Impact of the EU CRA Core Reporting Obligations on Importers
The EU Cyber Resilience Act (CRA) officially entered into force on December 10, 2024. Its core vulnerability and security incident mandatory reporting obligations took effect on September 11, 2026, while all core compliance obligations will be fully enforced starting December 11, 2027.
For importers, the CRA positions them as "gatekeepers" of the EU market, bearing market-entry verification responsibilities and joint liability — they can no longer act merely as "trade intermediaries." Below are the core obligations and potential impacts importers need to be aware of:
Core Obligations for Importers
Pre-Market Verification (Gatekeeping): Before placing products on the EU market, importers must ensure that the manufacturer has completed the conformity assessment, that the product bears the CE marking, and that the necessary Declaration of Conformity (DoC) and technical documentation are in place. Non-compliant products must not be placed on the market.
Information Disclosure & Labeling: Importers must indicate their name, registered trade name or trademark, postal address, and email address on the product's packaging or in accompanying documents, in a language easily understood by users and market surveillance authorities.
Document Retention: A copy of the EU Declaration of Conformity (DoC) must be retained for ten years after the product is placed on the market, ready for inspection by market surveillance authorities at any time.
Storage & Transport Security: Ensure that storage and transport conditions during the importer's period of responsibility do not compromise the product's compliance with CRA requirements.
Risk Response & Cooperation: If a product is found to be non-compliant or poses vulnerability/security risks, importers must immediately take corrective actions (such as withdrawal or recall) and notify both the manufacturer and market surveillance authorities. They must also cooperate with regulatory investigations.
Role Transformation Risk: If an importer makes substantial modifications to a product, or sells it under their own name/trademark (private labeling), they will be treated as the manufacturer and assume all core manufacturer responsibilities (such as secure design, vulnerability notification, conformity assessment, etc.).
Learn about Senghor Logistics services: sales12@senghorlogistics.com
Penalties for Non-Compliance & Potential Impacts
Substantial Fines: Violations of importer obligations (e.g., failure to verify CE marking, failure to retain documents) can result in fines of up to €10 million or 2% of the company's global annual turnover from the previous financial year, whichever is higher.
Product Removal & Recall: Regulatory authorities have the power to directly order non-compliant products to be withdrawn from the market, prohibited from being placed on the market, or mandatorily recalled.
Supply Chain Pressure Transmission: An importer's compliance responsibilities are directly dependent on upstream manufacturers. This means importers must establish strict supplier evaluation and management processes, requiring Chinese suppliers to provide a complete CRA compliance documentation package (including Software Bill of Materials [SBOM], risk assessment reports, vulnerability handling procedures, etc.), or they will face significant compliance risks themselves.
In short, the CRA extends compliance pressure from manufacturers to the entire supply chain. As an importer, you can no longer passively receive goods — you must proactively engage in upstream supply chain compliance management to ensure that every batch of digital products entering the EU has complete CRA compliance qualifications.
Contact our logistics expert about shipping from China!
Send your inquiry: sales12@senghorlogistics.com
Post time: Sep-23-2026


