Point of law
The Cyber Resilience Act
Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under its own name or trade mark, irrespective of payment. An importer or distributor is treated as a manufacturer under Art. 21 CRA as soon as it places a product on the market under its own name or makes a substantial modification. The reporting duty in Art. 14 CRA has applied since 11.09.2026 and therefore fifteen months before the remaining provisions.
Third party software under your own logo
A business buys in control software, puts its own logo on it and ships it with its machinery. A supplier developed it, the supplier maintains it, and the question about the Cyber Resilience Act has so far been addressed to that supplier.
A manufacturer is also anyone who merely lends the name
Who counts as a manufacturer is decided not by the development but by the marketing. Art. 3(13) CRA covers, alongside the developer, anyone who has products with digital elements developed and markets them under their own name or trade mark. The wording lists payment, monetisation and supply free of charge side by side, so the price is not a distinguishing feature.
Three routes into the manufacturer role
Your own logo on someone else’s software
Art. 3(13) CRA attaches to marketing under one’s own name or trade mark. Anyone having a product developed and shipping it under their own name is therefore a manufacturer, and the supplier is one alongside for its own product.
The distributor that becomes a manufacturer
Under Art. 3(17) CRA a distributor makes a product available without modifying its properties. Where it places the product on the market under its own name or modifies it substantially, Art. 21 CRA treats it as a manufacturer, subject to the duties in Art. 13 and 14 CRA.
A modification by a third party
Art. 22 CRA covers any other person who makes a substantial modification and makes the product available on the market. That reaches a systems integrator adapting a third party product for resale.
Two manufacturers therefore stand side by side, the supplier for its software and the business for the product under its own name. The duties in Art. 13 CRA can be backed by contract, but the addressee of the Regulation does not change with it.
A substantial modification is narrower than product maintenance
Whether a modification founds the manufacturer role turns on a definition narrower than the everyday understanding. Under Art. 3(30) CRA what matters is whether the modification affects conformity with the essential requirements or shifts the intended purpose for which the product was assessed.
Two modifications, two consequences
| Maintenance within the purpose | Merkmal | Substantial modification |
|---|---|---|
| Bug fix, security update, adaptation to an environment | What happens | New function, new interface, new purposeWhat governs under Art. 3(30) CRA is the effect on conformity or on the assessed purpose. |
| The existing one, unchanged | Who is the manufacturer | The modifier as wellUnder Art. 21 CRA the importer or distributor, under Art. 22 CRA any other person making the product available. |
| None added | Extent of the duties | The part affected or the wholeUnder Art. 22(2) CRA the whole product where the modification affects its cybersecurity as a whole. |
| The update within the existing process | What gets documented | Assessment, documentation, conformityArt. 13(12) CRA requires the technical documentation and the conformity assessment procedure before placing on the market. |
The third row is the expensive one. A modification affecting the cybersecurity of the product as a whole draws the duties onto the entire product and not only onto the part modified.
The reporting duty applies before everything else
What the preparation is directed at is usually the date of application in December 2027. For Art. 14 CRA, however, Art. 71(2) CRA names 11 September 2026, so the reporting duty runs fifteen months ahead of the product requirements. It also reaches a business that does not yet know of its manufacturer role.
What has to be reported under Art. 14(1) CRA is every actively exploited vulnerability, and Art. 3(42) CRA ties that concept to reliable evidence of actual exploitation. The early warning falls due within 24 hours, the report within 72 hours and the final report at the latest 14 days after a corrective or mitigating measure is available. The recipients are the CSIRT designated as coordinator and ENISA at the same time. Under subsection 8 the users have to be informed in addition.
How we support you with the Cyber Resilience Act
At the outset there is a list of the products that reach the market under the business’s own name, and for each the statement of who develops, who modifies and who places it on the market. It answers the question of role, shows for which products the reporting duty is running, and is the basis for the single point of contact under Art. 13(17) CRA.
Frequently asked questions
Does the Regulation cover internal software as well?
It attaches to placing on the market, which under Art. 3(21) CRA is the first making available on the Union market. Software used exclusively within the business is therefore unlikely to be covered. The line becomes difficult as soon as an application is made available to customers or to affiliated companies.
We hand software over free of charge. Are we outside?
Not for that reason. Art. 3(13) CRA covers marketing under one's own name expressly free of charge as well, and under Art. 3(22) CRA supply in the course of a commercial activity suffices. What matters is therefore the commercial context and not the price.
Which report goes to whom?
Under Art. 14(1) CRA simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. Where the same event concerns personal data, the report to the data protection authority under Art. 33 GDPR is added, and for an entity in scope of the BSIG the report under section 32 BSIG on top. Three chains with three recipients.
How long is the support period?
Under Art. 13(8) CRA at least five years, and shorter only where the product is expected to be in use for less. It is set by the expected use, and its end date has to be stated at the point of purchase with month and year under subsection 19. Security updates remain available for at least ten years under subsection 9.
What applies to open source components?
Anyone building them into a product of their own has to exercise due diligence under Art. 13(5) CRA so that they do not compromise the cybersecurity of the product. Where a vulnerability is identified in a component, it has to be reported under subsection 6 to the person or entity that manufactures or maintains that component. Responsibility for the result stays with the manufacturer.
More questions from this area
Checking whether NIS2 applies
Under section 33(1) BSIG it is the entity itself that establishes whether it is in scope, and the federal office registers of its own motion only where that duty is not met.
Supply chain security
Section 30(2) no. 4 BSIG covers the relationships with direct suppliers and service providers and reaches no further into the chain.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.