Cyber Resilience Act decision examples
CRA importers and distributors
Check the product, its documentation and the escalation path before supply. Compare worked examples and the evidence behind each CRA assessment.
What must the supply-chain operator verify?
Open a situation to compare the relevant facts, worked results and evidence to retain.
What should a CRA importer verify before supplying a product?
The importer needs a documented verification record for the product and manufacturer obligations that apply. Missing technical-documentation verification should remain visible as a gap.
View facts and examplesWhat should a CRA distributor do after finding a vulnerability?
The record should distinguish informing the manufacturer from assessing any non-conformity or significant-risk response. Evidence of one action does not establish the other.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.