Cyber Resilience Act

Importer

Legal definition Art. 3(16) CRA

“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”
Regulation (EU) 2024/2847, Art. 3(16) CRA

The importer is the interface between third countries and the Union market. The definition requires two things: the importer is established in the Union, and it places on the market a product bearing the name or trademark of a supplier established outside the Union.

The second element is the real fork. It separates importer from manufacturer. The line runs not at development but at the label.

What to verify before placing on the market

Article 19 of the Cyber Resilience Act (CRA) requires importers to place only products on the market that meet the essential cybersecurity requirements in Annex I, Part I and whose manufacturer processes meet Part II. Before doing so they must ensure, among other things, that

This is a duty to verify, not to produce. The importer need assess nothing itself, but must be able to evidence that it looked.

Why the language requirement matters in practice

The language condition is routinely underestimated. English instructions are not automatically sufficient. What governs is what users in the Member State concerned easily understand. For consumer products in Germany that usually means German.

Because translations take time, this check belongs at the start of import planning rather than at the end.

When the importer becomes the manufacturer

Two routes lead out of the importer role: placing the product on the market under your own name or trademark, and making a Substantial modification to a product already placed on the market. Either makes you the manufacturer.

The first applies more often than expected, for instance when imported devices are rebranded. Doing so takes on full development responsibility for something you did not develop.

After placing on the market

The role does not end at import. Importers must state their contact details on the product, on its packaging or in an accompanying document, and must inform the manufacturer as soon as they become aware of a vulnerability in the product; the market surveillance authorities have to be informed as well where the product presents a significant cybersecurity risk. They are therefore a reporting path by which information from the market finds its way back to the manufacturer.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.