If you run a business selling products with digital functions and target the EU market, you have most likely heard of the term “CRA”. Many people have questions when they first encounter it: What exactly is this regulation? Does my product fall under its scope? Am I a manufacturer or an importer? Who is liable if something goes wrong? This article starts with the most basic judgment steps, sorting out liability boundaries, compliance requirements, and key points to avoid pitfalls step by step. Even if you have never been exposed to EU regulations before, you can quickly master the core judgment methods.
Quick Entry-Level Judgment: Is Your Product/Business Subject to the CRA
Let’s first explain the CRA in plain terms: its official name is the EU Cyber Resilience Act (Regulation (EU) 2024/2847), a mandatory regulation issued by the EU that governs the cybersecurity of all products with digital functions. Its core purpose is to ensure products have anti-hacking capabilities throughout the entire process from design, production to after-sales, so as to protect the privacy of EU users and market security. Its regulatory logic is also clear: liability applies throughout the entire lifecycle, and a contactable and liable entity must be identifiable in the EU market; it does not fail to apply just because you are an overseas enterprise. The core obligations of the CRA are implemented in phases, and the main applicable milestones have been specified, but some product classifications, implementation details, and enforcement standards of member states shall still be subject to official EU documents and subsequent implementation rules.
First, Understand the Product Scope: Almost All Products with Digital Functions Are Covered
The core criterion for judging whether a product is covered is whether the product has software, networking, data processing, or digital interface functions. Even if it is indirectly connected to the internet (for example, a smart door lock connects to a mobile phone via Bluetooth and then to home WiFi), it is still considered covered.
Common covered products include smart cameras, routers, home apps, industrial control equipment, and even open-source software and hardware sold for commercial purposes.
There are also clearly excluded basic scenarios, including purely offline products without digital functions (such as ordinary plastic water cups), purely manual services (such as purely offline consulting services), as well as exemption scenarios such as personal use, non-commercial open source, and unrenovated second-hand products. For specific judgment criteria, see the section “Situations Exempt from CRA Liability” at the end of the article.
Here is a special reminder for friends in special industries such as medical care, automobiles, and aviation: although there are already dedicated cybersecurity regulations in these fields, this does not mean automatic exemption from the CRA — only when the special regulations have fully covered the cybersecurity requirements of the corresponding products will the corresponding parts not be subject to the CRA. Requirements that are not covered still need to be complied with, so do not take it for granted.

Two Basic Terms You Must Understand (to Avoid Misjudgment)
Many people get more confused the more they read the regulations, precisely because they do not first understand two core definitions:
The first is products with digital elements (professional abbreviation: PDE), which are actually products that meet the above judgment criteria and are the regulatory objects of the CRA. You don’t need to memorize the abbreviation; just know that it refers to “products with digital functions”.
The second is placing on the market. Don’t think it is the moment when a consumer pays and places an order — it refers to the time point when a product is first made available (including sale, gift, lease, etc.) on the EU market for commercial purposes. Customs clearance, transportation, and temporary storage in overseas warehouses do not in themselves constitute placing on the market; the judgment must be combined with whether the product has entered the EU supply chain and is supplied to distributors or end users. For example, in the cross-border e-commerce scenario, if goods are only transported to an EU overseas warehouse for temporary storage and have not been listed for sale or shipped to buyers, it is usually not considered placing on the market until the first delivery to buyers or distributors within the EU.
10-Second Self-Check: 3 Questions to Judge Whether You Are Covered
You don’t need to flip through thick regulations; just ask yourself three questions:
First, is the product sold or supplied to the EU market for commercial purposes?
Second, is it a product with digital elements?
Third, is it not subject to exemption/exclusion scenarios such as personal use, non-commercial open source, unrenovated second-hand products, or full coverage by special regulations (for specific judgment, see the exemption section at the end of the article)?
If all three are true, then your business basically needs to comply with the CRA requirements.
Identity Determination: What Type of Liable Entity Are You Under the CRA
After confirming that your product is covered, the next step is to determine your identity — the liabilities of different identities vary vastly, so don’t mix them up and take on unnecessary risks.
Manufacturer: The Entity Whose Brand the Product Bears Bears Primary Liability
Many people think that “a manufacturer is just someone who runs a factory”, but that is not correct. The core criterion for determining a manufacturer under the CRA is “who puts the product on the market under its own name or trademark”: you are considered a manufacturer if you design and produce the product yourself, if you hire a foundry to manufacture but affix your own brand, or if you make substantial modifications to an existing product (such as changing core security functions, modifying software or hardware that affect cybersecurity risks) and then resell it.
Here is a very important reminder: even if you are an overseas manufacturer with headquarters and factories outside the EU, as long as you sell products to the EU, you must bear all core obligations of a manufacturer; it is not the case that you are beyond regulation just because you are overseas.
A common misconception to avoid: pure foundries (only responsible for production according to requirements, do not affix their own brand, do not participate in market placement decisions) are not considered manufacturers under the CRA and do not bear the primary liability of a manufacturer.
Importer: The First Gatekeeper of the EU Market
The criteria for determining an importer are also clear: an entity established within the EU that first places products produced in third countries (non-EU/EEA) on the EU market for commercial purposes. Don’t treat importers as “only responsible for customs clearance”; the CRA positions importers as “market access gatekeepers” who are responsible for verifying the compliance of products entering the EU.
An importer cannot be determined solely based on “being responsible for customs clearance” or “holding ownership of the goods”; the judgment must be combined with who arranges for the product to enter the EU supply chain in its own name and who bears the responsibility for the first market supply. Two common misconceptions must be noted: logistics, customs clearance, and warehousing service providers are not importers if they only provide services and do not participate in product market supply decisions; individuals bringing goods into the EU for personal use are also not importers and do not bear liability.
Two Other Types of Easily Confused Entities (Don’t Mix Up Liabilities)
In addition to manufacturers and importers, there are two roles that are often confused, which we will clarify in advance:
The first is the EU Authorized Representative (AR): this is a compliance contact within the EU that non-EU manufacturers must appoint when placing products on the EU market. The two parties must sign a written entrustment agreement. The authorized representative only bears procedural obligations within the scope of the entrustment (such as cooperating with regulators to retrieve documents and receiving regulatory notices), and does not replace the manufacturer in bearing primary compliance liability. Appointing an authorized representative is only to meet procedural requirements and cannot transfer the manufacturer’s primary liability.
The second is distributor: an entity that resells products after they have already been placed on the EU market is a distributor. Distributors do not bear the liability for first placing on the market, and their obligations are significantly lighter than those of importers. There are three core obligations: first, verify whether basic information such as the CE mark, the names and contact information of manufacturers and importers, and safety instructions are complete before supplying goods; second, do not impair the cybersecurity compliance of products during storage and transportation; third, immediately stop selling products when they are found to be non-compliant, and cooperate with recall, traceability, and regulatory investigations.
Quickly Determine Your Role
If you are afraid of mixing them up, just refer to the corresponding relationships below, though specific judgments still need to be combined with actual business details:
- Selling products to the EU under your own brand/trademark → usually a manufacturer
- Established in the EU, first introducing overseas products to the EU market for sale (without changing the brand or making substantial modifications) → usually an importer
- Only reselling products that have been legally placed on the EU market → usually a distributor
- Entrusted by an overseas manufacturer, only bearing procedural obligations such as compliance liaison and document custody within the EU → EU Authorized Representative

Full-Cycle Compliance Obligations of Manufacturers (Bearing Primary Liability from Design to After-Sales)
If you determine that you are a manufacturer, then you are the primary liable entity in the entire CRA compliance chain, with liabilities covering the full lifecycle of the product from design to after discontinuation of sales.
Pre-Market: Build Security into the Product, Cannot Make Up for It Afterwards
The core logic of the CRA is “security by design”, and pre-market preparation is the top priority.
First, conduct a full-lifecycle risk assessment: you must not only assess the risks of the product itself, but also cover the risks of third-party components, open-source software, and supporting cloud services you use (if they are an inseparable part of the product) — don’t try to use “the vulnerability is from a third-party component” as an excuse. As long as it is in your product, you are liable.
Second, meet basic security requirements: default security out of the factory (no weak passwords like admin/admin), minimum privilege (useless functions and ports are turned off by default), support for security updates, and a public vulnerability reporting channel. These four are the bottom line, and none can be missing.
Then comes conformity assessment: the CRA sets different conformity assessment paths based on product category and risk level. Ordinary products can usually go through internal control (self-declaration); important products, critical products, or products that do not fully apply harmonized standards may require the participation of a notified body. Specific judgments need to be made against regulatory requirements:
| Product Category | Risk Level | Optional Conformity Assessment Paths |
|---|---|---|
| General products | Low/medium risk | Internal control (self-declaration), provided that applicable harmonized standards or common specifications are met |
| Important products | Higher risk | Internal control plus third-party assessment, or type examination with the participation of a notified body (specifically subject to the requirements of the regulation’s annexes) |
| Critical products | High risk (e.g., critical connected products in fields such as energy and transportation) | Usually require stricter assessment procedures. Whether the participation of a Notified Body (NB, i.e., an EU-recognized third-party conformity assessment body) is mandatory shall be subject to the CRA annexes, implementing acts, and the applicability of harmonized standards |
The classification and assessment path of specific products shall be judged against the CRA annexes and subsequently issued implementation details. Some products may also adopt the internal control path if they meet harmonized standards.
Finally, compliance marking and user notification: you must sign the EU Declaration of Conformity (DoC for short, which can be understood as a compliance guarantee signed by the enterprise itself) and affix the CE mark to the product — note here that the CE mark is a mark by which the manufacturer declares that the product complies with applicable EU regulations. The specific assessment method may include internal control or participation of a notified body; it is not equivalent to pre-approval by a regulatory authority, nor does it mean that the product has passed all compliance verifications. The product must also be marked with an identification code and contact information; users must also be clearly informed of how to configure security functions, how to update, and how long security updates will be supported.
Post-Market: Continuously Ensure Product Security
Many manufacturers think they have no responsibility after the product is sold, but the CRA requires full-lifecycle security assurance, and post-market ongoing obligations are the part where pitfalls are most easily encountered.
First is the security update obligation: in principle, the security update support period should cover the reasonably expected service life of the product, usually at least 5 years (calculated from the date the product is first placed on the EU market); if the objectively expected service life of the product is shorter than 5 years or subsequent implementation rules have further refinements, it shall be judged based on the official text of the CRA, product category, and provable basis for expected lifespan. The reasonably expected service life shall be comprehensively judged in combination with factors such as product type, industry practice, general user expectations, and product usage scenarios. For example, if there is sufficient basis to determine that the expected service life of an industrial-grade router is 8 years, the support period shall not be shorter than 8 years. Security updates shall not be provided only to paying users; all legitimate users have the right to receive them.
Second is vulnerability and incident response: different requirements shall be matched according to incident types. For serious vulnerabilities that are actively exploited and major cybersecurity incidents, manufacturers must submit an early warning report within 24 hours, a follow-up report containing detailed analysis and disposal plans within 72 hours, and the final supplementary report shall be submitted at the milestone required by the regulation. These milestones only apply to serious incidents and high-risk vulnerabilities that are actively exploited. Ordinary vulnerabilities do not need to go through the emergency reporting process; they only need to be fixed in a timely manner and recorded, and if they affect user security, affected users shall be notified simultaneously. The actual reporting portal, receiving authority (usually the regulatory authority of the member state where the product is placed, or the early warning system of the EU Agency for Cybersecurity, ENISA) and final report format shall be subject to the ENISA platform, competent authorities of member states, and subsequent implementation rules.
If a problem occurs, you must carry out rectification, remove the product from the market, or recall it as appropriate, and simultaneously notify all downstream distributors; you must not conceal it.
Full Cycle: Document Retention and Regulatory Cooperation
All compliance work must leave evidence, that is, technical documentation. The documents must include product descriptions, risk assessment reports, proof of security measures, test reports, vulnerability handling strategies, and lists of third-party components and open-source software; none can be missing.
How long should these documents be kept? At least 10 years after the last batch of products is placed on the market, or at least 10 years after the end of the security support period, whichever is longer. And when EU regulators request them, they must be retrievable at any time.
If you are an overseas manufacturer, you must also appoint an EU Authorized Representative. Documents can be stored at the authorized representative’s office, but the primary liability still rests with the manufacturer.
Full-Cycle Compliance Obligations of Importers (EU Market Access Gatekeeping)
The core responsibility of importers is “gatekeeping”. They do not need to do design or updates like manufacturers, but they must not skip any required verification or cooperation.
Pre-Market: No Import Without Compliance Verification
The first hurdle for importers is pre-market verification; they cannot just let products pass because the supplier provides a CE mark.
The statutory core contents to be verified include:
- The manufacturer has compiled technical documentation and signed the EU Declaration of Conformity (DoC) as required;
- The product bears a CE mark that complies with specifications;
- The product is marked with the manufacturer’s name and contact information, as well as the information of the EU Authorized Representative (if any);
- The product is accompanied by necessary user information such as safety instructions and update support period;
- For products that require the participation of a notified body in conformity assessment, the manufacturer has obtained the corresponding valid certificate or report;
- The DoC, notified body certificate/report, and technical documentation summary must be consistent with the model, batch, hardware version, and firmware/software version of the actual product; you cannot only check the document header or general version certificate.
Importers must take reasonable verification measures according to the product’s risk level, and cannot pass the review solely based on the supplier’s oral guarantee or a few photos; if the manufacturer cannot be contacted or cannot provide compliance documents, the product shall not be placed on the EU market, otherwise you will be liable if something goes wrong.
There is another very easy pitfall to fall into: you must not make substantial modifications to the product without authorization — whether it is modifying software/hardware, firmware, security configurations, or changing the brand/trademark, as long as you make modifications, you may be determined to be a manufacturer and bear all manufacturer liabilities (for specific boundaries, see the later section on liability comparison). If you only repackage or relabel (without changing the product itself and security configurations), you must recheck whether the product’s compliance marks and documents are consistent, and must not impair the product’s security performance. You should also pay attention during transportation and storage; you must not damage the product’s security performance due to transportation or storage.
Finally, marking requirements: the importer’s name, registered trade name or trademark, address, and contact information must be marked on the product, packaging, accompanying documents, and online sales pages/product information for EU consumers; it is not allowed to only display overseas manufacturer information. Online scenarios must also meet the supporting requirements of relevant EU regulations such as online goods sales and market surveillance.
Post-Market: Problem Handling and Cooperation Obligations
After the product is sold, the importer cannot completely wash their hands of it.
If a product is found to have security problems or be non-compliant, first notify the manufacturer to jointly verify the situation; if it is confirmed that there is a serious security risk, or the manufacturer fails to take corrective measures in a timely manner, the importer must stop supplying the relevant products and report to the competent authority in accordance with the regulatory requirements of the member state.
When a manufacturer initiates a recall, the importer must cooperate with its implementation within the EU, and if necessary, may proactively contact EU users according to regulatory requirements — after all, the manufacturer is overseas and it is inconvenient to directly contact users, so the importer must bear the responsibility of domestic cooperation.
In addition, a process for receiving user security complaints must be established. Complaints received must be promptly transferred to the manufacturer for follow-up; you cannot pretend not to see them.
Full Cycle: Document Retention and Traceability
Importers do not need to write the full set of technical documentation themselves, but they must keep copies: copies of the DoC, all compliance documents, and purchase and sales records must all be retained.
The retention period is consistent with the requirements for manufacturers: at least 10 years after the last batch of relevant products is placed on the market, or 10 years after the end of the security support period, whichever is longer; if member states or product-specific rules require a longer period, those provisions shall apply.
More importantly, there must be traceability capability: upstream, the corresponding manufacturer and authorized representative can be identified; downstream, distributors or end customers can be traced. The model and software version of each batch must be clearly recorded — if a security problem really occurs, you must be able to quickly locate which goods are problematic and to whom they were sold.
Liability Comparison and Boundary Judgment
Many people tend to confuse the liabilities of different roles. We uniformly compare the scenario of “the same overseas product with digital elements, commercially sold to the EU”. Exemption scenarios such as personal use and non-commercial use (for specific judgment, see the exemption section at the end of the article) are not within the scope of this comparison.
Comparison of Core Liability Items
To help you quickly see the differences, we have organized them into a table:
| Liability Item | Manufacturer’s Liability | Importer’s Liability |
|---|---|---|
| Security design | Bears full responsibility, implements cybersecurity requirements from the design stage | Does not bear design responsibility, only verifies whether the manufacturer’s compliance documents meet statutory requirements |
| Conformity assessment | Leads the completion, selects applicable assessment procedures according to product category | Verifies the assessment results and completeness of documents, does not lead the assessment work |
| Security updates | Responsible for developing and pushing security updates, ensuring the support period meets requirements | Cooperates in notifying users, not responsible for the development and maintenance of updates |
| Recall implementation | Leads recall decisions, formulates rectification and recall plans | Cooperates with the manufacturer in implementation within the EU, and cooperates in contacting users as required by regulators when necessary |
| Document obligations | Drafts the full set of technical documentation, retains originals and makes them available for regulatory retrieval | Retains copies of compliance documents, verifies the completeness of documents |
| Violation liability | Bears primary compliance liability | Bears liability for its own violations of obligations such as verification, marking, and traceability; if it places products on the market knowing they are non-compliant, or makes substantial modifications, it may bear heavier liability or even be determined to be a manufacturer |
3 Situations Where Liability Determination May Change
Don’t think that identity determination is set in stone. The following three situations will directly change the division of liability:
First, an importer is determined to be a manufacturer: if an importer sells products under its own name or trademark, makes substantial modifications to the product (affecting cybersecurity risks), or claims to be the manufacturer of the product, it will be regarded as a manufacturer and bear full compliance liability. Many sellers of white-label products easily fall into this pit: taking white-label goods from factories and selling them under their own brand will directly trigger an identity upgrade, and they will no longer be importers.
Second, triggering heavier liability: if an importer places products on the market knowing they do not meet CRA requirements, or fails to verify whether the manufacturer has appointed a qualified EU Authorized Representative, it will bear administrative penalties for violating its own verification and access obligations. In serious cases, it may bear joint and several liability with the manufacturer.
Third, situations where the importer must bear liability independently: if an importer privately makes substantial modifications to the product leading to security problems, or cannot provide valid contact information of the manufacturer during a regulatory investigation, or cannot prove that it has fulfilled its verification obligations, it must bear corresponding liability for its illegal acts, and the regulatory authority may directly take punitive measures against the importer.
The specific division of liability shall be judged in combination with the facts of the violation, the degree of subjective fault, and the enforcement rules of the member state; not all situations will automatically transfer full liability.
Clarification of Common Liability Misconceptions
There are several misconceptions that almost everyone falls into, which we specifically bring up to clarify:
- Authorized Representative ≠ Importer: the former is only a procedural contact, while the latter bears verification obligations and access responsibility; they are completely different things.
- Distributor ≠ Importer: distributors do not bear the liability for first placing on the market, and have fewer obligations than importers, but they are not completely without liability.
- Contractual agreement ≠ Exemption from statutory obligations: don’t think that signing a contract with a supplier stating “all liability is borne by the supplier” means everything is fine — statutory obligations cannot be exempted by civil contracts. Regulators will first hold the corresponding liable entity accountable. After you pay compensation, you can seek recourse from the supplier according to the contract, but don’t try to shift the blame directly.
- Component compliance ≠ Whole product compliance: even if all the parts and modules you use are compliant, when assembled into a new product, the compliance of the whole product must be re-evaluated; you cannot use component compliance as a shield.
Liability Determination for Common Business Models
After explaining the rules, let’s apply them to common business scenarios to see how to make specific judgments.
Cross-Border E-Commerce Scenario
Friends who sell on Amazon or run independent stations ask this the most:
- Amazon FBA and overseas warehouse models: the importer identity can be quickly determined in four steps to avoid misjudgment:
① First exclude entities that only provide services: platform warehouses that only provide warehousing and distribution, customs clearance companies and tax agents that only act as agents for customs declaration, and those that do not participate in product market supply decisions are usually not importers;
② An importer cannot be directly determined solely based on customs clearance responsibility or ownership of goods; it must be judged in combination with the responsibility for market placement decisions;
③ The core is to see who is established within the EU, first supplies products to EU distributors or end users in its own name, and bears the responsibility for market placement. Such entities are usually determined to be importers;
④ If you are an overseas seller without an entity established in the EU, you must arrange for a qualified EU entity to bear importer liability, otherwise the product will have entry and sales compliance risks.
Overseas sellers themselves must also appoint an EU Authorized Representative as required and bear the corresponding primary obligations of a manufacturer. - Direct mail from overseas official websites: there must be an entity established within the EU to bear the responsibility for first placing on the market (i.e., the importer), otherwise the product cannot enter the country legally; products that only rely on overseas direct mail and have no liable entity within the EU will be intercepted by customs or market surveillance authorities.
- Platform self-operated products: products sold by the platform under its own brand are determined to be manufacturers or importers according to the own-brand rules, depending on whether the platform places the products in its own name.
OEM/White-Label Scenario
For those in the OEM or white-label business, the core judgment rules are consistent with the definition of manufacturer mentioned earlier, and the liable entity is determined based on brand ownership:
- OEM/ODM manufacturing: the brand owner is the manufacturer. Pure foundries that do not affix their own brand and do not participate in product design and placement decisions usually do not bear the primary liability of a manufacturer.
- White-label products affixed with the importer’s own brand: the importer will directly be upgraded to a manufacturer and bear full compliance liability.
Software/SaaS/Continuous Update Scenario
Friends who work in software or SaaS should also not think the CRA has nothing to do with them. First, it must be clarified that the CRA regulates “products with digital elements”. Pure online services and independent SaaS that are not attached to hardware products and do not fall into the category of “products placed on the market” usually do not directly apply to the CRA; specifically, they can be divided into four categories:
- Embedded software (software sold together with hardware products, such as firmware for smart cameras): part of the hardware product, regulated by the CRA together with the hardware, with the hardware manufacturer bearing liability.
- Independent software (such as separately sold computer software, mobile apps, placed on the market in the form of products): if they meet the definition of “products with digital elements” and are placed on the EU market for commercial purposes, they must comply with the CRA. The software developer is the manufacturer, and the entity that first places them on the EU market is the importer.
- Cloud services supporting hardware (such as cloud storage and remote control services for smart door locks): if they are an inseparable part of the product’s functions, they are included in the CRA compliance scope together with the hardware, and the hardware manufacturer bears liability.
- Pure SaaS/pure cloud services (such as online document tools, pure cloud enterprise services, not attached to specific hardware products): usually fall into the category of services, not “products” regulated by the CRA. Specific judgments need to be combined with the service form and subsequent EU implementation details.
Regarding version updates: not all new versions require re-conformity assessment. Only when a new version constitutes a significant modification (such as changing core cybersecurity functions, adding new networking or data processing functions, significantly changing the product’s risk level) is it necessary to re-evaluate compliance and update technical documentation and the declaration of conformity according to applicable assessment procedures. Small security patches and bug fixes usually do not require going through the full assessment process again, but must be recorded in the technical documentation.
Other Common Scenarios
- Integration/assembly within the EU: if you assemble multiple components into a new whole product for sale in the EU, then you are the manufacturer of the whole product. Compliance of individual components does not mean compliance of the whole product, which must be re-evaluated.
- Intra-group transactions: even transactions between parent companies and subsidiaries must be compliant as long as they are placed on the EU market for commercial purposes; there is no exemption just because they are in the same group.
Pitfall Avoidance Guide: Common Violations, Penalties, and Self-Checks
After talking about liability, let’s talk about what everyone is most concerned about: what pitfalls are most easily encountered? Are the penalties heavy? What to do if something goes wrong?
Most Common Violation Pitfalls
We have sorted out the most common mistakes by role, and you can check against them:
- Common pitfalls for manufacturers: default weak passwords out of the factory, stopping security updates immediately after product discontinuation (not meeting the statutory support period), technical documentation stored overseas that cannot be retrieved by EU regulators in a timely manner, mistakenly believing that appointing an authorized representative can transfer their own liability.
- Common pitfalls for importers: only looking at the CE mark without verifying the documents behind it, privately making substantial modifications to the product or changing the brand, not marking their own information on the product/packaging/online pages, not having a product traceability system so that the flow cannot be tracked.
- Common pitfalls for all: concealing and not reporting serious vulnerabilities when found, having misunderstandings about the compliance validity of the CE mark — if non-compliance is found in subsequent spot checks, penalties will still be imposed.
Actual Situation of Violation Penalties
Many people panic when they hear that the CRA has high fines, but actually there’s no need to scare yourself:
The administrative penalties stipulated in the CRA include warnings, fines, restriction or prohibition of placing on the market, ordering withdrawal or recall of products, suspension or prohibition of relevant business activities, etc. The specific penalty intensity is determined by each member state based on the circumstances of the violation, the degree of harm, the enterprise’s rectification situation, etc.
Regarding the upper limit of fines, under the CRA framework, serious violations can be fined up to 4% of global annual turnover or 20 million euros, whichever is higher. This is the maximum upper limit set by the regulation; different types of violations correspond to different fine tiers, and the specific penalty amount is implemented by member states based on the circumstances of the violation, degree of harm, rectification situation, etc. The final amount shall be subject to the official effective text of the EU and member state detailed rules.
If product safety problems cause damage to consumers or third parties, relevant parties may also claim damages based on the product liability laws, civil laws, etc. of the EU and member states. This does not fall into the category of administrative penalties directly stipulated by the CRA.
1-Minute Quick Self-Check List
You don’t need to flip through the entire article; just check the following core questions to know if you have major problems:
Manufacturer self-check:
- Have you conducted a complete full-lifecycle risk assessment?
- Do you have a clear security update plan that meets the minimum period requirement?
- Do the CE mark and DoC correspond to the specific product model and version?
- Has the non-EU entity appointed a compliant EU Authorized Representative?
Importer self-check:
- Have you verified the manufacturer’s full set of compliance documents, instead of just looking at the CE mark?
- Is your own name and contact information marked on the product, packaging, accompanying documents, and online sales pages?
- Have you established a handling process for security issues?
- Can you quickly trace the upstream source and downstream flow of the product?
5-Step Handling Method After Finding Problems
If you do find problems, don’t panic; just follow these five steps:
Step 1: First suspend the import or sale of relevant products to prevent the risk from continuing to expand.
Step 2: Classify by severity: whether it is missing documents, general non-compliance, or serious security risks — different levels have different handling priorities.
Step 3: Require the manufacturer to rectify within a time limit, and ask the other party to provide verifiable rectification evidence (such as updated technical documentation, test reports, patches, etc.), not just verbal promises.
Step 4: If it is a serious security risk, be sure to notify the competent authority in a timely manner in accordance with the regulatory requirements of the member state, and cooperate with the manufacturer to initiate a recall if necessary. Active rectification usually results in lighter treatment.
Step 5: Record the entire handling process and results, and keep them well, so that evidence can be produced when regulators inspect in the future.
Special Rules: Transition Period, Exemptions, and Relief for Micro and Small Enterprises
Finally, let’s talk about several special situations that people often ask about, which can save you a lot of trouble.
Phased Effective Dates
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) has officially entered into force, and core obligations apply in phases:
- Vulnerability and serious cybersecurity incident reporting obligation: applicable from September 11, 2026. Manufacturers bear the core reporting obligation for actively exploited vulnerabilities and serious cybersecurity incidents (i.e., the 24-hour early warning, 72-hour detailed report and other processes mentioned above); when importers find security risks or non-compliance, they shall notify the manufacturer, suspend supply, and cooperate or report as required by the competent authority of the member state.
- Products related to critical fields: some products in fields such as energy and transportation that are included in the CRA’s important/critical categories may be subject to earlier compliance requirements (for newly launched products from around the end of 2026), but not all critical industry products automatically apply the same date. Specifics shall be subject to the CRA annexes, subsequent EU implementing acts, and industry-specific rules.
- General compliance obligations (including security by design, conformity assessment, CE marking, security updates, etc.): applicable to all ordinary products with digital elements newly placed on the EU market from December 11, 2027.
Regarding retroactivity: the CRA generally does not apply retroactively, that is, products that have been legally placed on the EU market before December 11, 2027 usually do not need to complete full CRA compliance retroactively; but if the product undergoes significant modifications after that date, or the manufacturer continues to produce new batches and place them on the market, the newly modified products or new batches must meet CRA requirements. In addition, if the product is still in the support/maintenance period and triggers the already effective vulnerability and incident reporting obligations, it may still be required to perform corresponding reporting, disposal, or user notification obligations.

Situations Exempt from CRA Liability
The following situations are usually not subject to all or part of the CRA requirements, and specific judgments need to be combined with actual situations:
- Products brought into the EU for personal use: items used only for personal non-commercial purposes are not regulated by the CRA.
- Non-commercial open-source software and hardware: open-source projects that are completely free and not placed on the market for commercial purposes are usually not applicable; but if open-source software and hardware are sold commercially or integrated into commercial products, they still need to comply with the CRA.
- Second-hand products: if a product has been placed on the EU market before the CRA’s applicable date, and has not undergone significant modifications or been refurbished to the extent equivalent to a new product, it does not need to re-comply with CRA requirements when resold; but if a second-hand product is substantially modified or refurbished and then re-placed on the market, it must comply as a new product.
- Products already covered by special regulations: in fields such as medical devices, in vitro diagnostic medical devices, motor vehicles, and aerospace products, if the corresponding EU special regulations have fully covered the relevant cybersecurity requirements, the corresponding parts are not subject to the CRA; requirements that are not covered still need to be complied with, and there is no automatic full exemption.
Relief Policies for Micro and Small Enterprises
The CRA has certain supportive arrangements for micro-enterprises. The criteria for determining micro-enterprises are: fewer than 10 employees, and annual turnover or total balance sheet not exceeding 2 million euros in the previous fiscal year. Eligible micro-enterprises can enjoy simplified support in the conformity assessment process, some document requirements, and related administrative procedures, with specifics subject to the implementation details of the EU and member states.
But note: core security requirements cannot be exempted — bottom-line obligations such as banning weak passwords, providing security updates, establishing vulnerability response channels, and handling major risks must be complied with regardless of enterprise size. Relief only applies to procedural requirements, not to security standards themselves.
Final Summary
In summary, you can quickly judge whether a product is subject to the CRA through three questions, accurately determine whether you are a manufacturer, importer, authorized representative, or distributor based on your business model, and implement corresponding full-cycle compliance obligations. It should be noted that liability boundaries are not static: if an importer sells under its own brand or makes substantial modifications to the product, it will be upgraded to a manufacturer, and placing products on the market knowing they are non-compliant may trigger joint and several liability. You can regularly check for risks against the self-check list, handle problems by level according to the process, and reasonably plan the compliance pace in combination with the transition period, exemption rules, and support policies for micro and small enterprises. The core logic of the CRA is to promote enterprises to integrate cybersecurity into the entire product lifecycle. Clarifying your identity in advance and implementing corresponding obligations will allow you to cope smoothly.