under Directive (EU) 2020/1828 on representative actions. Article 67 inserts the CRA into Annex I to that Directive as point 69, and recital 124 gives 11 December 2027 as the starting date.
- Involvement. Consumer associations are among the stakeholders the Commission consults under Article 9(1). Under Article 52(12), market surveillance authorities have to facilitate, where relevant, cooperation with relevant stakeholders, including consumer organisations.
Consumer products in Annex III
One further effect is indirect and concerns product classification. Annex III lists several class I categories that in practice occur only in a private setting:
- smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- internet connected toys covered by Directive 2009/48/EC that have social interactive or location tracking features
- personal wearables with a health monitoring purpose to which Regulation (EU) 2017/745 or (EU) 2017/746 does not apply, or wearables intended for use by and for children
Classification follows the function, not the target group. In practice it still means that typical consumer products count as Important products with digital elements. Recital 10 names toys and baby monitoring systems as consumer products intended for vulnerable consumers, and holds that consumer products in this category should undergo a stricter conformity assessment procedure. What binds is Article 32(2): for class I, the internal control procedure remains available only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial are applied in full. Otherwise the route runs through EU type-examination followed by conformity to type, or through full quality assurance.
What this means in practice
For implementation work the question “do we sell to consumers?” is rarely decisive. The answer changes neither the Annex I requirements nor the documentation. It bears on three points: where the CE marking goes when the product is pure software, exposure to representative actions, and, for the Annex III categories, the route through conformity assessment.
Practical questions
-
The CRA does not answer that. Article 3(18) turns on the purpose a person acts for, but says nothing about how to decide mixed use. For your duties as a manufacturer the classification is almost always irrelevant, because the Regulation does not tie its requirements to the consumer. Where it does matter, such as access to the CE marking on a website, the safe route is to keep that section openly reachable without a login.
-
No. Annex II knows a single addressee, the user, and draws no line by prior knowledge. Article 13(18) does require the information to be clear, understandable, intelligible and legible, and to be in a language easily understood by users and market surveillance authorities. Where your product is used both at work and at home, the one version has to work for the less experienced group. A second, simplified version is allowed but not required.
-
The CRA itself gives individual consumers no cause of action. Article 65 instead makes Directive (EU) 2020/1828 on representative actions for the protection of the collective interests of consumers applicable to representative actions against infringements by economic operators that harm, or may harm, the collective interests of consumers. Liability for defective products is not governed by the CRA. Recital 31 points to Directive (EU) 2024/2853 as complementary: it imposes strict manufacturer liability, and a lack of security updates can amount to the lack of safety that triggers it. For consumers the route therefore runs through the representative action, not through a claim under the CRA itself.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.