Importer / distributor.
What this means for you
You have your own obligations (Articles 19–20): verify the manufacturer has carried out conformity assessment and CE marking, that documentation is available, report vulnerabilities to the manufacturer, and do not place a non-compliant product on the market. If you modify the product or sell it under your own brand, you become the manufacturer (Article 22).
Key facts
- The Cyber Resilience Act is Regulation (EU) 2024/2847; obligations phase in over time.
- From 11 September 2026: report actively exploited vulnerabilities and severe incidents (24 h / 72 h / 14 days) via ENISA's Single Reporting Platform.
- From 11 December 2027: no product with digital elements on the EU market without CE marking and the Annex I security requirements.
- Penalties up to €15 million or 2.5 % of worldwide annual turnover.
Source: EUR-Lex (Regulation (EU) 2024/2847); European Commission guidance of 27 July 2026.
Disclaimer
Informational tool based on Regulation (EU) 2024/2847 and the European Commission's guidance as of 27 July 2026. Not legal advice and not a conformity assessment; borderline cases (especially SaaS, open source and custom development) should be reviewed with a professional.