Article 21 — why the CRA treats private-label sellers as manufacturers
If your brand is on a connected product, the Cyber Resilience Act makes you its manufacturer. How the rule works, the GPSR Article 8(1) parallel, substantial modification, and what to ask your factory.
Most private-label sellers of connected products assume cybersecurity is the factory's problem. The factory wrote the firmware, chose the chipset and runs the update server — surely it is responsible if something goes wrong?
Under the Cyber Resilience Act, it is not. If your brand is on the product, the CRA treats you as the manufacturer, with every obligation that comes with it. This guide explains the rule, why it mirrors GPSR, what "substantial modification" means, and the conversation you need to have with your suppliers before December 2027.
What the rule says
The CRA reaches private-label sellers in two ways.
First, the definition of manufacturer already covers anyone who has a product with digital elements designed, developed or manufactured by someone else, and markets it under their own name or trademark. If you commission a Wi-Fi camera from an ODM and sell it as your brand, you are its manufacturer from the start.
Second, Article 21 closes the gap for importers and distributors. An importer or distributor is treated as the manufacturer, and takes on the manufacturer's obligations under Articles 13 and 14, when it:
- places a product with digital elements on the market under its own name or trademark, or
- carries out a substantial modification of a product already on the market.
Article 22 extends the substantial-modification rule to anyone else — not just importers and distributors — who substantially modifies a product and makes it available on the market.
The practical conclusion is the same whichever route applies: own brand means manufacturer. Not the factory. Not the ODM. You.
The GPSR parallel
If this sounds familiar, it should. GPSR Article 8(1) applies the same principle to product safety: anyone who places a product on the market under their own name or trademark, or modifies it in a way that affects compliance, is the manufacturer.
The two rules share a logic. EU law wants a named, reachable party in the supply chain who is responsible for the product as sold. For branded goods, that is the brand owner, because the brand owner decides what is sold, controls the listing and is the name consumers see.
So a private-label seller of a smart plug is already the GPSR manufacturer — responsible for the risk assessment, technical documentation, traceability and labelling. From December 2027 the same seller is also the CRA manufacturer — responsible for cybersecurity. The obligations stack; they don't replace each other.
What "substantial modification" means
A substantial modification is a change to the product after it has been placed on the market that affects its compliance with the essential cybersecurity requirements, or changes its intended purpose in a way the original risk assessment did not cover.
For private-label sellers, the risk usually sits in changes that feel cosmetic but are not:
- Firmware rebranding. Swapping the boot logo and app name is usually harmless. But if the rebrand involves pointing the device at your own cloud backend, changing authentication, or bundling a different companion app, you may have changed the product's attack surface.
- Adding features. Enabling remote access, adding a voice assistant, or unlocking a radio mode the original design disabled.
- Changing the update route. Moving from the factory's update server to your own, or disabling automatic updates.
Ordinary security updates that fix vulnerabilities, without changing the intended purpose, are not substantial modifications. If you are unsure whether a change is substantial, treat it as substantial and redo the risk assessment — the cost of being wrong is carrying manufacturer obligations for a product you have not assessed.
What being the manufacturer means in practice
As the deemed manufacturer, the obligations in the Cyber Resilience Act overview are yours:
The cybersecurity risk assessment. You must carry it out and keep it current. Your factory's design documents and test reports are inputs; the assessment and the responsibility are yours.
The SBOM. You must be able to produce a machine-readable Software Bill of Materials listing the product's software components, at least the top-level dependencies. You cannot write this yourself from the outside — it has to come from whoever builds the firmware.
Vulnerability handling and reporting. You must publish a contact point for vulnerability reports, fix vulnerabilities without delay, and notify actively exploited vulnerabilities and severe incidents — with a 24-hour early warning — through ENISA's single reporting platform. That duty has applied since 11 September 2026. See CRA vulnerability reporting.
Security updates for the support period. You must set a support period of at least five years (unless the product's expected use is shorter), show the end date at the point of sale, and deliver free security updates throughout.
Conformity assessment, documentation and CE marking. You must complete the correct assessment route, draw up the technical documentation, issue the EU Declaration of Conformity referencing the CRA, and affix the CE mark.
Every one of those depends on information and work that sits with your supplier. That is the real problem Article 21 creates.
The factory conversation
Before December 2027, every private-label seller of connected products needs a clear answer from each supplier to these questions:
- Can you provide an SBOM for this product, in SPDX or CycloneDX format, and update it with every firmware release?
- Will you commit, in writing, to security updates for at least five years from when we place the last unit on the market — and fix reported vulnerabilities promptly?
- Who runs the update infrastructure, and what happens to it if our contract ends or your company is acquired?
- Will you tell us within hours when you learn of an actively exploited vulnerability, so we can meet the 24-hour early warning?
- Can you provide the design and test evidence we need for the risk assessment and technical documentation?
- Is the product secure by default — unique credentials per device, no open debug ports, encrypted communications?
Put the answers into the supply contract. A verbal "yes" from a sales contact is not evidence a market surveillance authority will accept.
If your supplier can't deliver
Be realistic about what a "no" means. If a supplier cannot provide an SBOM and cannot commit to security updates, you cannot demonstrate conformity with the CRA. After 11 December 2027 you cannot place that product on the EU market under your brand.
Your options are:
- Change supplier to one that can support CRA compliance — many larger ODMs are already building this into their offers;
- Change the product — for example, a non-connected version, if that still makes sense for customers; or
- Stop selling it in the EU once your pre-December 2027 stock runs out.
Units placed on the market before 11 December 2027 do not need to be re-assessed unless they are substantially modified. But the reporting obligation already applies to them, and stock placed on the market after the deadline must comply in full. Plan your last compliant order date with that in mind.
What to do this quarter
- Mark every own-brand product with digital elements in your catalogue.
- Send the six questions above to each supplier and record the answers.
- Set up your reporting route now — the 24-hour obligation is live.
- Review planned firmware changes for anything that could count as a substantial modification.
- Check your GPSR position at the same time. The same brand-owner principle makes you the GPSR manufacturer, and GPSR has applied since December 2024.
The EU Cyber Resilience Act Playbook (€49) includes a full Article 21 analysis, the SBOM template and a risk assessment template you can hand to your suppliers.
This guide is general information based on the published text of Regulation (EU) 2024/2847; it is not legal advice. Guidance and harmonised standards are still being developed.
More on the Cyber Resilience Act
- CRA Vulnerability Reporting: 24-Hour Rule — CRA vulnerability reporting has applied since 11 September 2026: 24-hour early warning, 72-hour notice, final report.
- GPSR Seller Responsibilities Explained — What GPSR requires from manufacturers, importers, distributors and online sellers — and who is liable.
- Cyber Resilience Act (CRA) Guide for Sellers — What the EU Cyber Resilience Act means for connected products: scope, deemed manufacturer rule, SBOM, reporting and the 2027 deadline.
- Free GPSR checker → — The deemed manufacturer rule applies under GPSR too — check your listing in 30 seconds.
- EU Cyber Resilience Act Playbook — SBOM, 24-hour reporting, Article 21 and conformity assessment — €49.
- All EU regulations we track — overview
Need hands-on help? Our team can handle your compliance — from a €499 single-product scan to full catalogue management. Book a consultation →
CRA platform support coming soon — start with the 9 regulations we cover today
A free workspace checks your first three products against GPSR, CE marking, the Battery Regulation and six more EU regulations. CRA assessments join the platform next.
Start free workspaceEvery EU deadline, on one page.
Nine mandates, each with dates attached between now and 2030. Get the calendar, plus a note when the guidance behind an article like this one changes.
- → Every applicable EU compliance date
- → Which mandate hits your category first
- → An alert when a rule or guidance changes
Compliance guidance based on published EU regulatory texts. Not legal advice. Consult qualified counsel for your specific situation.