The EU Cyber Resilience Act: What Hardware Importers Must Do

Table of Contents

You have named your importer of record, cleared customs, and checked the CE marking. For connected hardware entering the EU, that is no longer the whole job. The EU Cyber Resilience Act adds a separate market-access condition, cybersecurity, and it introduces a second kind of importer whose duties are defined by law, not by your freight paperwork. The trap is assuming the party who handles your customs entry automatically covers this too. It does not.

This guide is written from the freight and customs side of that problem, which is where the gap usually hides.

If you bring servers, networking equipment, IoT devices, or other hardware with digital elements into the EU, the CRA may affect you depending on the product’s scope, exclusions, and intended use. What follows is the deadline that is already live, the two importer roles you need to keep separate, exactly what the law makes an importer verify, the penalties for getting it wrong, and how to prepare. The dates, thresholds, and obligations here are based primarily on Regulation (EU) 2024/2847 and current European Commission and ENISA guidance, and where the detail is still being defined, this guide says so.

Quick Answer

QuestionShort answer (verify for your product)
What is itRegulation (EU) 2024/2847, mandatory cybersecurity requirements for products with digital elements
Who it coversManufacturers, importers, and distributors placing covered products on the EU market, wherever based
Manufacturer vulnerability reporting from11 September 2026
Full application from11 December 2027
How compliance is shownConformity assessment, EU declaration of conformity, and CE marking
Importer penalty tierUp to 10 million euros or 2% of worldwide annual turnover for specified importer breaches once the applicable provisions apply; Member States set enforcement rules
A starting point for orientation, not legal advice. Confirm the requirements for your specific product and role.

What the Cyber Resilience Act Actually Is

The Cyber Resilience Act, formally Regulation (EU) 2024/2847, is the first EU-wide law to set mandatory cybersecurity requirements for products with digital elements, covering both hardware and software across the full product lifecycle. It entered into force on 10 December 2024. Its central idea is a shift of responsibility: security becomes the duty of the businesses that design, import, and sell a product, rather than a problem left to the end user. A covered product may only be placed on the EU market when the applicable CRA requirements have been met and the relevant economic operators have fulfilled their obligations.

The scope is broad, but connectivity alone is not a complete legal determination. A product with digital elements is any hardware or software product, including its remote data processing solutions, whose intended or reasonably foreseeable use involves a direct or indirect data connection to a device or network. Whether a specific product is covered depends on the CRA definition, its exclusions, the product’s category and component status, and how it interacts with other EU legislation. Standalone software can be in scope, and a component placed separately on the market may have its own treatment.

Some products are excluded, or subject to specific interaction rules, where other EU legislation already addresses the relevant cybersecurity requirements, so the applicable framework must be checked product by product. The reach also extends beyond the EU: a manufacturer in the United States, Taiwan, or China falls within the regulation if its products are placed on the EU market. That extraterritorial effect is why the importer role carries real weight, and why the next question is who, precisely, the importer is.

Does the CRA Apply to Servers and Data Centre Equipment?

Potentially. Servers, switches, routers, network interface cards, operating systems, security appliances, and other data centre equipment may fall within the Cyber Resilience Act where they meet the definition of a product with digital elements and no exclusion applies. For the connected infrastructure that Carra Globe’s clients import, this is the practical question that decides whether the CRA obligations attach.

The important distinction is that the CRA does not regulate a product simply because it is electronic or used in a data centre. The product’s functionality, connectivity, category, component status, intended purpose, and interaction with other EU legislation must be assessed before deciding whether the CRA applies. Each product line should be assessed on its own facts rather than assumed in or out.

The CRA Importer Is Not the Same as the Customs Importer of Record

This distinction is central, and conflating the two roles is the most common mistake importers make. Bringing a product into the EU involves two roles that arise from different legal frameworks.

The customs importer of record is the party responsible for the customs entry and its associated obligations: classification, valuation, duties, and customs compliance. The Cyber Resilience Act, by contrast, defines an “importer” as the economic operator established in the Union that places a product with digital elements from a third country on the Union market. That is defined by placing the product on the market, not by physically bringing it in or clearing customs, and it carries its own statutory duty to verify conformity first.

The same organisation may perform both roles, but neither should be assumed from the other. A customs importer of record is not automatically the CRA importer, and customs representation and CRA economic-operator status should be confirmed separately for each shipment. Getting this mapping right is the first compliance question, not an administrative afterthought, because the two roles carry different duties and different penalty exposure.

The Deadlines That Matter

The regulation is already in force, and its provisions apply in stages. Treating December 2027 as the only date is the mistake that leaves an import programme unprepared. Four milestones matter for planning.

  • 11 June 2026: the provisions on the notification of conformity assessment bodies began to apply, establishing the framework for notified conformity-assessment capacity under the CRA.
  • 11 September 2026: the manufacturer reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting covered products through the EU single reporting platform, and this extends to in-scope products already on the market before 11 December 2027.
  • 11 December 2026: Member States are to strive to ensure that a sufficient number of notified bodies are available for CRA conformity assessments. This is a capacity milestone, not a guarantee that every product category will have immediate assessment capacity.
  • 11 December 2027: the general application date arrives. The essential requirements, conformity assessment, CE marking, and principal manufacturer, importer, and distributor obligations generally apply from this date, subject to the regulation’s transitional provisions and any earlier provisions that already apply.

The 11 September 2026 reporting obligations fall primarily on manufacturers, not on importers as a general reporting duty.

Importers should not read that as breathing room, though: building the verification, documentation, and supplier-evidence process the full regime requires takes time, and the conformity assessment framework is being stood up now. The European Commission published practical guidance on 27 July 2026, covering scope, substantial modification, support periods, reporting, and risk assessment, available on its Cyber Resilience Act policy pages. That Commission guidance is non-binding and should be read alongside the regulation itself. The sensible planning assumption is to be ready ahead of December 2027, not on it.

What an Importer Must Do Under Article 19

One timing point first. The Article 19 duties below describe the importer obligations that apply when the main CRA regime applies from 11 December 2027. Importers should build these controls now, but should not read this as saying that every Article 19 verification and CE-marking obligation is already enforceable for every product before that date.

The manufacturer remains responsible for designing the product, meeting the essential cybersecurity requirements, carrying out the applicable conformity assessment, preparing the technical documentation, and issuing the EU declaration of conformity. The importer’s duties, set out in Article 19 of the regulation, are independent of that, and they run in two phases: verification before placing the product on the market, and active obligations afterwards.

This is real due diligence, not a box-tick. The importer is not required to reproduce the manufacturer’s cybersecurity development process or repeat the conformity assessment, but checking that a CE mark simply exists is not enough. Before placing a product with digital elements on the market, an importer must ensure the manufacturer carried out the appropriate conformity assessment, drew up the technical documentation, and that the product bears the CE marking and is accompanied by the EU declaration of conformity, the user information and instructions, and the product identification and manufacturer contact details.

It must place on the market only products that comply, and must not place a product it knows, or has reason to believe, does not conform until that is fixed.

The obligations do not stop at the border. After placing a product on the market, an importer must keep the EU declaration of conformity available and, on a reasoned request, provide documentation demonstrating conformity to market surveillance authorities. It must ensure that storage and transport conditions under its control do not compromise the product’s conformity, and take corrective action, up to withdrawal or recall, where it identifies non-conformity.

If an importer becomes aware of a vulnerability, it must inform the manufacturer without undue delay. Where the product presents a significant cybersecurity risk, the importer must follow the applicable authority-notification requirements, including informing the market surveillance authorities of the affected Member States where Article 19 requires it, and providing details of the non-compliance and any corrective measures taken.

Where the importer knows, or has reason to believe, that a product it has placed on the market is not compliant, it must take the necessary corrective measures, or withdraw or recall the product where appropriate. The formal Article 14 reporting sequence, the early warning, follow-up notification, and final report, primarily applies to manufacturers.

On records, for products subject to the applicable CRA obligations, importers must keep a copy of the EU declaration of conformity available for at least 10 years after the product is placed on the market, or for the support period, whichever is longer.

The transition rule matters for existing equipment: under Article 69, products placed on the EU market before 11 December 2027 generally become subject to the CRA requirements if they undergo a substantial modification from that date, while the Article 14 reporting duty applies to in-scope products already on the market as well. Whether a later software or hardware change is a substantial modification should be assessed against the regulation and the Commission’s guidance.

There is a trap worth naming. If an importer or distributor places a product on the market under its own name or trademark, or modifies a product already on the market in a substantial way, it can be treated as a manufacturer and take on the far heavier manufacturer obligations. The commercial decision to rebrand a device can quietly convert a verification duty into full design-and-assessment liability. Knowing which role you are in is the first compliance question.

CRA importer document check

CheckWhat the importer should verify
Product scope and conformityProduct assessed against the CRA scope, category, and exclusions, with the manufacturer’s conformity process and product requirements verified
ManufacturerManufacturer identity and contact details present
Conformity assessmentAppropriate procedure completed by the manufacturer
Technical documentationManufacturer has drawn it up
EU declaration of conformityCurrent declaration available
CE markingCorrectly affixed
User informationRequired instructions present, in an understandable language
VulnerabilitiesProcess to escalate a known vulnerability to the manufacturer
RecordsEU declaration of conformity retained for at least 10 years after the product is placed on the market, or the support period, whichever is longer
Market surveillanceProcess to respond to an authority’s reasoned request
Indicative checklist based on Article 19. Confirm the exact requirements for your product and role.

Importing connected hardware into the EU and unsure who carries the CRA duties? Carra Globe coordinates EU market entry alongside customs clearance and acts as importer of record across 175+ countries, checking that the required product-compliance documentation has been provided and flagging gaps before shipment. Request an EU market-entry review →

Infographic contrasting the customs importer of record with the CRA importer, the Article 19 checks, and the Cyber Resilience Act timeline.

Customs Release and Placing on the Market Are Not the Same

The Cyber Resilience Act is a product-compliance regulation, not a customs or tariff measure, and that difference matters for how you plan an EU import. Clearing customs and paying any duty gets goods into free circulation. It does not, on its own, make a product legally sellable in the EU.

Importation and placing on the market are related but distinct: a product may enter the EU for testing, temporary admission, re-export, exhibitions, research, or further manufacturing without being placed on the Union market in the same way as a finished product sold for use. Check the product’s customs procedure and intended use before assuming the CRA importer obligations apply identically.

The CRA also becomes one of the EU conformity bases for covered products rather than replacing the others. A connected product may already need CE marking under the applicable EU product legislation, including electrical-safety, electromagnetic-compatibility, and, where relevant, radio-equipment requirements.

The CRA adds cybersecurity requirements to that framework. For a covered product, CE marking indicates conformity with the applicable CRA requirements and any other EU legislation covered by the product’s conformity assessment.

It is not a standalone cybersecurity certificate and does not replace separate obligations under electrical-safety, EMC, radio-equipment, machinery, medical-device, or other applicable rules, and a single EU declaration of conformity can cover several applicable acts at once. A server, a router, or a radio-enabled device may therefore need to satisfy more than one instrument before it can lawfully be placed on the market.

The CRA is also not the only EU regime that places liability on the importer rather than the overseas maker: our guide to EU Digital Product Passport importer liability covers the parallel lifecycle-data obligations under the ESPR framework. Our field guide to HS codes for electronics covers the customs-classification side that runs alongside, and the global trade compliance overview sets out how these layers fit together.

The Penalties, and Which Tier Applies to Importers

Article 64 of the regulation sets maximum administrative fine levels in tiers, and it is worth being precise about them. Breaching the essential cybersecurity requirements, or the core manufacturer obligations on product security and reporting, can reach up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher. Specified importer and distributor obligations, and certain conformity-assessment, declaration-of-conformity, and CE-marking breaches, may be subject to maximum administrative fines of up to 10 million euros or 2%.

Supplying incorrect, incomplete, or misleading information to notified bodies or authorities can reach up to 5 million euros or 1%, with the exact tier depending on the specific provision breached.

Two points make this more than theoretical. These are maximum levels: Member States establish the applicable penalty rules and enforcement arrangements, which must be effective, proportionate, and dissuasive, and the fine in any case is set on the facts.

And the financial penalty is not the only consequence. Because the figures are calculated on worldwide turnover, the percentage can exceed the fixed cap for a large group, and market surveillance authorities can also order corrective action, restrict a product’s availability, or force it off the EU market.

For an importer, a failure can mean both a fine and the loss of the market the shipment was headed for. The wider enforcement climate for regulated imports is covered in our analysis of the 2026 customs audit landscape, and the broader pattern of EU rules shifting cost and liability onto the importer runs through measures such as the EU Carbon Border Adjustment Mechanism.

The Roles, Side by Side

RoleMain CRA or customs function
ManufacturerDesigns the product, meets the essential requirements, completes technical documentation, and issues the EU declaration of conformity
CRA importerThe EU-established operator that verifies conformity evidence before placing a non-EU product on the market, and takes required corrective action
Customs importer of recordHandles the customs entry, classification, valuation, duties, and customs obligations
DistributorChecks the required markings and documents are present before making the product available
Customs brokerFiles the customs entry as an authorised agent where permitted; does not automatically become the CRA importer or customs importer of record
One organisation may hold more than one role, but each role’s obligations arise separately.

On many shipments the same organisation ends up carrying the customs and the CRA importer roles together, which is exactly why the pre-shipment process should cover customs and product compliance in one workflow rather than in separate silos.

A freight forwarder moves the goods and a customs broker can file the entry, but neither automatically takes on either accountable role.

If a non-EU business places covered products on the EU market, it must identify the EU-established economic operator responsible for the CRA importer role. That party may or may not be the same entity as the customs importer of record.

Carra Globe can coordinate this through its importer of record services, and the distinction from the parties that merely move or file goods is set out in our guide on the importer of record versus the customs broker. For high-value connected infrastructure, our IOR for AI servers and GPU clusters and our IOR for data centre equipment show how the same discipline applies to data centre deployments.

How to Prepare Now

  • Confirm your role for each product line, importer, distributor, or, if you rebrand or substantially modify, manufacturer, because the obligations and penalty tier follow the role.
  • Map which products are in scope as products with digital elements, checking the CRA definition, exclusions, and any sector-specific EU legislation that also applies.
  • Determine whether each product is a standard product with digital elements, an important product with digital elements, or a critical product with digital elements, because the category can affect the conformity-assessment route and whether a notified body is required.
  • Build a supplier-evidence process to obtain the conformity assessment, technical documentation, EU declaration of conformity, and CE marking from manufacturers before shipment.
  • Set up document retention for the EU declaration of conformity and supporting records for at least 10 years after the product is placed on the market, or for the support period, whichever is longer.
  • Establish a process for escalating vulnerabilities to the manufacturer and, where risk is significant, to market surveillance authorities.
  • Align your customs and product-compliance checks into one pre-shipment workflow, rather than treating clearance and conformity as separate steps.

How Carra Globe Helps

Carra Globe specialises in the international movement and customs compliance of high-value and regulated technology hardware, the connected servers, networking equipment, and devices most affected by this regulation. We help on three fronts: the customs side, HS classification, duty, and the customs entry; the CRA importer side, confirming the economic-operator role and checking that the manufacturer’s required conformity evidence has been provided; and escalation, identifying missing conformity documentation and coordinating with the manufacturer or a compliance specialist where technical assessment is required.

We act as your importer of record across 175+ countries. Requirements vary by product and role, and the regulation’s detail continues to develop, so we confirm the current position for your specific case before shipment.

Placing connected hardware on the EU market? Tell us the products, the origin, and the destination, and we will map the customs and compliance path and act as your importer of record. Get a compliance quote →

Importer of Record · 175+ countries

Two gates into the EU: customs, and cybersecurity conformity. We help you clear both.

Carra Globe acts as your importer of record, classifies the hardware, and checks that the product-compliance documentation a connected product needs has been provided, so your EU market entry is mapped as one process. Explore how we help:

Free tools:  HS Code Finder|Volumetric Weight Calculator|Pallet Calculator

Placing connected hardware on the EU market? Tell us the products, origin, and destination, and we will map the path.

Get a compliance quote

Frequently Asked Questions

What is the EU Cyber Resilience Act?

It is Regulation (EU) 2024/2847, the first EU-wide law setting mandatory cybersecurity requirements for products with digital elements, covering manufacturers, importers, and distributors placing covered hardware or software on the EU market.

Compliance is demonstrated through a conformity assessment, an EU declaration of conformity, and CE marking.

Is the CRA importer the same as the customs importer of record?

Not necessarily. The CRA importer is the EU-established operator that places a covered non-EU product on the market and verifies its conformity evidence. The customs importer of record handles the customs entry.

The roles arise from different legal frameworks, so neither should be assumed from the other.

When does the Cyber Resilience Act apply?

It entered into force on 10 December 2024 and applies in phases. Manufacturer reporting obligations begin on 11 September 2026, and the main obligations generally apply from 11 December 2027, subject to transitional rules.

Conformity assessment body rules began applying on 11 June 2026, so the framework is being built now.

Does the CRA apply to servers and networking equipment?

It can. Servers, networking equipment, and other connected hardware may fall within the CRA where they meet the definition of a product with digital elements and no exclusion applies.

The CRA does not apply simply because a product is electronic. The product category, remote-processing function, component status, intended use, and sector-specific legislation must be assessed for each product line.

Does the CRA apply when importing hardware from China?

Yes, if the covered product is placed on the EU market, the CRA can apply regardless of where the manufacturer is established. The EU importer has its own duties under Article 19.

The non-EU manufacturer must meet the applicable CRA requirements for its covered products to be lawfully placed on the EU market, while the EU-established importer carries its own Article 19 obligations.

What are the penalties for importers?

Specified breaches of importer and distributor obligations can reach up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. These are maximum levels; Member States set the enforcement rules.

Breaches of the essential requirements or core manufacturer duties sit in a higher tier of up to 15 million euros or 2.5%.

What must manufacturers report from 11 September 2026?

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting in-scope products through the EU single reporting platform, on the applicable timelines. This extends to products already on the market.

Importers do not generally file the manufacturer’s Article 14 report, but they should have an escalation process for anything they learn.

Is the CRA a customs or a tariff rule?

No. It is a product-compliance regulation, separate from customs and duty. Clearing customs does not make a product sellable in the EU, the CRA adds cybersecurity to the market-access conditions a connected product must meet.

Customs classification and CRA conformity are parallel checks that both have to be satisfied.

Sources and Verification

  • Regulation (EU) 2024/2847, the Cyber Resilience Act: the primary law, including Article 19 (importer obligations), Article 64 (penalties), and Article 69 and Article 71 (transitional provisions and application dates). Available via EUR-Lex.
  • European Commission, Cyber Resilience Act policy pages: timeline, CE marking, implementation milestones, and the 27 July 2026 guidance on scope, substantial modification, support periods, reporting, and risk assessment.
  • Manufacturer vulnerability and incident reporting from 11 September 2026, through the single reporting platform: European Commission CRA reporting obligations and ENISA.
  • Product category, notified-body, and transitional detail: verify the current position against the Official Journal and Commission guidance, as requirements continue to be defined.

Disclaimer: This guide is for informational purposes only and does not constitute legal, customs, or cybersecurity-compliance advice, and Carra Globe does not act as a conformity assessment body. The Cyber Resilience Act is being implemented in phases and its detailed requirements continue to be defined, so some specifics may change after publication. European Commission guidance is non-binding and should be read alongside the regulation. Obligations depend on the product, its configuration, and your role in the supply chain. Always verify the current requirements against the regulation and European Commission guidance, or with qualified counsel, before placing products on the EU market.

Facebook
Twitter
LinkedIn
WhatsApp
Email

Request a Quote