Result · G

Importer / distributor.

What this means for you

You have your own obligations (Articles 19–20): verify the manufacturer has carried out conformity assessment and CE marking, that documentation is available, report vulnerabilities to the manufacturer, and do not place a non-compliant product on the market. If you modify the product or sell it under your own brand, you become the manufacturer (Article 22).

Key facts

  • The Cyber Resilience Act is Regulation (EU) 2024/2847; obligations phase in over time.
  • From 11 September 2026: report actively exploited vulnerabilities and severe incidents (24 h / 72 h / 14 days) via ENISA's Single Reporting Platform.
  • From 11 December 2027: no product with digital elements on the EU market without CE marking and the Annex I security requirements.
  • Penalties up to €15 million or 2.5 % of worldwide annual turnover.

Source: EUR-Lex (Regulation (EU) 2024/2847); European Commission guidance of 27 July 2026.

Disclaimer

Informational tool based on Regulation (EU) 2024/2847 and the European Commission's guidance as of 27 July 2026. Not legal advice and not a conformity assessment; borderline cases (especially SaaS, open source and custom development) should be reviewed with a professional.