Under the Cyber Resilience Act (CRA), an EU importer must do more than receive a product and make it available for sale. Before placing a product with digital elements on the Union market, the importer must verify that the manufacturer has completed key conformity steps, that the required product and user information is present, and that the product should not be held back because of known non-conformity or significant cybersecurity risk.
Article 19 turns that into a defined importer control point in the supply chain. The practical task is not to repeat the manufacturer's entire engineering process, but to obtain and verify enough controlled evidence to show that the required manufacturer-side steps were completed before the importer places the product on the market.
The general CRA obligations, including Article 19, apply from 11 December 2027. Article 14 manufacturer reporting obligations apply earlier, from 11 September 2026, but they should not be confused with the separate importer duties in Article 19.
First confirm that you are acting as an importer
The CRA defines an importer as a natural or legal person established in the Union who places on the market a product with digital elements bearing the name or trademark of a natural or legal person established outside the Union. "Placing on the market" means the first making available of that product on the Union market.
That role definition matters because CRA duties follow the economic operator's actual role, not the label used in a purchasing system. A company should therefore document, for each product flow:
- who the manufacturer is and where it is established;
- whose name or trademark appears on the product;
- which legal entity first places the product on the Union market;
- whether another group company is the importer of record for CRA purposes; and
- whether the importer later changes the product or markets it under its own name or trademark.
The last point is especially important because Article 21 can turn an importer into a manufacturer for CRA purposes.
Build a pre-market importer verification gate
Article 19 requires importers to place on the market only products that comply with the essential cybersecurity requirements in Annex I Part I and where the manufacturer's vulnerability-handling processes comply with Annex I Part II. Before market placement, the importer must verify a defined set of manufacturer outputs.
A practical gate should record the evidence reviewed, its version or identifier, the product or model it covers, who performed the check, when it was performed, and the resulting decision.
Conformity assessment
The importer must ensure that the manufacturer has carried out the appropriate conformity assessment procedure under Article 32.
The importer does not need to recreate the assessment, but it should verify that an assessment route exists, that it is appropriate for the product's CRA classification and circumstances, and that the resulting records actually cover the product being imported. Where a notified body or another third-party route is required, the importer should be able to identify the relevant certificate or assessment record rather than relying on a generic supplier statement.
Technical documentation
The importer must ensure that the manufacturer has drawn up the technical documentation required by the CRA.
This is a verification duty, not a requirement for the importer to author the manufacturer's technical file. The importer should nevertheless have a controlled way to confirm that the documentation exists and can be made available to authorities when required. A useful verification record can include the technical-documentation revision or package identifier, the product scope, the manufacturer responsible for it, and the location or process through which it can be retrieved.
CE marking and declaration of conformity
Before placing the product on the market, the importer must ensure that it bears the CE marking required by Article 30 and is accompanied by the EU declaration of conformity referred to in Article 13(20).
The check should go beyond "a CE logo is visible." Verify that the declaration identifies the same product, variant or software delivery that is being imported and that the marking is applied in the permitted form for that product. Where a simplified EU declaration of conformity is used, confirm that the required reference to the full declaration is controlled and resolves to the correct product information.
User information and instructions
Article 19 also requires the importer to ensure that the product is accompanied by the information and instructions to the user set out in Annex II, in a language that can be easily understood by users and market-surveillance authorities.
For an Austrian market-placement process, this should be handled as a release and distribution control rather than a packaging afterthought. Record which user-information revision accompanies the imported product and verify that it maps to the same product state as the declaration and technical evidence.
Manufacturer identification and required product information
Article 19(2) also points the importer to several manufacturer obligations in Article 13. The importer must ensure that the manufacturer has provided the required product identification, manufacturer contact information and support-period information.
A practical check should therefore cover at least:
- a type, batch, serial number or another identifier that allows product identification;
- the manufacturer's name, registered trade name or trademark;
- the manufacturer's postal and digital contact details and, where applicable, website;
- the single point of contact required for communications concerning vulnerabilities; and
- the support-period information required by the CRA.
These fields should be checked against the physical product, software delivery, packaging or accompanying documentation as applicable, not copied from a supplier master-data record without verification.
Add the importer's own contact details
Article 19(4) requires importers to indicate their own name, registered trade name or trademark, postal address, email address or other digital contact, and, where applicable, website. The information must be placed on the product or, where that is not possible, on packaging or accompanying documentation.
The contact details must be clear, understandable and legible. This creates a concrete operational dependency between legal-entity master data and product or packaging releases. If the importing entity, address or contact channel changes, teams need a controlled way to identify affected products and documentation rather than waiting for the next artwork update to reveal the mismatch.
Do not place a product on the market when conformity is in doubt
If an importer considers or has reason to believe that a product or the manufacturer's processes do not conform to the CRA's essential cybersecurity requirements, Article 19 requires the importer not to place the product on the market until conformity has been restored.
If the product presents a significant cybersecurity risk, the importer must also inform the manufacturer and the relevant market-surveillance authorities. This means the importer needs an escalation path before stock reaches the market.
A workable hold process should answer four questions:
- What evidence or observation triggered the concern?
- Which product identifiers, batches or software versions are affected?
- Who has authority to release or continue the market-placement hold after the issue is resolved?
- What evidence demonstrates that conformity was restored or that the original concern was resolved?
The importer should preserve that decision trail. A later authority request may focus not only on the final state but also on what the importer knew before market placement and how it acted.
Post-market duties continue after import
Importer responsibilities do not end when the product crosses the market-placement gate. Article 19(5) requires action when an importer has reason to believe that a product it placed on the market is not in conformity with the CRA.
The importer must immediately take the corrective measures necessary to bring the product into conformity, or to withdraw or recall it as appropriate. If the importer becomes aware of a vulnerability, it must inform the manufacturer without undue delay. Where the product presents a significant cybersecurity risk, the importer must immediately inform the market-surveillance authorities of the Member States in which it made the product available, giving details of the non-conformity and corrective measures taken.
This makes post-market intake part of the importer's CRA workflow. Security advisories, supplier notices, customer reports, support escalations and authority communications need a route to the team that owns the importer decision for the affected product.
Retain the declaration and preserve access to technical evidence
Article 19(6) requires the importer to keep a copy of the EU declaration of conformity available to market-surveillance authorities for at least 10 years after the product is placed on the market or for the support period, whichever is longer. The importer must also ensure that the technical documentation can be made available to those authorities on request.
A useful retention package can include:
- the EU declaration of conformity actually verified before market placement;
- product and release identifiers covered by that declaration;
- the importer verification record and decision date;
- the technical-documentation package identifier or retrieval reference;
- conformity-assessment references and certificates where applicable;
- the user-information revision verified for the market; and
- later corrective-action or authority-request records linked to the same product scope.
Do not silently replace the retained declaration with a newer version when a manufacturer updates its documentation. Historical evidence needs to remain connected to the product state that was actually placed on the market.
Be ready for a reasoned authority request
Under Article 19(7), an importer must provide, following a reasoned request from a market-surveillance authority, the information and documentation necessary to demonstrate the conformity of the product and of the processes put in place by the manufacturer. The importer must also cooperate with the authority on action taken to eliminate cybersecurity risks posed by products it placed on the market.
The operational test is therefore retrieval, not merely retention. If the importer verification package exists but teams cannot locate the relevant declaration, product scope or technical-documentation contact when an authority asks, the evidence process is incomplete.
Plan for manufacturer cessation
Article 19(8) adds a less common but important scenario. If the importer becomes aware that the manufacturer has ceased operations and can no longer comply with CRA obligations, the importer must inform the relevant market-surveillance authorities without undue delay and, by any means available and to the extent possible, inform users of products placed on the market.
Importers should define how supplier monitoring, insolvency information, discontinued support channels or other credible signals reach the product-security and regulatory owners. The response should identify affected products and markets before communications are sent.
Know when the importer becomes the manufacturer
Article 21 changes the role entirely in two cases: when an importer places a product with digital elements on the market under its own name or trademark, or when it carries out a substantial modification of a product already placed on the market.
In those cases, the importer is considered a manufacturer for CRA purposes and becomes subject to Articles 13 and 14. A private-label decision, rebranding project or technical modification therefore needs a CRA role check before teams assume that the lighter importer verification model still applies.
The same principle applies to substantial product changes: document who controls the change, whether it meets the CRA definition of substantial modification, and which legal entity now owns the resulting manufacturer obligations.
Austria: make the importer check a controlled market-placement step
The Austrian Federal Chancellery's CRA FAQ describes the Article 19 importer flow in operational terms: verify the manufacturer's conformity assessment and technical documentation, CE marking, declaration, user information, product identification, support-period information and manufacturer contacts; add importer contacts; stop market placement where conformity is in doubt; retain the declaration and technical-documentation access; and act on post-market non-conformity and vulnerabilities.
For Austrian organizations importing products from manufacturers outside the EU, this supports a simple governance model: no market-placement approval until the Article 19 evidence set is complete and attributable to the exact product being imported.
Keep importer evidence connected to the exact product
Importer verification can become a collection of PDFs and email confirmations unless each record stays tied to the exact product, manufacturer, market-placement decision and later corrective action.
AA-sec is designed around traceability between requirements, security evidence, decisions and exact product or lifecycle context. That can support internal evidence organization for teams coordinating importer verification with product-security and CRA-readiness work, while the importer remains responsible for its own legal verification and decisions.
Key takeaway
Treat CRA importer obligations as a controlled market-placement gate, not a supplier questionnaire completed once. Before the first Union market placement, verify the manufacturer's conformity assessment, technical documentation, CE marking, declaration, user information and required product details; add the importer's own contacts; and hold the product when conformity is in doubt.
After market placement, retain the exact declaration and retrieval path for technical evidence, route vulnerabilities and non-conformity into corrective action, cooperate with authorities, and re-check the company's legal role whenever branding or substantial modification could turn the importer into the manufacturer.
Official sources
- Regulation (EU) 2024/2847 — Cyber Resilience Act — EUR-Lex
- The Cyber Resilience Act - Summary of the legislative text — European Commission
- Fragen und Antworten zur Cyberresilienz-Verordnung — Austrian Federal Chancellery
