Cyber Resilience Act

Manufacturer

Legal definition Art. 3(13) CRA

“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”
Regulation (EU) 2024/2847, Art. 3(13) CRA

The Cyber Resilience Act (CRA) knows several economic operators, but the burden is distributed very unevenly. Practically everything sits with the manufacturer: the essential cybersecurity requirements, vulnerability handling across the entire support period, the technical documentation, conformity assessment and the reporting obligations.

That makes the question of who holds this role all the more important. The answer regularly differs from expectations.

You do not have to develop anything

The definition names two equivalent routes into the role: you develop or manufacture yourself, or you have something designed, developed or manufactured and market the result under your own name or trademark.

This captures the classic case of a bought-in product. Whoever sells an externally developed device or piece of software under their own logo is the manufacturer for the purposes of the regulation. The actual developer may never appear publicly at all, yet the obligations still rest with the party whose name is on the product.

Free of charge counts too

The definition covers marketing explicitly “whether for payment, monetisation or free of charge”. A price tag is not a precondition.

Free editions, trial versions and indirectly financed products are therefore covered. The regulation does, however, provide a distinctly lighter role for the open-source world: the open-source software steward is explicitly not a manufacturer, so non-commercial open-source development is not pulled into manufacturer obligations.

When distributors and importers become manufacturers

Article 21 covers a case that is frequently overlooked in practice. An importer or distributor is deemed a manufacturer, and subject to the obligations in Articles 13 and 14, where they

  • place a product on the market under their own name or trademark, or
  • make a substantial modification to a product already placed on the market.

Article 22 draws the same conclusion for everyone else: a person who is neither the manufacturer nor the importer nor the distributor, but substantially modifies a product and makes it available, is likewise deemed a manufacturer. The duties reach the part of the product affected by the modification, and the whole product where that modification affects the product’s cybersecurity as a whole.

In practice this means rebranding, white-label distribution and deep customer-specific adaptations shift responsibility. Anyone who thinks they are “just reselling” should check whether that still holds.

Several manufacturers along one supply chain

Because separately marketed components are themselves products with digital elements, a supply chain regularly contains several manufacturers side by side. The supplier of a module is the manufacturer of that module; the device maker is the manufacturer of the device the module sits in.

Obligations do not disappear upstream. The device manufacturer has to answer for the security of its product including the components built into it. That is the real reason Software Bill of Materials (SBOM) features so prominently in the CRA.

What this means organisationally

The manufacturer role cannot be contracted away. Agreements with suppliers govern the internal relationship; towards authorities and the market, the manufacturer remains responsible.

It therefore pays to settle three things early: which products you are the manufacturer of, who internally owns the obligations per product, and which suppliers have to deliver which information so that you can meet those obligations at all.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.