Under the Cyber Resilience Act (CRA), a distributor is not expected to repeat the manufacturer's conformity assessment, but it does have its own control duties before making a product with digital elements available on the EU market. Article 20 requires distributors to act with due care, verify specific product and economic-operator information, hold products when conformity is in doubt, and support corrective action and market surveillance after distribution.
For Austrian distributors, this is best treated as a controlled distribution gate rather than a one-time supplier questionnaire. The gate should show what was checked, which exact product or software state was covered, who made the decision, and how later vulnerability or non-conformity information reaches the responsible team.
The CRA's main obligations, including Article 20 distributor duties, apply from 11 December 2027. Manufacturer reporting obligations under Article 14 apply earlier, from 11 September 2026. Those reporting dates do not move the Article 20 application date forward, but distributors can use the remaining preparation period to establish their verification and escalation processes.
First confirm that the company is acting as a distributor
The CRA defines a distributor as a natural or legal person in the supply chain, other than the manufacturer or importer, who makes a product with digital elements available on the Union market without affecting its properties.
That definition matters because CRA duties depend on the economic operator's actual role. A reseller may be a distributor for one product flow and have a different role for another. Before designing the control, document:
- who manufactured the product;
- whether an EU importer is involved;
- which entity first placed the product on the Union market;
- which entity is now making it available further in the supply chain; and
- whether the distributor changes the product or places it on the market under its own name or trademark.
The last point can change the legal role. Under Article 21, an importer or distributor is considered a manufacturer where it places a product on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market.
Due care is the baseline distributor obligation
Article 20 requires distributors, when making a product with digital elements available on the market, to act with due care in relation to the CRA requirements.
The Regulation then turns that general duty into concrete checks. A practical distributor process should therefore avoid treating "due care" as an undefined policy statement. Convert it into a repeatable checklist linked to the exact product, model, release or software delivery being supplied.
A useful record can capture the product identifier, manufacturer and importer where applicable, evidence reviewed, review date, reviewer, exceptions found, escalation owner and final distribution decision.
Verify CE marking before making the product available
Before making a product available on the market, the distributor must verify that it bears the CE marking required by Article 30.
This should be a product-level check, not merely a supplier-level assumption. The evidence should identify which product, version or delivery was inspected and where the CE marking was found. For software where the CRA permits digital presentation of required information, teams should preserve enough context to demonstrate what was available to the user for the relevant release.
A CE mark is not a substitute for the distributor's other Article 20 checks. The distributor also has to verify that specified information required from the manufacturer and, where relevant, the importer is present.
Verify manufacturer information and user documentation
Article 20 requires the distributor to verify that the manufacturer has complied with several obligations referenced from Article 13. In operational terms, the distributor should check that the product can be identified and that the required manufacturer and user information accompanies it.
The check should cover the applicable manufacturer information, including:
- a type, batch, serial number or another element that enables product identification;
- the manufacturer's name, registered trade name or registered trademark;
- the manufacturer's postal address and digital contact details;
- the single point of contact through which users can communicate securely with the manufacturer, including for vulnerability information;
- the support-period information required by the CRA; and
- the information and instructions to the user required by Annex II.
The Austrian Federal Chancellery's CRA FAQ describes the distributor obligation similarly: distributors should verify CE marking and confirm that the manufacturer or importer has provided the necessary information, including contact details, the single point of contact, Annex II information, support-period information and the EU declaration of conformity.
For distribution operations, the practical objective is consistency. Product identification, declarations, instructions and contact information should refer to the same product state rather than being collected from unrelated supplier records.
Check importer information when an importer is involved
Where the supply chain includes an importer, Article 20 also requires the distributor to verify that the importer has complied with Article 19(4). That provision requires the importer to indicate its name, registered trade name or trademark, postal address, digital contact and, where applicable, website.
The information may be placed on the product or, where that is not possible, on packaging or accompanying documentation. A distributor should therefore include importer identification in its incoming or pre-distribution control where the product originates from outside the Union through an importer.
If the economic-operator information is missing or clearly inconsistent with the product being supplied, the distributor should not treat that as an administrative defect to be fixed after sale. It belongs in the conformity escalation process before further market availability.
Stop distribution when conformity is in doubt
If a distributor considers or has reason to believe that a product with digital elements or the processes put in place by the manufacturer do not comply with the essential cybersecurity requirements in Annex I, Article 20 requires the distributor not to make the product available until it has been brought into conformity.
This creates a real hold decision. Teams need to know who can place the hold, what product scope it covers, what evidence triggered it and what evidence is required before distribution can resume.
A practical hold record should answer:
- What observation or evidence created the conformity concern?
- Which product identifiers, batches, releases or software versions are affected?
- Has the manufacturer or importer been informed and what response was received?
- Who is authorised to release the hold?
- What evidence demonstrates that the issue has been corrected?
Do not overwrite the original concern when the issue is resolved. Retaining the initial evidence, decision and resolution creates a clearer audit trail if a market-surveillance authority later asks what the distributor knew and how it acted.
Significant cybersecurity risk requires immediate escalation
Article 20 distinguishes ordinary suspected non-conformity from a product presenting a significant cybersecurity risk. Where the distributor considers or has reason to believe that such a risk exists, it must inform the manufacturer or importer and the relevant market-surveillance authorities without undue delay.
The process therefore needs an escalation route that is usable before distribution and after products have already reached customers. It should identify the affected product scope, the nature of the risk, the evidence available at the time, the economic operators contacted and the authorities that must be informed for the relevant markets.
The distributor does not need to invent a parallel vulnerability-management system, but it does need a reliable way to move credible security information to the manufacturer or importer and to its own regulatory owner quickly enough to support the Article 20 duties.
Post-market duties continue after the product is distributed
Article 20 also covers products that a distributor has already made available on the market. If the distributor considers or has reason to believe that a product is not in conformity with the CRA, it must make sure that the corrective measures necessary to bring the product into conformity are taken, or that the product is withdrawn or recalled as appropriate.
This means the distribution process needs to preserve enough product and customer-channel traceability to act later. A useful operational record links:
- the affected product and release identifiers;
- the supplier or manufacturer communication;
- the non-conformity or vulnerability record;
- the decision on correction, withdrawal or recall;
- the markets or channels affected; and
- evidence that the chosen corrective action was carried out.
The distributor's obligation is not satisfied by forwarding an email and losing the connection to the affected product. Corrective action needs an owner and a traceable outcome.
Vulnerabilities must reach the manufacturer
Where a distributor becomes aware of a vulnerability in a product it has made available, Article 20 requires it to inform the manufacturer without undue delay. If a significant cybersecurity risk is involved, the market-surveillance authorities of the Member States in which the distributor made the product available must also be informed immediately, with details of the non-conformity and corrective measures taken.
This makes vulnerability intake relevant even for organizations that do not develop the product. Customer support, security contacts, reseller channels and internal incident processes should know where a product-security report goes and how to preserve the product identifiers and original evidence.
A distributor should also avoid silently merging separate reports. Multiple observations may concern different product versions, releases or configurations and can lead to different corrective actions.
Be ready for market-surveillance requests
Following a reasoned request from a market-surveillance authority, Article 20 requires distributors to provide the information and documentation necessary to demonstrate the conformity of the product and the processes put in place by the manufacturer. Distributors must also cooperate on action taken to eliminate cybersecurity risks posed by products they made available on the market.
The operational test is retrieval. A distributor should be able to identify the relevant product, economic operators, declaration and supporting information without reconstructing the supply-chain history from personal mailboxes.
This does not mean duplicating the manufacturer's entire technical documentation. It means maintaining a reliable path to the records the distributor is required to verify or provide and knowing who can obtain additional conformity information when an authority requests it.
Plan for manufacturer cessation
Article 20 also addresses the case where a distributor becomes aware that a manufacturer has ceased operations and, as a result, is unable to comply with the CRA obligations. The distributor must inform the relevant market-surveillance authorities and, by any means available and to the extent possible, users of the affected products.
Supplier-management and product-security processes should therefore have a route for credible cessation information. The response should identify which supported products are affected, where they were made available and which communication channels remain available.
Re-check the role before rebranding or substantially modifying a product
Article 21 prevents a distributor from relying on the distributor role after certain changes. A distributor becomes subject to manufacturer obligations when it places a product with digital elements on the market under its own name or trademark or carries out a substantial modification of a product already placed on the market.
Private-label arrangements, rebranding and technical modifications should therefore trigger a CRA role review before the product moves through the ordinary distributor gate. The result should be recorded because the applicable obligations can change materially.
Build one controlled distributor evidence trail
A distributor's Article 20 duties span pre-market checks, security escalation, corrective action and authority cooperation. Those activities are easier to defend when the evidence remains connected to the exact product and decision rather than being spread across supplier portals, tickets and email threads.
AA-sec is designed around traceability between requirements, security evidence, decisions and exact product or lifecycle context. For teams coordinating CRA distribution controls with product-security work, that model can help structure the evidence trail without replacing the distributor's own legal decisions, supplier relationships or market-surveillance responsibilities.
Key takeaway
Treat CRA distributor obligations as a repeatable control point in the product supply chain. Before making a product available, verify CE marking and the required manufacturer and importer information, and stop distribution when there is reason to doubt conformity.
After distribution, keep vulnerability and non-conformity information connected to the affected product, make corrective action traceable, cooperate with market-surveillance authorities, and reassess the company's legal role whenever branding or substantial modification could turn the distributor into the manufacturer.
Official sources
- Regulation (EU) 2024/2847 — Cyber Resilience Act — EUR-Lex
- Cyber Resilience Act — European Commission
- Fragen und Antworten zur Cyberresilienz-Verordnung — Austrian Federal Chancellery
