The situation
A distributor receives a credible technical report about a product it supplies. The report is logged, but no one has confirmed that it reached the manufacturer. The distributor must preserve the communication and separately assess whether supply or corrective action needs to change.
Facts that change the answer
- Has the manufacturer been informed without undue delay?
- Is there reason to suspect non-conformity or significant cybersecurity risk?
- Which notifications and market actions follow from those facts?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Manufacturer handoff missing
Hypothetical example 1
Key facts in this example
- Reason to believe the product presents a significant cybersecurity risk
- none identified
- Market and corrective-action status
- product made available after checks
- The manufacturer was informed of the vulnerability without undue delay
- No
All recorded assumptions (16)
- Product with digital elements
- Hypothetical example product
- Supply-chain role
- distributor
- The product bears the CE marking
- Yes
- The product is accompanied by the EU declaration of conformity or the required simplified declaration route
- Yes
- Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
- Yes
- Manufacturer identification and contact details are present as required
- Yes
- The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
- Yes
- The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
- Yes
- Importer identification and contact details
- verified
- Reason to believe the product or manufacturer processes are non-conforming
- none identified
- Reason to believe the product presents a significant cybersecurity risk
- none identified
- Market and corrective-action status
- product made available after checks
- Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
- not required on recorded facts
- The operator is aware of a vulnerability in the product
- yes
- The manufacturer was informed of the vulnerability without undue delay
- No
- The manufacturer has ceased operations and cannot meet CRA obligations
- no
Significant cybersecurity risk identified
Hypothetical example 2
Do not place or make the product available until conformity is restored. Where significant cybersecurity risk is suspected, complete the required authority and supply-chain notifications.(CRA Articles 19(3)–(5) and 20(3)–(4))
Key facts in this example
- Reason to believe the product presents a significant cybersecurity risk
- significant risk suspected or identified
- Market and corrective-action status
- product not made available pending conformity
- The manufacturer was informed of the vulnerability without undue delay
- Yes
All recorded assumptions (16)
- Product with digital elements
- Hypothetical example product
- Supply-chain role
- distributor
- The product bears the CE marking
- Yes
- The product is accompanied by the EU declaration of conformity or the required simplified declaration route
- Yes
- Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
- Yes
- Manufacturer identification and contact details are present as required
- Yes
- The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
- Yes
- The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
- Yes
- Importer identification and contact details
- verified
- Reason to believe the product or manufacturer processes are non-conforming
- none identified
- Reason to believe the product presents a significant cybersecurity risk
- significant risk suspected or identified
- Market and corrective-action status
- product not made available pending conformity
- Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
- not required on recorded facts
- The operator is aware of a vulnerability in the product
- yes
- The manufacturer was informed of the vulnerability without undue delay
- Yes
- The manufacturer has ceased operations and cannot meet CRA obligations
- no
Evaluated on 2026-09-13 using EU Cyber Resilience Act importer and distributor readiness check, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Vulnerability report and receipt time
- Manufacturer notification and delivery evidence
- Risk assessment and any supply or corrective-action decision
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Assign the manufacturer handoff and document the risk decision. Escalation requirements should not be reduced to a support-ticket status.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 19 and 20; Articles 13, 30 and 32; Annex II
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.