You Put Your Name on It. The CRA Makes You the Manufacturer.

If you sell a connected product under your own name or trademark in the EU, the Cyber Resilience Act (Regulation (EU) 2024/2847) makes you the manufacturer. Not a reseller. Not a distributor. The manufacturer - with the full weight of manufacturer obligations attached.
This is not a penalty for modifying anything. It flows directly from the CRA's definition of "manufacturer" and applies from the moment you brand the product as yours.
Key points
- The CRA's definition of "manufacturer" explicitly includes any person who has a product designed, developed, or manufactured by someone else and then markets it under their own name or trademark.
- Own-branding is not a "substantial modification" trigger - it is the manufacturer definition itself.
- As the deemed manufacturer, you cannot rely on the original maker's CE marking or Declaration of Conformity. You must be able to produce your own.
- Reporting obligations (24h early warning, 72h notification, 14-day final report) apply from 11 September 2026. Full application of essential requirements, CE marking, and technical documentation follows on 11 December 2027.
- Penalties for breaching essential requirements reach up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
- The practical fix starts in the contract negotiation, before you sign the supply deal.
What the law actually says
The CRA defines a manufacturer as a natural or legal person who develops or manufactures products with digital elements - or who has them designed, developed, or manufactured - and markets them under their own name or trademark (Article 3(13), Regulation (EU) 2024/2847).
That second limb is the one that catches private-label and white-label buyers. You do not need to have written a line of code or assembled a single unit. If your name or trademark is on the product when it reaches the EU market, you are the manufacturer.
Article 21 reinforces this for importers and distributors specifically: an importer or distributor that places a product with digital elements on the market under its own name or trademark is considered to be a manufacturer and is subject to Articles 13 and 14 - the core manufacturer obligations. The same article also covers substantial modification as a separate trigger, but own-branding does not depend on that route at all.
Own-branding is not a modification trigger — it is the definition. You do not need to change the product to become the manufacturer. Putting your name on it is enough. This catches a wide range of arrangements: private-label hardware, white-label IoT devices, OEM products marketed under a corporate group's brand, and software platforms repackaged by a reseller.
Who this catches in practice
The arrangements most likely to create an unrecognised manufacturer role are:
Private-label and white-label purchases. You buy a finished product, apply your brand, and sell it. The original maker's CE marking and Declaration of Conformity cover their product - not yours. The moment you put your name on it, you need your own.
OEM arrangements. A manufacturer builds to your specification and you market the result. You are the manufacturer under the CRA regardless of how much engineering you contributed.
Corporate groups where one entity builds and another markets. The entity whose name appears on the product is the manufacturer. If that is a sales subsidiary with no engineering capability, it still carries the full obligation set - and needs access to the technical file held by the group entity that actually built the product.
Integrators who bundle and rebrand. If you take a third-party connected component, integrate it into a product, and sell the result under your brand, you are the manufacturer of that product. You are also responsible for the security of the components you chose to include.
Check every product line, not just new launches. As Hogan Lovells noted in June 2026, the manufacturer role should be determined for each in-scope product — and this is particularly relevant for corporate groups, white-label products, OEM arrangements, and products developed by one entity but marketed by another. Legacy products already on the EU market are also subject to the reporting obligations from 11 September 2026.
Use this tool to check your role
The widget below walks through the key questions. Answer them for each product line - the result tells you whether you are likely to be the manufacturer, an importer, a distributor, or whether you need to look more carefully at a specific arrangement.
What manufacturer obligations actually mean for you
If you are the manufacturer - whether because you built the product or because you put your name on it - the obligations are the same. Here is what you are taking on:
Security by design and secure by default. The product must be designed with cybersecurity built in from the start: minimal attack surface, no weak default passwords, a reset-to-secure-state capability.
Cybersecurity risk assessment (Article 13). You must carry out and document a risk assessment covering the product's cybersecurity properties across its lifecycle.
Software Bill of Materials (SBOM). The CRA requires manufacturers to draw up a machine-readable SBOM - in CycloneDX or SPDX format - covering at least the top-level dependencies, kept in the technical documentation. It does not have to be public, but authorities can request it.
Vulnerability handling and coordinated disclosure. You must have a process for identifying, documenting, and remediating vulnerabilities, and a published coordinated vulnerability disclosure (CVD) policy with a contact point.
Free security updates across the support period. The CRA presumes a support period of at least five years unless the product's expected use is shorter. Security updates must be free to the user throughout that period.
CE marking and EU Declaration of Conformity (Annex V). You must draw up your own DoC. The original maker's DoC does not cover you.
Technical documentation (Annex VII). Technical documentation must be kept for 10 years. It must be available to market surveillance authorities on request.
Reporting via the ENISA Single Reporting Platform. From 11 September 2026, you must report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification with corrective measures, and a 14-day final report.
You cannot inherit the original maker's CE marking. When you own-brand a product, the original manufacturer's CE marking and Declaration of Conformity cover their product — not yours. You must be able to draw up your own Declaration of Conformity and produce the Annex VII technical file if a market surveillance authority asks for it. If you cannot, you are non-compliant from the moment you place the product on the market.
The penalties if you get this wrong
The CRA's penalty structure (Article 64) is tiered, and the top tier applies directly to manufacturers:
| Tier | What triggers it | Maximum fine |
|---|---|---|
| Tier 1 (highest) | Breaching essential requirements (Annex I) or manufacturer obligations (Arts. 13–14) | €15M or 2.5% of worldwide annual turnover, whichever is higher |
| Tier 2 | Other CRA obligations — importer/distributor duties, conformity assessment, DoC | €10M or 2% of worldwide annual turnover, whichever is higher |
| Tier 3 | Supplying incorrect, incomplete, or misleading information to authorities | €5M or 1% of worldwide annual turnover, whichever is higher |
Fines are not the only tool. Market surveillance authorities can also order product withdrawal, recall, or a ban on making the product available - which for many businesses is a more immediate threat than the financial penalty itself.
What to do before you sign the supply deal
The most effective point to manage this risk is before you commit to own-branding a product. Once you have placed it on the market under your name, the obligations are already running.
Go through every product you sell or plan to sell in the EU. Flag the risk cases: private-label purchases, white-label arrangements, OEM deals, and any product where your brand appears but another company built it. Do this per product, not per category.
If you will be the manufacturer, you need the Annex VII technical file — or a contractual right to access it and produce your own. Agree this before you sign. A supplier who will not give you access to the documentation is a supplier who is leaving you exposed.
Ask for the machine-readable SBOM (CycloneDX or SPDX) and the cybersecurity risk assessment. You need these to draw up your own DoC and to meet your ongoing vulnerability-handling obligations. If the supplier cannot provide them, factor that into your risk assessment of the deal.
Your supplier must commit to telling you about vulnerabilities in the product and providing security updates across the support period you will declare. That period is presumed to be at least five years. Get this in writing, with timelines that let you meet the CRA's 24h/72h/14-day reporting windows.
You cannot use the original maker's DoC. You must draw up your own Annex V Declaration of Conformity, referencing the conformity assessment you have carried out (or had carried out on your behalf). Keep the technical documentation for 10 years.
The ENISA Single Reporting Platform reporting obligations apply from 11 September 2026 — to products already on the market, not just new launches. Establish your internal process for identifying, assessing, and reporting actively exploited vulnerabilities and severe incidents before that date.
A note on substantial modification
Own-branding makes you the manufacturer from the start - it does not depend on the substantial modification rules. But substantial modification is a separate trigger worth understanding, because it can catch you even if you are not the original brand owner.
Under Article 22, any person (not just an importer or distributor) who carries out a substantial modification of a product and then makes it available on the EU market is treated as a manufacturer for the modified part, subject to Articles 13 and 14. A substantial modification is a change that affects the product's compliance with the Annex I essential requirements, or that changes the intended purpose for which the product was assessed.
This matters if you customise a product for a specific customer, update firmware in a way that materially changes its security properties, or integrate a third-party component that alters the product's attack surface. See our guide on substantial modification for the detail.
Where to go next
- CRA compliance checklist - the full list of manufacturer obligations, with article references.
- CRA deadlines and timeline - every confirmed date, including the 11 September 2026 reporting deadline.
- SBOM starter guide - what to ask your supplier for, and how to build the capability yourself.
- Substantial modification guide - when a change to a product re-opens conformity.
- Importers and distributors guide - if you are not own-branding, your obligations are different but still real.
Official sources: Regulation (EU) 2024/2847 on EUR-Lex · European Commission CRA summary
Stay current as guidance develops. The European Commission published draft implementing guidance in March 2026, and further clarifications are expected before the September 2026 deadline. Subscribe to The CRA Brief for plain-English updates when anything changes — no spam, unsubscribe any time.
This guide explains the CRA's manufacturer definition to help you understand your position. It is general information, not legal advice. For advice specific to your situation, consult a qualified legal adviser.
Related reading

The CRA Authorised Representative (Article 18): What It Is, What It Isn't, and Whether You Need One
Under the Cyber Resilience Act, appointing an EU authorised representative is optional - unlike MDR or RED. Article 18 explained: what the mandate must cover, what it cannot delegate, and why non-EU manufacturers often appoint one anyway.

CRA Transitional Provisions: Do You Have to Re-Certify Products Already on the Market?
Already selling connected products into the EU? Here's exactly what the CRA's transitional provisions mean for legacy inventory - and the one obligation that applies to everyone right now.

CRA Annex I, Part II: The Eight Vulnerability-Handling Obligations That Run for Your Product's Entire Life
Annex I, Part II of Regulation (EU) 2024/2847 sets eight ongoing engineering and process obligations that apply from first sale until end of support. Here's what each one means in practice.