If you import, distribute or rebrand
Short answer. If you import or distribute somebody else's product, your duties are verification and reporting, not documentation. You check that the manufacturer did its job, you add your own contact details, you keep a copy of the declaration for ten years, and you speak up when something is wrong.
But two things make you the manufacturer with the full set of obligations:
- Selling it under your own name or trade mark.
- Substantially modifying it.
The first is the one that catches people, because it is a commercial decision that nobody frames as a compliance one.
This page is for the part of the supply chain that did not build the thing. It is a genuinely lighter regime than the manufacturer's — and the boundary is sharp rather than gradual, which is what makes it worth knowing precisely.
What an importer must do
An importer is the party that places a product from outside the Union on the EU market. Article 19 gives it a checking duty, an identification duty, a reporting duty and a retention duty.
Before placing it on the market — check four things
| Check | What it means in practice |
|---|---|
| The manufacturer carried out the appropriate conformity assessment procedures | Ask which route was used. If the product is Annex III Class II or Annex IV, self-assessment is not available and a certificate should exist |
| The manufacturer drew up the technical documentation | You do not have to hold it, but you do have to establish that it exists. Ask, in writing |
| The product bears the CE marking and is accompanied by the EU declaration of conformity | Get the declaration. You will need a copy for ten years anyway, so get it at the start of the relationship rather than during an investigation |
| The manufacturer complied with the requirements on product identification and contact details | Type, batch or serial number on the product; the manufacturer's name and address on the product or its packaging |
Add your own identification
Your name, registered trade name or registered trade mark, and a postal address plus an email address or other digital contact, on the product, its packaging or the accompanying documentation — in a language easily understood by users and market surveillance authorities.
If something looks wrong
Where an importer considers or has reason to believe the product does not conform, it must not place it on the market until it has been brought into conformity. Where the product presents a significant cybersecurity risk, the importer must inform the manufacturer and the market surveillance authorities.
Keep the declaration for ten years
An importer must keep a copy of the EU declaration of conformity at the disposal of market surveillance authorities for at least ten years after the product has been placed on the market, or for the support period, whichever is longer.
This is an independent duty. It is not satisfied by the manufacturer having its own copy, and it does not end if the supplier relationship does. Two practical consequences: get the declaration at the start, and store it where it will survive a decade of reorganisations — alongside the product and version it belongs to, never overwritten when a new version arrives.
What a distributor must do
A distributor is anyone else in the supply chain who makes the product available on the market. Article 20's duties are lighter again, and the interesting one is the last.
- Act with due care. Before making a product available, verify that it bears the CE marking and that the manufacturer and the importer have met their obligations under Articles 13 and 19.
- Do not make it available if you suspect non-conformity, until it has been brought into conformity — and where there is a significant cybersecurity risk, inform the manufacturer and the market surveillance authorities.
- Speak up about vulnerabilities. On becoming aware of a vulnerability in a product you distribute, inform the manufacturer without undue delay, and ensure corrective measures are taken — which can extend to bringing the product into conformity, withdrawing it or recalling it. Where there is a significant cybersecurity risk, immediately inform the market surveillance authorities, with details of the non-compliance and of the corrective measures taken.
- Cooperate on request, providing the documentation needed to demonstrate conformity.
The vulnerability duty is the one distributors underestimate. It means a distributor cannot treat a security report from a customer as somebody else's problem. Passing it to the manufacturer is a legal duty with a "without undue delay" clock on it, and where the risk is significant there is a separate, immediate duty to tell the authorities. That needs a named person and an inbox that is actually read.
The line: when you become the manufacturer
Article 21 is short and it is the most consequential provision on this page. An importer or distributor is subject to the manufacturer's obligations in Articles 13 and 14 where it:
- places a product with digital elements on the market under its own name or trade mark; or
- carries out a substantial modification of a product with digital elements already placed on the market.
Cross the line and the whole apparatus arrives at once: the essential requirements in Annex I, the risk assessment, the Annex VII technical documentation, the Annex II user information, the Annex V declaration of conformity signed under your sole responsibility, the vulnerability-handling process, the support-period decision, the ten-year retention duties and the Article 14 reporting duties.
| Importer or distributor | Once Article 21 bites | |
|---|---|---|
| Technical documentation | Verify it exists | Draw it up yourself |
| Declaration of conformity | Keep a copy for ten years | Sign your own, under sole responsibility |
| Essential requirements (Annex I) | Not yours | Yours |
| Risk assessment | Not yours | Yours |
| Support period | Not yours | You decide it, and you honour it |
| Vulnerability handling | Report upstream | Run the process: remediate, disclose, ship free updates |
| Article 14 reporting | Not yours | Yours, on 24 and 72-hour clocks |
| Penalty exposure | The €10m tier | The €15m tier |
Rebranding, in practice
The white-label case is worth spelling out, because it is a normal commercial arrangement that carries an abnormal compliance consequence.
You find a manufacturer in another market, agree a private-label deal, put your brand on the product and sell it as yours. Commercially that is the point of the arrangement: your customers buy from you, and trust your name. Legally, Article 21 makes you the manufacturer of a product you did not design and cannot see inside.
That produces a specific and uncomfortable position. You now owe a declaration that the product meets the essential requirements, signed under your sole responsibility, and a technical file describing design decisions somebody else made. You owe a support period you cannot unilaterally honour, because the security updates come from your supplier. You owe Article 14 reports about vulnerabilities you may learn of last.
None of that is a reason not to do it. It is a reason for the contract to do work it probably does not do today:
- A right to the technical documentation, in a form you can hand to an authority, kept current.
- A committed support period from the supplier at least as long as the one you declare — and a declared support period no longer than theirs.
- A notification obligation flowing to you, fast enough that you can meet a 24-hour clock. Your duty to report starts when you become aware; a supplier who tells you a week later has not saved you.
- A commitment to free security updates for the whole period, since Annex I Part II requires them to be provided without charge.
- Access to the SBOM, and a right to pass it to a market surveillance authority on a reasoned request.
- What happens if the supplier stops. Your obligations do not.
The cheapest time to negotiate all of that is before the first order.
Substantial modification, and who it catches
The second trigger is modification, and it reaches further than the supply chain. Article 22 provides that any other person — not the manufacturer, importer or distributor — who carries out a substantial modification of a product with digital elements and makes it available on the market is considered to be a manufacturer, and must comply with Articles 13 and 14 either for the modified part or, where the modification affects the product's cybersecurity as a whole, for the whole product.
So the systems integrator who reflashes firmware, the reseller who installs a custom build, and the service company that modifies a device before deploying it are all inside this provision if the modification is substantial and the product then goes to market.
But we are not going to tell you where the line is, because nobody has drawn it yet. If your business model involves modifying other people's products before selling them, this is a question worth real advice rather than a web page's guess, and it is worth asking before the Commission's guidance settles it in a way you have not planned for.
What it costs to get this wrong
The penalty tiers follow the role, which is another reason the line matters.
- The importer and distributor obligations in Articles 19 and 20 sit in the €10m or 2% tier, alongside the other supply-chain and CE-marking duties.
- The manufacturer obligations in Articles 13 and 14, and the Annex I essential requirements, sit in the €15m or 2.5% tier — the top one.
- Giving an authority incorrect, incomplete or misleading information in reply to a request is a separate offence in its own right, at €5m or 1%. For an importer answering questions about a product it did not build, this is a real risk: answer from the documents, not from memory or from what the supplier told you on the phone.
The three tiers in full, and the exemption small manufacturers keep missing.
What to actually do
- Work out which role you are in, per product, and write it down. A company can be an importer for one line, a distributor for another and a manufacturer for a third.
- If you sell anything under your own brand, treat yourself as its manufacturer and read the manufacturer's obligations. Do not wait for someone to tell you.
- Collect the declaration of conformity for every product you import, now, and file it by product and version. Ten years starts from placing on the market, not from when you get round to it.
- Put the checking duty into your onboarding process for a new supplier, as four questions with written answers.
- Name the person who receives vulnerability reports and give them a route to the manufacturer that works in hours rather than weeks.
- Fix the contracts using the list above, starting with the suppliers whose products you rebrand.
An honest note on confidence, and it is lower than most pages on this site. Articles 19, 20, 21 and 22 were each read in a single reproduction rather than two, so the paragraph-level detail above — the four importer checks, the ten-year retention duty, the two Article 21 triggers and Article 22's split between the modified component and the whole product — should be confirmed against the text before you rely on it. The penalty-tier allocation is two-sourced. The contract checklist in the rebranding section is our own commercial advice, not a statement of law. And "substantial modification" is genuinely undefined, as set out above. Nothing here is legal advice.
If you rebrand, you are the manufacturer — and you need the whole file
Conformance House produces the technical documentation, the declaration of conformity and the user information for a product you sell under your own name, from one questionnaire, with every version dated and kept for the ten years the regulation requires.
Not sure which role you are in for a given product? The free check asks that question directly.