The CRA treats an importer or distributor as the manufacturer, with Articles 13 and 14 obligations, when it places a product on the market under its own name or trademark or substantially modifies a product already placed on the market.
The Regulation also treats another person that substantially modifies and makes a product available as a manufacturer for the affected part or, when overall cybersecurity is affected, for the whole product.
Inventory the role-changing facts
List every product sold under a house brand, relabelled for a regional channel, modified after import, or combined into a new market offering. For each, record the original manufacturer, contracting chain, branding shown to users, technical changes, release owner, and entity making it available.
Do not let procurement labels decide the legal role. “Distributor,” “integrator,” and “OEM” may describe a commercial relationship without resolving the CRA test.
Create a role-decision file
For every potentially role-changing event, record the legal entity, original product, new market offering, name or trademark shown, technical change, cybersecurity effect under review, release date, evidence, and accountable reviewer. Keep branding and modification tests as separate findings.
If only part of a product is modified, map the changed part and its dependencies. If the modification may affect overall cybersecurity, preserve the architecture and threat analysis used to reach that conclusion. Do not let a commercial launch deadline decide the role before the evidence is reviewed.
Review modifications at the product boundary
Describe what changed, who controlled it, and whether it affects the cybersecurity of one part or the product as a whole. Preserve architecture, version, configuration, and release evidence. Assign counsel and product security to approve the role conclusion together.
Where the role changes, create manufacturer-level reporting readiness for that entity: product inventory, trigger ownership, coordinating-CSIRT route, platform representatives, user-contact path, and evidence retention. A contract saying the original vendor will help does not replace the new manufacturer’s own record.
Where the role does not change, preserve why neither the branding nor modification test was met and define a reopening condition. A later firmware change, private-label decision, or expanded integration can alter the facts.
Keep supplier escalation alongside reporting
The deemed manufacturer may still need rapid evidence and fixes from the original supplier. Define the protected channel, response expectations, and information-sharing terms before an event. Link supplier correspondence to the reporting case without allowing it to obscure who owns the Article 14 decision.
Review the matrix whenever branding, firmware, software bundles, or integration responsibilities change. The safe result is one accountable legal manufacturer per market offering, supported by product-specific facts rather than assumptions about the supply chain.
At incident intake, resolve the role before assigning the Article 14 owner. Link supplier assistance and evidence to the case, but keep the approved manufacturer decision visible to every reporter and reviewer.
Continue this workflow with the manufacturer register and the non-EU manufacturer analysis.