Importers and distributors

What should a CRA importer verify before supplying a product?

The importer needs a documented verification record for the product and manufacturer obligations that apply. Missing technical-documentation verification should remain visible as a gap.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

An EU importer prepares a batch of network equipment for supply. Product identity, marking and user information are present, but the team has not verified the manufacturer’s technical documentation. A complete packing list cannot resolve that separate verification step.

Facts that change the answer

  • Has the manufacturer’s conformity procedure been verified?
  • Is the required documentation, identification and user information present?
  • Is there reason to suspect non-conformity or significant cybersecurity risk?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Importer cannot confirm technical documentation

Hypothetical example 1

Assessment resultverification or record gap
Key facts in this example
The manufacturer drew up the required technical documentation
No
All recorded assumptions (17)
Product with digital elements
Hypothetical example product
Supply-chain role
importer
The manufacturer completed the applicable Article 32 conformity-assessment procedure
Yes
The manufacturer drew up the required technical documentation
No
The product bears the CE marking
Yes
The product is accompanied by the EU declaration of conformity or the required simplified declaration route
Yes
Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
Yes
Manufacturer identification and contact details are present as required
Yes
The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
Yes
The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
Yes
Importer identification and contact details
verified
Reason to believe the product or manufacturer processes are non-conforming
none identified
Reason to believe the product presents a significant cybersecurity risk
none identified
Market and corrective-action status
product made available after checks
Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
not required on recorded facts
The operator is aware of a vulnerability in the product
no
The manufacturer has ceased operations and cannot meet CRA obligations
no

Importer checks complete on the recorded facts

Hypothetical example 2

Assessment resultready to make available on recorded facts
Key facts in this example
The manufacturer drew up the required technical documentation
Yes
All recorded assumptions (17)
Product with digital elements
Hypothetical example product
Supply-chain role
importer
The manufacturer completed the applicable Article 32 conformity-assessment procedure
Yes
The manufacturer drew up the required technical documentation
Yes
The product bears the CE marking
Yes
The product is accompanied by the EU declaration of conformity or the required simplified declaration route
Yes
Annex II information and instructions are present in a language easily understood by users and the market-surveillance authority
Yes
Manufacturer identification and contact details are present as required
Yes
The product bears a type, batch, serial number or other element allowing its identification, or equivalent information accompanies it
Yes
The support-period end date, including at least month and year, is clearly and accessibly specified at purchase
Yes
Importer identification and contact details
verified
Reason to believe the product or manufacturer processes are non-conforming
none identified
Reason to believe the product presents a significant cybersecurity risk
none identified
Market and corrective-action status
product made available after checks
Required supply-chain and market-surveillance notifications for non-conformity or significant cybersecurity risk
not required on recorded facts
The operator is aware of a vulnerability in the product
no
The manufacturer has ceased operations and cannot meet CRA obligations
no

Evaluated on 2026-09-13 using EU Cyber Resilience Act importer and distributor readiness check, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Batch-specific verification checklist
  • Manufacturer documentation and conformity references
  • Contact details, support end date and escalation owner

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Resolve the missing verification before relying on a readiness result. Record suspected non-conformity and required market action explicitly.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations