← CRA Glossary
CRA Legal Terms

Economic Operator (CRA)

Economic operators are the legal entities in the supply chain - manufacturers, authorised representatives, importers, and distributors - upon whom the EU Cyber Resilience Act places specific obligations. The manufacturer bears the primary and most extensive obligations, but importers and distributors have supplementary duties that can result in them inheriting manufacturer obligations if the original manufacturer is non-compliant.

Economic operators are the legal entities in the supply chain - manufacturers, authorised representatives, importers, and distributors - upon whom the EU Cyber Resilience Act places specific obligations. The manufacturer bears the primary and most extensive obligations, but importers and distributors have supplementary duties that can result in them inheriting manufacturer obligations if the original manufacturer is non-compliant.

CRA Legal Terms

What Is an Economic Operator Under the CRA?

The EU Cyber Resilience Act uses 'economic operator' as the umbrella term for all entities in the commercial supply chain who have a role in bringing a product with digital elements to the EU market. The CRA defines four types of economic operator: manufacturers (who design, develop, and produce products); authorised representatives (EU-established entities designated by non-EU manufacturers to act on their behalf); importers (EU-established entities who place a non-EU manufacturer's products on the EU market); and distributors (entities in the supply chain who make products available on the market after a manufacturer or importer). Each type has distinct but overlapping obligations.

CRA reference:Article 3, Article 17, Article 18, Article 19, Article 20

How Obligations Are Distributed Between Economic Operators

The manufacturer bears the primary and most extensive obligations: conducting risk assessments, implementing Annex I requirements, establishing CVD processes, generating SBOMs, affixing CE marking, and providing security updates. The importer must verify that the manufacturer has completed conformity assessment, that the product bears the CE marking, and that the manufacturer's contact details are on the product. If an importer has reason to believe a product is not compliant, they must not place it on the market. The distributor must similarly verify CE marking and documentation before making products available. Crucially, if a manufacturer cannot be identified, importers or distributors can become responsible for manufacturer obligations.

CRA reference:Article 17, Article 18, Article 19, Article 20

Authorised Representatives and Non-EU Manufacturers

Non-EU manufacturers who place products on the EU market must designate an authorised representative established in the EU before market placement. The authorised representative acts as the regulatory point of contact within the EU: they receive and handle communications from market surveillance authorities, hold a copy of the technical documentation, and are listed in the Declaration of Conformity. Non-EU manufacturers who fail to designate an authorised representative are non-compliant, and importers who knowingly place such products on the EU market share liability. The authorised representative does not acquire the substantive technical obligations of the manufacturer but can face liability for misrepresentation.

CRA reference:Article 18

Common Mistakes

The most common economic operator error is assuming that obligations flow only to the manufacturer and that importers and distributors are passive bystanders. The CRA imposes active verification duties on importers and distributors: they must not place or make available products that they have reason to believe are non-compliant. Importers who source products from non-EU manufacturers without verifying CVD policy compliance, CE marking, and Declaration of Conformity completeness are themselves non-compliant. Another error is failing to designate an authorised representative before market placement - this is a pre-condition for legal EU market access for non-EU manufacturers, not an administrative formality that can be addressed after the fact.

CRA reference:Article 18, Article 19, Article 20

CVD Portal makes Economic Operator (CRA) compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Is a software company that publishes apps a manufacturer under the CRA?+

Yes, if the software is a standalone product with digital elements placed on the EU market. The CRA explicitly covers software as well as hardware. A company that develops and distributes a standalone application - including a mobile app, a desktop application, or a cloud-connected device application - is a manufacturer for CRA purposes and must comply with all manufacturer obligations, including Annex I essential requirements, CVD process establishment, SBOM generation, and security update provision.

What happens if a non-EU manufacturer does not comply with the CRA?+

If the manufacturer cannot be identified or is non-compliant and cannot be engaged, the CRA provides that the **importer** may become responsible for the manufacturer's obligations. This is a significant liability risk for businesses that source products from non-EU manufacturers without conducting due diligence on CRA compliance. Importers should contractually require CRA compliance from their suppliers and verify conformity documentation before each product is placed on the EU market.

Does an open-source software project qualify as an economic operator under the CRA?+

Generally, not-for-profit open-source projects are not considered economic operators in the traditional sense, as they do not pursue a commercial activity. The CRA introduces a specific category of 'open-source software steward' with lighter-touch obligations for these entities. However, a company that develops open-source software as part of a commercial activity - for example, selling support contracts or commercial versions - may be considered a manufacturer for the commercial components. The boundary between steward and manufacturer for open-source entities requires careful legal analysis.

Related terms

Manufacturer Obligations (CRA)Manufacturer obligations under the EU Cyber Resilience Act are the comprehensive set of cybersecurity duties that apply to any entity that designs, develops, or produces a product with digital elements for the EU market. These obligations span product design, vulnerability handling, market surveillance cooperation, and post-market security support.Conformity AssessmentConformity assessment is the process by which a manufacturer demonstrates that its product meets the CRA's essential cybersecurity requirements. The process required depends on the product's classification: Default and Class I products can self-assess; Class II and Critical products require third-party assessment by a notified body.CE Marking (Cybersecurity)The CE mark is the mandatory conformity marking that manufacturers must affix to products with digital elements before placing them on the EU market under the CRA. It indicates that the product meets the CRA's essential cybersecurity requirements and has passed the applicable conformity assessment procedure.EU Declaration of Conformity (DoC)The EU Declaration of Conformity is a formal document signed by the manufacturer (or authorised representative) declaring that a product meets the essential requirements of all applicable EU regulations, including the CRA. It must be drawn up before the CE mark is affixed and kept available for market surveillance authorities for at least 10 years.Market Surveillance Authority (MSA)A Market Surveillance Authority is a national regulatory body responsible for enforcing product safety and compliance legislation within an EU member state. Under the Cyber Resilience Act, MSAs investigate non-compliant products with digital elements, order corrective actions, and can impose fines or market bans.

Browse the full CRA Compliance Checklist

See how Economic Operator (CRA) fits into your complete CRA compliance programme.

View checklists →