Source: OJ L 2024/2847, 20.11.2024Current language: EN
- Cyber resilience for products with digital elements
Basic legislative acts
- CRA regulation
Article 20 Obligations of distributors
Summary What does Article 20 of the CRA regulation say?
This article sets out the obligations that apply specifically to distributors — those in the supply chain who make products with digital elements available on the EU market without affecting their properties.
It sits alongside Articles 13 and 19, which cover manufacturers and importers respectively, and together these articles form the framework of obligations across the supply chain.
Distributors are cast as a final checkpoint before a product reaches the market: they must verify that the CE marking is in place and that manufacturers and importers have met their key documentation and information obligations.
Beyond pre-market checks, the article also governs what distributors must do when they discover non-compliance or vulnerabilities after a product is already on the market, including their duty to report to manufacturers and market surveillance authorities and to cooperate with those authorities on request.
Important points:
- Verify, before making a product available, that it bears the CE marking and that all required documentation from the manufacturer and importer has been provided.
- If you become aware of a vulnerability or non-compliance after the product is on the market, inform the manufacturer without undue delay and, where a significant cybersecurity risk exists, immediately notify the relevant market surveillance authorities.
- If the manufacturer has ceased operations and can no longer meet its obligations under this Regulation, inform the relevant market surveillance authorities without undue delay and, to the extent possible, the users of the affected products.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
When making a product with digital elements available on the market, distributors shall act with due care in relation to the requirements set out in this Regulation.
Before making a product with digital elements available on the market, distributors shall verify that:
the product with digital elements bears the CE marking;
the manufacturer and the importer have complied with the obligations set out in Article 13(15), (16), (18), (19) and (20) and Article 19(4), and have provided all necessary documents to the distributor.
Where a distributor considers or has reason to believe, on the basis of information in its possession, that a product with digital elements or the processes put in place by the manufacturer are not in conformity with the essential cybersecurity requirements set out in Annex I, the distributor shall not make the product with digital elements available on the market until that product or the processes put in place by the manufacturer have been brought into conformity with this Regulation. Furthermore, where the product with digital elements poses a significant cybersecurity risk, the distributor shall inform, without undue delay, the manufacturer and the market surveillance authorities to that effect.
Distributors who know or have reason to believe, on the basis of information in their possession, that a product with digital elements, which they have made available on the market, or the processes put in place by its manufacturer are not in conformity with this Regulation shall make sure that the corrective measures necessary to bring that product with digital elements or the processes put in place by its manufacturer into conformity, or to withdraw or recall the product, if appropriate, are taken.
Upon becoming aware of a vulnerability in the product with digital elements, distributors shall inform the manufacturer without undue delay about that vulnerability. Furthermore, where the product with digital elements presents a significant cybersecurity risk, distributors shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market to that effect, giving details, in particular, of the non-compliance and of any corrective measures taken.
Distributors shall, further to a reasoned request from a market surveillance authority, provide all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements and the processes put in place by its manufacturer with this Regulation in a language that can be easily understood by that authority. They shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by a product with digital elements which they have made available on the market.
Where the distributor of a product with digital elements becomes aware, on the basis of information in its possession, that the manufacturer of that product has ceased its operations and, as result, is not able to comply with the obligations laid down in this Regulation, the distributor shall inform, without undue delay, the relevant market surveillance authorities about this situation, as well as, by any means available and to the extent possible, the users of the products with digital elements placed on the market.
Relevant recitals
Recital 20 Distribution via open repositories
The sole act of hosting products with digital elements on open repositories, including through package managers or on collaboration platforms, does not in itself constitute the making available on the market of a product with digital elements. Providers of such services should be considered to be distributors only if they make such software available on the market and hence supply it for distribution or use on the Union market in the course of a commercial activity.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
incident
Definition
vulnerability
Definition
importer
Definition
component
Definition
cyber threat
Definition
cybersecurity
Definition
manufacturer
Definition
distributor
Definition
making available on the market
Definition
Union harmonisation legislation
Definition
product with digital elements
Definition
CE marking
Definition
significant cybersecurity risk
Definition
remote data processing
Definition
cybersecurity risk
Definition
electronic information system
Definition
market surveillance authority
Definition
hardware
Definition
software
Definition
recall