Importers and distributors

What should a CRA distributor do after finding a vulnerability?

The record should distinguish informing the manufacturer from assessing any non-conformity or significant-risk response. Evidence of one action does not establish the other.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A distributor receives a credible technical report about a product it supplies. The report is logged, but no one has confirmed that it reached the manufacturer. The distributor must preserve the communication and separately assess whether supply or corrective action needs to change.

Facts that change the answer

  • Has the manufacturer been informed without undue delay?
  • Is there reason to suspect non-conformity or significant cybersecurity risk?
  • Which notifications and market actions follow from those facts?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Manufacturer handoff missing

Hypothetical example 1

Assessment resultverification or record gap
Key facts in this example
Reason to believe the product presents a significant cybersecurity risk
none identified
Market and corrective-action status
product made available after checks
The manufacturer was informed of the vulnerability without undue delay
No
All recorded assumptions (16)
Product with digital elements
Hypothetical example product
Supply-chain role
distributor
The product bears the CE marking
Yes
The product is accompanied by the EU declaration of conformity or the required simplified declaration route
Yes
Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
Yes
Manufacturer identification and contact details are present as required
Yes
The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
Yes
The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
Yes
Importer identification and contact details
verified
Reason to believe the product or manufacturer processes are non-conforming
none identified
Reason to believe the product presents a significant cybersecurity risk
none identified
Market and corrective-action status
product made available after checks
Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
not required on recorded facts
The operator is aware of a vulnerability in the product
yes
The manufacturer was informed of the vulnerability without undue delay
No
The manufacturer has ceased operations and cannot meet CRA obligations
no

Significant cybersecurity risk identified

Hypothetical example 2

Assessment resultstop market and escalate

Do not place or make the product available until conformity is restored. Where significant cybersecurity risk is suspected, complete the required authority and supply-chain notifications.(CRA Articles 19(3)–(5) and 20(3)–(4))

Key facts in this example
Reason to believe the product presents a significant cybersecurity risk
significant risk suspected or identified
Market and corrective-action status
product not made available pending conformity
The manufacturer was informed of the vulnerability without undue delay
Yes
All recorded assumptions (16)
Product with digital elements
Hypothetical example product
Supply-chain role
distributor
The product bears the CE marking
Yes
The product is accompanied by the EU declaration of conformity or the required simplified declaration route
Yes
Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
Yes
Manufacturer identification and contact details are present as required
Yes
The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
Yes
The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
Yes
Importer identification and contact details
verified
Reason to believe the product or manufacturer processes are non-conforming
none identified
Reason to believe the product presents a significant cybersecurity risk
significant risk suspected or identified
Market and corrective-action status
product not made available pending conformity
Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
not required on recorded facts
The operator is aware of a vulnerability in the product
yes
The manufacturer was informed of the vulnerability without undue delay
Yes
The manufacturer has ceased operations and cannot meet CRA obligations
no

Evaluated on 2026-09-13 using EU Cyber Resilience Act importer and distributor readiness check, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Vulnerability report and receipt time
  • Manufacturer notification and delivery evidence
  • Risk assessment and any supply or corrective-action decision

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Assign the manufacturer handoff and document the risk decision. Escalation requirements should not be reduced to a support-ticket status.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations