Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Who is covered by the EU Cyber Resilience Act?
Updated
The CRA (Regulation (EU) 2024/2847) names five economic-operator roles — manufacturer, authorised representative, importer, distributor, and open-source software steward — with different Chapter II duties. This page does not classify YOU. It is not legal advice and does not start a clock.
CRA who-is-covered guide, last verified 8 September 2026 against Regulation (EU) 2024/2847 Articles 3(12)–(17), 13, 14, 18–24 and 71, the European Commission's CRA pages (last updated 7 September 2026) and 27 July 2026 guidance (guidance, not the regulation), and ENISA product-security / Single Reporting Platform materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a determination of YOUR economic-operator role, and not a substitute for counsel.
This is roles, not YOUR role
Audience: a founder, legal owner, CTO, or compliance lead at an organisation that might make products with digital elements available on the Union market. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, authorised representative, importer, distributor, or open-source software steward, that a product with digital elements has been made available on the Union market, or that a filing is due.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. Chapter II (Articles 13 to 26) sets obligations of economic operators and provisions on open-source software. This page quotes those articles. It does not apply them to YOU. Last verified 8 September 2026. Not legal advice.
- Statute versus guidance: Articles 3(12)–(17), 13, 14, 18–24 and 71 are legal requirements only if they apply. Commission CRA pages and the 27 July 2026 Commission guidance are Commission materials — guidance, not the regulation. ENISA product-security and Single Reporting Platform materials are agency guidance, not the regulation. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The live Article 14 reporting guide on this site is the CRA Article 14 page under breach reporting.
- A dedicated products-in-scope, SaaS-scope, and penalties guide is not on this site yet. Naming them is not a link.
Article 3 role definitions — not YOUR class
Article 3(12) defines economic operator as the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation. The five named roles below are the ones this page compares. This page does not place YOU in any of them. Last verified 8 September 2026. Not legal advice.
| Role | What Article 3 says | Kind of text | Last verified |
|---|---|---|---|
| Manufacturer — Article 3(13) | A natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark. | Legal requirement — Article 3(13). This page does not find that YOU are a manufacturer. | 8 September 2026 |
| Open-source software steward — Article 3(14) | A legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as open-source software and intended for commercial activities, and that ensures the viability of those products. | Legal requirement — Article 3(14). Other than a manufacturer. This page does not classify YOU as a steward. | 8 September 2026 |
| Authorised representative — Article 3(15) | A natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks. | Legal requirement — Article 3(15). This page does not find that YOU hold that mandate. | 8 September 2026 |
| Importer — Article 3(16) | A natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union. | Legal requirement — Article 3(16). This page does not find that YOU are an importer. | 8 September 2026 |
| Distributor — Article 3(17) | A natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties. | Legal requirement — Article 3(17). This page does not find that YOU are a distributor. | 8 September 2026 |
| Placing on the market — Article 3(21) | The first making available of a product with digital elements on the Union market. | Legal requirement — Article 3(21). Used by the importer definition and by manufacturer placing-on-the-market duties. | 8 September 2026 |
| Making available on the market — Article 3(22) | The supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity. | Legal requirement — Article 3(22). This page does not find that YOUR supply is that activity. | 8 September 2026 |
Role-comparison table — not a determination
Obligations differ by role. Manufacturers carry essential cybersecurity requirements, vulnerability handling, Article 14 reporting, the EU declaration of conformity, and CE marking. Importers and distributors have placing and making-available duties. Authorised representatives perform mandated tasks. Open-source software stewards have a lighter, distinct set under Article 24. This table is an aid. It is not a determination that YOU hold any of these roles. Not legal advice.
| Role | Core Chapter II duties | Article 14 reporting | CE marking | Kind of text | Last verified |
|---|---|---|---|---|---|
| Manufacturer | Article 13(1): when placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I. Article 13 also covers cybersecurity risk assessment, due diligence on third-party components, vulnerability handling for the support period, technical documentation, conformity assessment, the EU declaration of conformity, and cooperation with market surveillance authorities. | Article 14 applies to manufacturers from 11 September 2026 (Article 71(2)). This page does not start that clock. | Article 13(12): where conformity has been demonstrated, manufacturers shall draw up the EU declaration of conformity in accordance with Article 28 and affix the CE marking in accordance with Article 30. | Legal requirement — Articles 13, 14, 28 and 30. Only if the role applies. | 8 September 2026 |
| Authorised representative | Article 18(1): a manufacturer may, by a written mandate, appoint an authorised representative. Article 18(2): the obligations laid down in Article 13(1) to (11), Article 13(12), first subparagraph, and Article 13(14) shall not form part of the authorised representative's mandate. Article 18(3) requires the mandate to allow at least keeping the EU declaration of conformity and technical documentation, providing information to a market surveillance authority, and cooperating on risk-elimination action. | Not the manufacturer's Article 14 duty. Article 14(7) uses the authorised representative in the CSIRT-cascade when there is no main establishment in the Union — a recipient rule, not a finding that YOU are that representative. | Not the manufacturer's CE-marking duty. Article 18(2) keeps Article 13(12), first subparagraph, out of the mandate. | Legal requirement — Article 18. Only if the mandate exists. | 8 September 2026 |
| Importer | Article 19(1): importers shall place on the market only products with digital elements that comply with the essential cybersecurity requirements set out in Part I of Annex I and where the processes put in place by the manufacturer comply with Part II of Annex I. Article 19(2): before placing, the importer shall ensure the manufacturer's conformity assessment, technical documentation, CE marking, EU declaration of conformity, and selected Article 13 identification and support-period markings. | Not the manufacturer's Article 14 duty, unless Article 21 treats the importer as a manufacturer. | The importer verifies that the product bears the CE marking (Article 19(2)(c)). The importer does not affix that marking as manufacturer unless Article 21 applies. | Legal requirement — Article 19. Only if the role applies. | 8 September 2026 |
| Distributor | Article 20(1): when making a product with digital elements available on the market, distributors shall act with due care in relation to the requirements set out in this Regulation. Article 20(2): before making available, the distributor shall verify CE marking and that the manufacturer and the importer have complied with the listed Article 13 and Article 19(4) obligations. | Not the manufacturer's Article 14 duty, unless Article 21 treats the distributor as a manufacturer. | The distributor verifies that the product bears the CE marking (Article 20(2)(a)). The distributor does not affix that marking as manufacturer unless Article 21 applies. | Legal requirement — Article 20. Only if the role applies. | 8 September 2026 |
| Open-source software steward | Article 24(1): open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product. Article 24(2): they shall cooperate with market surveillance authorities at their request. | Article 24(3) applies Article 14(1) to the extent the steward is involved in the development of the products, and Article 14(3) and (8) to the extent severe incidents affect network and information systems the steward provides. That is not the full manufacturer Article 14 ladder. | Article 24 does not impose the manufacturer's CE-marking duty. Recital 19 (a recital, not an operative article) states that those acting as open-source software stewards should not be permitted to affix the CE marking to the products whose development they support. | Legal requirement — Article 24. Recital 19 is a recital, not an operative article. Only if the role applies. | 8 September 2026 |
Open-source software stewards versus manufacturers
An open-source software steward is not a manufacturer. Article 3(14) says 'other than a manufacturer'. Article 24 is a distinct, lighter set of duties. It is not Article 13, not the EU declaration of conformity, and not CE marking. This comparison is not a finding that YOU are either. Last verified 8 September 2026. Not legal advice.
The 27 July 2026 Commission guidance discusses remote data processing solutions and open-source software. That document is Commission guidance, not the regulation. This page does not apply that guidance to YOU. A dedicated products-in-scope and SaaS-scope guide is not on this site yet. Naming them is not a link.
| Dimension | Manufacturer | Open-source software steward | Kind of text | Last verified |
|---|---|---|---|---|
| Who the person is | Article 3(13): develops or manufactures products with digital elements, or has them designed, developed or manufactured, and markets them under its name or trademark. | Article 3(14): a legal person, other than a manufacturer, that systematically provides support on a sustained basis for the development of specific products with digital elements qualifying as open-source software and intended for commercial activities, and that ensures the viability of those products. | Legal requirement — Article 3(13) and 3(14). | 8 September 2026 |
| Essential cybersecurity requirements (Annex I) | Article 13(1) and 13(8): design, development and production in accordance with Part I of Annex I; vulnerability handling in accordance with Part II of Annex I for the support period. | Article 24(1): a documented cybersecurity policy to foster secure development and effective vulnerability handling by the developers of that product, including documenting, addressing and remediating vulnerabilities and promoting sharing of information concerning discovered vulnerabilities within the open-source community. That is not Annex I conformity as manufacturer. | Legal requirement — Articles 13 and 24. | 8 September 2026 |
| CE marking and EU declaration of conformity | Article 13(12), Articles 28 and 30: draw up the EU declaration of conformity and affix the CE marking where conformity has been demonstrated. | Article 24 does not impose CE marking. Recital 19 (recital, not an operative article) states they should not be permitted to affix the CE marking to the products whose development they support. | Articles 13, 28 and 30 are legal requirements. Recital 19 is a recital. | 8 September 2026 |
| Article 14 reporting | Article 14 in full, from 11 September 2026 (Article 71(2)). The live Article 14 reporting guide on this site is the ladder. This page does not start that clock. | Article 24(3) applies selected Article 14 points to the extent that article states. Article 71(2) names Article 14 — not Article 24 — as the 11 September 2026 exception. ENISA's SRP FAQ (updated 7 September 2026) states that corresponding steward reporting under Article 24(3) applies from 11 December 2027. That FAQ is agency guidance, not the regulation. | Article 24(3) and Article 71(2) are legal requirements. The ENISA date reading is agency guidance. | 8 September 2026 |
| Market-surveillance cooperation | Article 13(22): provide information and documentation demonstrating conformity and cooperate on measures to eliminate cybersecurity risks. | Article 24(2): cooperate with market surveillance authorities at their request with a view to mitigating the cybersecurity risks posed by a product with digital elements qualifying as open-source software, and provide the Article 24(1) documentation on a reasoned request. | Legal requirement — Articles 13(22) and 24(2). | 8 September 2026 |
When an importer or distributor is treated as a manufacturer
Article 21: an importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.
Article 22(1): a natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of a product with digital elements and makes that product available on the market, shall be considered to be a manufacturer for the purposes of this Regulation. Article 22(2) limits those Articles 13 and 14 duties to the part affected by the substantial modification or, if the modification has an impact on the cybersecurity of the product as a whole, to the entire product.
Substantial modification is defined in Article 3(30). This page does not find that YOUR change is a substantial modification, and does not re-classify YOU as a manufacturer. A dedicated products-in-scope guide is not on this site yet. Naming it is not a link. Last verified 8 September 2026. Not legal advice.
When those role duties apply — Article 71, not YOUR dates
Last verified 8 September 2026 against Article 71 on EUR-Lex. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Role obligations that are not Article 14 — including Article 13 manufacturer essential-requirements duties, Article 18 authorised-representative duties, Article 19 importer duties, Article 20 distributor duties, and Article 24 steward duties — follow 11 December 2027 unless the article you quote says otherwise.
Article 71(2) names Article 14, not Article 24, as the 11 September 2026 exception. ENISA's SRP FAQ (updated 7 September 2026) states that corresponding steward reporting under Article 24(3) applies from 11 December 2027. That FAQ is agency guidance, not the regulation. This page does not start a clock.
| Date in the regulation | What applies to roles | Kind of text | Last verified |
|---|---|---|---|
| 11 September 2026 | Article 14 reporting obligations of manufacturers. This page does not start that clock. The live Article 14 reporting guide on this site is the ladder. | Article 71(2), second subparagraph. Legal requirement. | 8 September 2026 |
| 11 December 2027 | The rest of the Regulation, including Article 13 manufacturer essential-requirements and CE-marking duties, Articles 18–20 authorised-representative, importer and distributor duties, and Article 24 steward duties. | Article 71(2), first subparagraph. Legal requirement. | 8 September 2026 |
| Steward Article 24(3) reporting — date reading | Article 71(2) does not name Article 24 as an 11 September 2026 exception. ENISA's SRP FAQ treats corresponding steward reporting under Article 24(3) as applying from 11 December 2027. | Article 71(2) is the legal requirement. The ENISA date reading is agency guidance, not the regulation. | 8 September 2026 |
What to do now
As of last verification on 8 September 2026, Article 14 applies from 11 September 2026 — three days from that verification date. Full essential-requirements and other Chapter II role duties remain 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you hold any economic-operator role, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer, authorised representative, importer, distributor, or open-source software steward under Articles 3(13)–(17). This page does not run that test. Marking CRA in an obligation map is not that determination.
- Ask counsel whether Article 21 or Article 22 would treat YOU as a manufacturer. This page does not re-classify you.
- If counsel says Article 14 may apply to a manufacturer, open the live Article 14 reporting guide on this site for the 24-hour / 72-hour / 14-day ladder. This page does not start that clock.
- Do not treat an open-source software steward as a manufacturer. Do not treat Commission or ENISA guidance as the regulation. Do not treat this product's CRA control-set as a conformity-assessment file.
- A dedicated products-in-scope, SaaS-scope, penalties, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a filing, and not YOUR role determination. Walk it with counsel. The CRA overview on this site is the pillar page. The live Article 14 reporting guide on this site is the ladder.
- Which Article 3 role, if any — manufacturer, authorised representative, importer, distributor, or open-source software steward? This page does not run that test.
- Would Article 21 or Article 22 treat an importer, distributor, or other person as a manufacturer? This page does not re-classify YOU.
- Manufacturer Article 14 from 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track. This page does not start that clock.
- Other Chapter II role duties from 11 December 2027, unless the article you quote says otherwise. Readiness in this product is not CE marking.
- Is an open-source software steward the same as a manufacturer? No — Article 3(14) is other than a manufacturer; Article 24 is not Article 13.
- Document the assessment, including a not-this-role decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative readiness mapping, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not compliance, not CE marking, and not a market-surveillance determination. The product does not classify you as manufacturer, authorised representative, importer, distributor, or open-source software steward.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that the CRA applies, does not decide that you are a manufacturer, and does not file with a CSIRT or ENISA. A named human still files.
The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. An in-scope mark on the obligation map is not a determination of economic-operator role and is not a finding that you are a manufacturer. The cyber risk register lives under Security. It is not an Article 14 file.
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 8 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 3(12)–(17), 13, 14, 18–24 and 71, is a legal requirement only if it applies. Article 14 applies from 11 September 2026; the rest of those Chapter II role duties from 11 December 2027 (Article 71(2)). The European Commission's CRA policy page (updated 7 September 2026), CRA implementation FAQs, and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. ENISA's product-security pages and Single Reporting Platform materials, including the SRP FAQ updated 7 September 2026, are agency guidance, not the regulation. Directive (EU) 2022/2555 is a different instrument; the NIS2 incident-reporting guide is on this site. A NIS2 entity class does not assign a CRA economic-operator role. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The CRA Article 14 reporting guide on this site is the live ladder. The reporting-deadlines page on this site is the statute table of clocks. The NIS2 incident-reporting guide on this site is Article 23. The DORA incident-reporting guide on this site is Articles 18–19. A dedicated products-in-scope, SaaS-scope, penalties, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a role-comparison page distilled from Regulation (EU) 2024/2847 Articles 3 and 13–24, with Commission and ENISA materials labelled as guidance, not the regulation. Whether YOU are a manufacturer, authorised representative, importer, distributor, or open-source software steward is a legal question for counsel on your facts. This page does not start a clock.
Does ShipReady decide we are a manufacturer?
No. The product does not classify you as a manufacturer, authorised representative, importer, distributor, or open-source software steward. Signed-in CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a manufacturer-status determination, does not file, and does not start a clock. A named human still files.
Does an in-scope mark on the obligation map mean we are a manufacturer?
No. Marking the bundled framework key cra in-scope on the obligation map is not a determination of economic-operator role and is not a finding that you are a manufacturer. Counsel applies Article 3 to YOUR facts. This page does not run that test.
Is an open-source steward the same as a manufacturer?
No. Article 3(14) defines an open-source software steward as a legal person other than a manufacturer. Article 24 is a distinct, lighter set of duties; it is not Article 13, not CE marking, and not the full manufacturer Article 14 ladder.
Does NIS2 manufacturer status (if any) discharge CRA roles?
No. NIS2 (Directive (EU) 2022/2555) classifies essential and important entities. It does not assign CRA economic-operator roles. A NIS2 entity class, or the absence of one, does not discharge Articles 13–24 of Regulation (EU) 2024/2847.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.