Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Point of law

The Cyber Resilience Act

Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under its own name or trade mark, irrespective of payment. An importer or distributor is treated as a manufacturer under Art. 21 CRA as soon as it places a product on the market under its own name or makes a substantial modification. The reporting duty in Art. 14 CRA has applied since 11.09.2026 and therefore fifteen months before the remaining provisions.

A business buys in control software, puts its own logo on it and ships it with its machinery. A supplier developed it, the supplier maintains it, and the question about the Cyber Resilience Act has so far been addressed to that supplier.

A manufacturer is also anyone who merely lends the name

Who counts as a manufacturer is decided not by the development but by the marketing. Art. 3(13) CRA covers, alongside the developer, anyone who has products with digital elements developed and markets them under their own name or trade mark. The wording lists payment, monetisation and supply free of charge side by side, so the price is not a distinguishing feature.

Three routes into the manufacturer role

Your own logo on someone else’s software

Art. 3(13) CRA attaches to marketing under one’s own name or trade mark. Anyone having a product developed and shipping it under their own name is therefore a manufacturer, and the supplier is one alongside for its own product.

The distributor that becomes a manufacturer

Under Art. 3(17) CRA a distributor makes a product available without modifying its properties. Where it places the product on the market under its own name or modifies it substantially, Art. 21 CRA treats it as a manufacturer, subject to the duties in Art. 13 and 14 CRA.

A modification by a third party

Art. 22 CRA covers any other person who makes a substantial modification and makes the product available on the market. That reaches a systems integrator adapting a third party product for resale.

Two manufacturers therefore stand side by side, the supplier for its software and the business for the product under its own name. The duties in Art. 13 CRA can be backed by contract, but the addressee of the Regulation does not change with it.

A substantial modification is narrower than product maintenance

Whether a modification founds the manufacturer role turns on a definition narrower than the everyday understanding. Under Art. 3(30) CRA what matters is whether the modification affects conformity with the essential requirements or shifts the intended purpose for which the product was assessed.

Two modifications, two consequences

Maintenance within the purposeMerkmalSubstantial modification
Bug fix, security update, adaptation to an environmentWhat happensNew function, new interface, new purposeWhat governs under Art. 3(30) CRA is the effect on conformity or on the assessed purpose.
The existing one, unchangedWho is the manufacturerThe modifier as wellUnder Art. 21 CRA the importer or distributor, under Art. 22 CRA any other person making the product available.
None addedExtent of the dutiesThe part affected or the wholeUnder Art. 22(2) CRA the whole product where the modification affects its cybersecurity as a whole.
The update within the existing processWhat gets documentedAssessment, documentation, conformityArt. 13(12) CRA requires the technical documentation and the conformity assessment procedure before placing on the market.

The third row is the expensive one. A modification affecting the cybersecurity of the product as a whole draws the duties onto the entire product and not only onto the part modified.

The reporting duty applies before everything else

What the preparation is directed at is usually the date of application in December 2027. For Art. 14 CRA, however, Art. 71(2) CRA names 11 September 2026, so the reporting duty runs fifteen months ahead of the product requirements. It also reaches a business that does not yet know of its manufacturer role.

11.09.2026the reporting duty in Art. 14 CRA has applied since this day

What has to be reported under Art. 14(1) CRA is every actively exploited vulnerability, and Art. 3(42) CRA ties that concept to reliable evidence of actual exploitation. The early warning falls due within 24 hours, the report within 72 hours and the final report at the latest 14 days after a corrective or mitigating measure is available. The recipients are the CSIRT designated as coordinator and ENISA at the same time. Under subsection 8 the users have to be informed in addition.

How we support you with the Cyber Resilience Act

At the outset there is a list of the products that reach the market under the business’s own name, and for each the statement of who develops, who modifies and who places it on the market. It answers the question of role, shows for which products the reporting duty is running, and is the basis for the single point of contact under Art. 13(17) CRA.

Frequently asked questions

Does the Regulation cover internal software as well?

It attaches to placing on the market, which under Art. 3(21) CRA is the first making available on the Union market. Software used exclusively within the business is therefore unlikely to be covered. The line becomes difficult as soon as an application is made available to customers or to affiliated companies.

We hand software over free of charge. Are we outside?

Not for that reason. Art. 3(13) CRA covers marketing under one's own name expressly free of charge as well, and under Art. 3(22) CRA supply in the course of a commercial activity suffices. What matters is therefore the commercial context and not the price.

Which report goes to whom?

Under Art. 14(1) CRA simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. Where the same event concerns personal data, the report to the data protection authority under Art. 33 GDPR is added, and for an entity in scope of the BSIG the report under section 32 BSIG on top. Three chains with three recipients.

How long is the support period?

Under Art. 13(8) CRA at least five years, and shorter only where the product is expected to be in use for less. It is set by the expected use, and its end date has to be stated at the point of purchase with month and year under subsection 19. Security updates remain available for at least ten years under subsection 9.

What applies to open source components?

Anyone building them into a product of their own has to exercise due diligence under Art. 13(5) CRA so that they do not compromise the cybersecurity of the product. Where a vulnerability is identified in a component, it has to be reported under subsection 6 to the person or entity that manufactures or maintains that component. Responsibility for the result stays with the manufacturer.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.