Book a call

All notes

We only make a module. Is the OEM responsible under the CRA?

Sell a module under your own name? The EU Cyber Resilience Act then treats you as a manufacturer, with your own reporting duty. Plain words, exact articles.

6 min read

You make a radio module, a sensor board or a small gateway. A bigger company, the OEM, builds it into its own product and sells that product in the EU. So the EU Cyber Resilience Act (CRA) is their problem, not yours. Right?

Often, it is not. The CRA does not look at how big you are, or at who sells the final product. It looks at whose name is on the product. This note shows what that means for component suppliers, with the exact articles, and what to do next.

A beaver engineer packs small circuit modules into boxes at a workbench. Every box has the same red mark.
Bina's team makes radio modules. Their mark is on every box.

The short answer

If you sell your module under your own name or trademark, the CRA treats you as a manufacturer. You then carry the manufacturer duties for that module. This includes the reporting clock for flaws that attackers use.

Your customer is a manufacturer too, for its own product. Both are true at the same time. One does not cancel the other.

What the Cyber Resilience Act says about components

Three sentences in the regulation do most of the work.

Article 3(1)

‘product with digital elements’ means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.

So a module that you sell on its own is a product under the CRA. It is not only a part of someone else’s product.

Article 3(13)

‘manufacturer’ means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge.

The test is your name or trademark on the module. Your size does not change it, and the size of your customer does not change it.

Article 13(5)

Manufacturers shall exercise due diligence when integrating components sourced from third parties so that those components do not compromise the cybersecurity of the product with digital elements.

This one is your customer’s duty. It is the reason their questionnaires reach your inbox.

Kavach the pangolin holds up one box and points at the red mark on it. The beaver looks at the mark, surprised.
Kavach points at the mark. The name on the product decides who the manufacturer is.

Module maker, OEM or distributor: who is the manufacturer?

Case 1

You sell the module under your own name

In a catalogue, with your datasheet, to several customers.

Manufacturer of the moduleYou (Article 3(13))

Articles 13 and 14 apply to you. Your customers will also ask you for evidence.

Case 2

You make a custom part under the customer's name

Made to your customer's design. Only your customer's name is on it.

Manufacturer of the moduleUsually your customer (Article 3(13))

Your customer will still ask you for evidence, because of its due diligence duty. Check what your contract says.

Case 3

A distributor sells your module under its own name

An importer or distributor puts its own name or trademark on it.

Manufacturer of the moduleThe distributor or importer (Article 21)

It carries the manufacturer duties for that product, and it will ask you for the evidence.

If your case sits between these three, ask your lawyer. Small details in a contract or on a label can change the answer.

CRA deadlines for module makers

Since 11 September 2026, the reporting duties of Article 14 apply (Article 71(2)). They also cover modules that you already sell (Article 69(3)). When you become aware of an actively exploited vulnerability in your module, you send:

  1. an early warning within 24 hours;
  2. a vulnerability notification within 72 hours;
  3. a final report no later than 14 days after a fix or a mitigation is available.

You send these through the EU single reporting platform (Article 14(1) and (2)).

From 11 December 2027, the other duties apply to modules that you place on the market from that date (Article 71(2)). They include the security requirements in Annex I, for example an SBOM that covers at least the top-level dependencies (Annex I, Part II, point 1). A module that you placed on the market before that date needs them only after a substantial modification (Article 69(2)).

A note for small companies: micro and small enterprises cannot get a fine for missing the 24-hour early warning deadline (Article 64(10)). The duty to report stays.

A large friendly elephant leans through a doorway and hands down a very long paper questionnaire. It unrolls across the beaver's desk. Kavach stands next to the beaver.
Bina's biggest customer must check every part it builds in. So its questions come down the chain.

What your OEM customers will ask

Because of Article 13(5), expect questions like these:

  • an SBOM for each module version;
  • how you handle vulnerability reports, and who your security contact is;
  • how long you give security updates for each version;
  • how fast you tell them about a flaw that affects them.

It also works the other way. When your customer finds a vulnerability in your module, the CRA tells it to report the flaw to you (Article 13(6)). So a person at your company must read those reports.

What to do this month

  1. List every module that carries your name or trademark, with its versions.
  2. Name a security contact, and make sure a person reads it every working day. A report that sits unread for a week is a bad start, and an authority may ask why nobody read it.
  3. Build an SBOM for each version that you still sell.
  4. Prepare the 24-hour early warning before you need it: who decides, who files, and a draft that is ready to fill in.
Kavach and the beaver sit calmly at a tidy desk with stacked folders, a long list pinned up and a small red alarm clock. The elephant raises its trunk in the doorway.
With a parts list for each version and a report plan ready, the 24 hours go into decisions, not paperwork.

Where Relvault fits

This is the work that Relvault prepares for small device makers: the SBOMs, the daily check against exploited-vulnerability lists, the report drafts and the answers to customer questionnaires. Your engineers check each item, and your company signs and files. See how it works and the prices.

Next, read The email nobody read for a day: why your security inbox decides how much of the 24 hours is left.

Common questions

Does the CRA apply to components and modules?

Yes, when they are placed on the market separately. The definition of a product with digital elements includes “software or hardware components being placed on the market separately” (Article 3(1)).

Is a supplier a manufacturer under the CRA?

A supplier that markets a component under its own name or trademark is the manufacturer of that component (Article 3(13)). A supplier that makes a part only under its customer’s name is usually not.

Do the reporting duties cover modules that are already on the market?

Yes. Since 11 September 2026, Article 14 applies to all products in scope, also to products placed on the market before 11 December 2027 (Article 69(3) and Article 71(2)).

Does the OEM still need to check my module?

Yes. The OEM must use due diligence when it integrates components from third parties (Article 13(5)). That is why its questionnaires reach you.

Source

Regulation (EU) 2024/2847, the Cyber Resilience Act, official text on EUR-Lex. This note uses Articles 3(1), 3(13), 13(5), 13(6), 14(1) and (2), 21, 64(10), 69(2) and (3), and 71(2), and Annex I, Part II, point 1.

This note explains the law in plain words. It is not legal advice. For your own case, ask your lawyer.