Cyber Resilience Act
Distributor
Legal definition Art. 3(17) CRA
“a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties”
The distributor carries the lightest set of obligations, and the definition explains why: it makes the product available without affecting its properties. Change nothing and you answer for nothing about its condition.
The definition expressly excludes manufacturers and importers. A distributor is therefore whoever neither created the product nor first brought it onto the Union market, but passes it along the chain.
The verification duties
Article 20 of the Cyber Resilience Act (CRA) first requires compliance to be pursued with due care. Specifically, before making a product available, distributors verify whether
- the product bears the CE marking,
- the manufacturer and importer met their marking and information duties and provided the distributor with the required documents.
That is a visual and documentary check, not a technical assessment. The distributor need not judge whether the product is secure; it must establish whether the formal preconditions are in place.
The duty to act
Doubt ends passivity. Where a distributor has reason to believe, on the basis of information in its possession, that a product or the processes put in place by the manufacturer fail the essential cybersecurity requirements in Annex I, it must not make the product available until conformity has been restored. Where the product poses a significant cybersecurity risk, it must also inform the manufacturer and the market surveillance authorities without undue delay. Where the doubts arise only after the product was made available, Article 20(4) requires the distributor to make sure the necessary corrective measures are taken to bring it into conformity or, if appropriate, to withdraw or recall it.
In practice this means a distributor needs a route by which signals from the market reach, internally, whoever decides on continued availability.
Where the role ends
Two acts move a distributor into the manufacturer role:
- Placing on the market under your own name or trademark, even where nothing about the product itself changes.
- Substantial modification of a product already placed on the market.
The second is particularly close to hand in software distribution. Anyone deeply adapting configurations, adding modules or reworking products for individual customers should check whether that still happens “without affecting its properties”. The answer decides the entire set of obligations.
Practical questions
-
Two things: whether the product bears the CE marking, and whether the manufacturer and importer met their information duties and supplied you with the required documents. Beyond that, the general duty to act with due care applies. A distributor owes no technical assessment of its own.
-
Two acts: placing the product on the market under your own name or trademark, and any substantial modification to a product already placed on the market. The definition itself draws the line, because it presupposes that the product’s properties are not affected. Touch them and you leave the distributor role.
-
The product must then not be made available. Where a distributor has reason to believe, on the basis of information in its possession, that a product or the processes put in place by the manufacturer fail the essential cybersecurity requirements in Annex I, it must refrain from making it available until conformity has been restored. Where the product also poses a significant cybersecurity risk, it must inform the manufacturer and the market surveillance authorities without undue delay.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.