You make a radio module, a sensor board or a small gateway. A bigger company, the OEM, builds it into its own product and sells that product in the EU. So the EU Cyber Resilience Act (CRA) is their problem, not yours. Right?
Often, it is not. The CRA does not look at how big you are, or at who sells the final product. It looks at whose name is on the product. This note shows what that means for component suppliers, with the exact articles, and what to do next.
The short answer
If you sell your module under your own name or trademark, the CRA treats you as a manufacturer. You then carry the manufacturer duties for that module. This includes the reporting clock for flaws that attackers use.
Your customer is a manufacturer too, for its own product. Both are true at the same time. One does not cancel the other.
What the Cyber Resilience Act says about components
Three sentences in the regulation do most of the work.
Article 3(1)
‘product with digital elements’ means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.
So a module that you sell on its own is a product under the CRA. It is not only a part of someone else’s product.
Article 3(13)
‘manufacturer’ means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge.
The test is your name or trademark on the module. Your size does not change it, and the size of your customer does not change it.
Article 13(5)
Manufacturers shall exercise due diligence when integrating components sourced from third parties so that those components do not compromise the cybersecurity of the product with digital elements.
This one is your customer’s duty. It is the reason their questionnaires reach your inbox.
Module maker, OEM or distributor: who is the manufacturer?
Case 1
You sell the module under your own name
In a catalogue, with your datasheet, to several customers.
Manufacturer of the moduleYou (Article 3(13))
Articles 13 and 14 apply to you. Your customers will also ask you for evidence.
Case 2
You make a custom part under the customer's name
Made to your customer's design. Only your customer's name is on it.
Manufacturer of the moduleUsually your customer (Article 3(13))
Your customer will still ask you for evidence, because of its due diligence duty. Check what your contract says.
Case 3
A distributor sells your module under its own name
An importer or distributor puts its own name or trademark on it.
Manufacturer of the moduleThe distributor or importer (Article 21)
It carries the manufacturer duties for that product, and it will ask you for the evidence.
If your case sits between these three, ask your lawyer. Small details in a contract or on a label can change the answer.
CRA deadlines for module makers
Since 11 September 2026, the reporting duties of Article 14 apply (Article 71(2)). They also cover modules that you already sell (Article 69(3)). When you become aware of an actively exploited vulnerability in your module, you send:
- an early warning within 24 hours;
- a vulnerability notification within 72 hours;
- a final report no later than 14 days after a fix or a mitigation is available.
You send these through the EU single reporting platform (Article 14(1) and (2)).
From 11 December 2027, the other duties apply to modules that you place on the market from that date (Article 71(2)). They include the security requirements in Annex I, for example an SBOM that covers at least the top-level dependencies (Annex I, Part II, point 1). A module that you placed on the market before that date needs them only after a substantial modification (Article 69(2)).
A note for small companies: micro and small enterprises cannot get a fine for missing the 24-hour early warning deadline (Article 64(10)). The duty to report stays.
What your OEM customers will ask
Because of Article 13(5), expect questions like these:
- an SBOM for each module version;
- how you handle vulnerability reports, and who your security contact is;
- how long you give security updates for each version;
- how fast you tell them about a flaw that affects them.
It also works the other way. When your customer finds a vulnerability in your module, the CRA tells it to report the flaw to you (Article 13(6)). So a person at your company must read those reports.
What to do this month
- List every module that carries your name or trademark, with its versions.
- Name a security contact, and make sure a person reads it every working day. A report that sits unread for a week is a bad start, and an authority may ask why nobody read it.
- Build an SBOM for each version that you still sell.
- Prepare the 24-hour early warning before you need it: who decides, who files, and a draft that is ready to fill in.
Where Relvault fits
This is the work that Relvault prepares for small device makers: the SBOMs, the daily check against exploited-vulnerability lists, the report drafts and the answers to customer questionnaires. Your engineers check each item, and your company signs and files. See how it works and the prices.
Next, read The email nobody read for a day: why your security inbox decides how much of the 24 hours is left.
Common questions
Does the CRA apply to components and modules?
Yes, when they are placed on the market separately. The definition of a product with digital elements includes “software or hardware components being placed on the market separately” (Article 3(1)).
Is a supplier a manufacturer under the CRA?
A supplier that markets a component under its own name or trademark is the manufacturer of that component (Article 3(13)). A supplier that makes a part only under its customer’s name is usually not.
Do the reporting duties cover modules that are already on the market?
Yes. Since 11 September 2026, Article 14 applies to all products in scope, also to products placed on the market before 11 December 2027 (Article 69(3) and Article 71(2)).
Does the OEM still need to check my module?
Yes. The OEM must use due diligence when it integrates components from third parties (Article 13(5)). That is why its questionnaires reach you.
Source
Regulation (EU) 2024/2847, the Cyber Resilience Act, official text on EUR-Lex. This note uses Articles 3(1), 3(13), 13(5), 13(6), 14(1) and (2), 21, 64(10), 69(2) and (3), and 71(2), and Annex I, Part II, point 1.