Cyber Resilience Act
Importer
Legal definition Art. 3(16) CRA
“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”
The importer is the interface between third countries and the Union market. The definition requires two things: the importer is established in the Union, and it places on the market a product bearing the name or trademark of a supplier established outside the Union.
The second element is the real fork. It separates importer from manufacturer. The line runs not at development but at the label.
What to verify before placing on the market
Article 19 of the Cyber Resilience Act (CRA) requires importers to place only products on the market that meet the essential cybersecurity requirements in Annex I, Part I and whose manufacturer processes meet Part II. Before doing so they must ensure, among other things, that
- the manufacturer carried out the appropriate Conformity assessment procedure,
- the Technical documentation has been drawn up,
- the product bears the CE marking,
- the EU declaration of conformity and the information and instructions to the user are supplied with it, in a language easily understood by users and market surveillance authorities.
This is a duty to verify, not to produce. The importer need assess nothing itself, but must be able to evidence that it looked.
Why the language requirement matters in practice
The language condition is routinely underestimated. English instructions are not automatically sufficient. What governs is what users in the Member State concerned easily understand. For consumer products in Germany that usually means German.
Because translations take time, this check belongs at the start of import planning rather than at the end.
When the importer becomes the manufacturer
Two routes lead out of the importer role: placing the product on the market under your own name or trademark, and making a Substantial modification to a product already placed on the market. Either makes you the manufacturer.
The first applies more often than expected, for instance when imported devices are rebranded. Doing so takes on full development responsibility for something you did not develop.
After placing on the market
The role does not end at import. Importers must state their contact details on the product, on its packaging or in an accompanying document, and must inform the manufacturer as soon as they become aware of a vulnerability in the product; the market surveillance authorities have to be informed as well where the product presents a significant cybersecurity risk. They are therefore a reporting path by which information from the market finds its way back to the manufacturer.
Practical questions
-
It turns on whose name is on the product. Placing a product on the market under the brand of a third-country supplier makes you the importer. Selling the same product under your own brand makes you the Manufacturer, with the full set of obligations. The difference lies purely in the labelling, not in the supply chain.
-
No, but you must satisfy yourself that the manufacturer produced it. The CRA does not require importers to assess, it requires them to verify that the preconditions exist. In practice that means you need access to the documents and a contractual basis for it, otherwise you cannot meet your own duty.
-
Then you must not place the product on the market. The CRA allows importers to place only conformant products. Where doubts arise later, corrective measures have to be taken without delay, and the market surveillance authorities have to be informed where the product presents a significant cybersecurity risk. Looking away is expressly not an option.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.