Skip to content
Law & compliance

Cyber Resilience Act: B2B Shop Duties From September

From 11 September 2026 the CRA reporting duty in Article 14 applies. Which duty starts when, who is a manufacturer and what must be visible in a B2B shop.

14 min read ComplianceIT-SicherheitProduktdaten

The Cyber Resilience Act bites for the first time on 11 September 2026 (Regulation 2024/2847) - but not in full. On that day Article 14 applies, the reporting duty of manufacturers for actively exploited vulnerabilities and for severe security incidents. The remaining catalogue of duties follows on 11 December 2027 (Regulation 2024/2847). Between the two lie 15 months in which many assortments carry on unchanged, while the question of who actually counts as a manufacturer has long since arisen. The occasion is real: in its reporting period the BSI counted an average of 119 (BSI) newly disclosed vulnerabilities worldwide per day, around 24 percent (BSI) more than in the previous period. Damage from cyber attacks in the German economy most recently stood at 202.4 billion euros (Bitkom); 34 percent (Bitkom) of the companies surveyed were hit by ransomware attacks. This article sorts out which CRA duty starts on which date, which role a B2B shop occupies, which articles in an assortment are products with digital elements at all, and which details therefore move into the product data - from the end date of the support period through the contact point for vulnerability reports to the EU declaration of conformity at the article.

Key takeaways

  • On 11 September 2026 only Article 14 applies - the reporting duty of manufacturers. Chapter IV on notified bodies already applied from 11 June 2026, and the entire remaining catalogue of duties follows on 11 December 2027 (Regulation 2024/2847).
  • A shop operator is not automatically a manufacturer. The regulation distinguishes manufacturers, importers and distributors with very different sets of duties. Anyone placing a product on the market under their own name or trademark is treated as a manufacturer under Article 21.
  • Under Article 13(8) the support period is at least five years, unless the product is in use for a shorter time. Its end date has to be easily accessible at the time of purchase - in a shop that means a dedicated product attribute, not a sentence in running text.
  • Annex II lists nine items that have to accompany the product: manufacturer contact details, contact point for vulnerabilities, intended purpose, EU declaration of conformity, end date of the support period and instructions. That is product data work, not a legal question.
  • Article 69(3) pulls the reporting duty forward: it also covers products placed on the market before 11 December 2027. The running assortment therefore does not fall into a grandfathering gap.

What actually applies on 11 September

The regulation sets out its own timetable in a single article. Article 71(2) says: the regulation shall apply from 11 December 2027, however Article 14 shall apply from 11 September 2026 and Chapter IV with Articles 35 to 51 from 11 June 2026 (Regulation 2024/2847). That leaves three dates side by side which are routinely mixed up in practice. Chapter IV concerns the notification of conformity assessment bodies; it prepares the system and addresses authorities and testing bodies, not your assortment. Article 14 concerns you directly if you are a manufacturer within the meaning of the regulation. Everything else - the essential cybersecurity requirements from Annex I, the CE marking, the technical documentation, the conformity assessment - takes effect only in December 2027.

Entry into force, by contrast, happened back on 10 December 2024 (European Commission). Entry into force and start of application are two different things: the text has been binding Union law since December 2024, but its duties take effect in stages. Anyone who reads "in force since 2024" and concludes that the requirements have long applied gets it wrong in both directions - treating duties as overdue that have not started, and overlooking the one that really does start in September.

Article 14 requires two reporting strands from the manufacturer. For an actively exploited vulnerability: an early warning within 24 hours (Regulation 2024/2847) of becoming aware, a vulnerability notification within 72 hours and a final report no later than 14 days after a corrective or mitigating measure has become available. For a severe security incident the same entry applies with 24 hours and 72 hours, with the final report following within one month. The report goes simultaneously to the CSIRT designated as coordinator and to ENISA, through a single reporting platform.

Three dates, three sets of duties

11 June 2026: Chapter IV, notification of conformity assessment bodies. 11 September 2026: Article 14, reporting obligations of manufacturers. 11 December 2027: the entire remaining catalogue of duties, including Annex I, CE marking and technical documentation. All three dates are set out in Article 71(2) (Regulation 2024/2847).

Manufacturer, importer, distributor: which one are you

The regulation addresses economic operators in clearly separated roles. Under Article 3 a distributor is a person in the supply chain who makes a product with digital elements available on the Union market without affecting its properties. An importer places a product on the Union market under the name or trademark of a person established outside the Union. A shop operator reselling branded goods from a European manufacturer is therefore a distributor - and thus affected neither by Annex I nor by Article 14. Whoever sources the same goods directly from a third country and puts them on the market here for the first time is an importer and carries a considerably larger set of duties (Regulation 2024/2847).

RoleCore duty before the saleWhen a vulnerability becomes knownRetention
Manufacturer (Articles 13, 14)Meet Annex I, risk assessment, technical documentation, CE marking, determine the support periodReport to CSIRT and ENISA after 24 and 72 hours, final report after 14 daysDocumentation and EU declaration of conformity for ten years or the support period
Importer (Article 19)Verify that the conformity assessment was carried out and that technical documentation, CE marking, declaration of conformity and Annex II information in an easily understood language are presentInform the manufacturer without delay, and the market surveillance authorities as well in case of significant riskKeep a copy of the EU declaration of conformity for ten years or the support period
Distributor (Article 20)Verify that the CE marking is present and that manufacturer and importer have met their marking and information dutiesInform the manufacturer without delay, and the market surveillance authorities as well in case of significant riskNo retention duty of its own, but information owed to market surveillance
Own brand or substantial modification (Articles 21, 22)Considered a manufacturer and subject to the duties of Articles 13 and 14Full reporting duty like a manufacturerAs for a manufacturer

The roles are not a matter of choice, they follow from the transaction. And they can coexist inside the same shop: a wholesaler may be a distributor for the majority of its articles, an importer for three imported product lines and a manufacturer for its own house brand. That is precisely why the role belongs at the article as a field rather than in a note. Whoever keeps it in the product data model can later filter which articles need which evidence - and can see straight away which part of the assortment is affected on 11 September 2026.

An own brand switches the role

Article 21 is the sentence that surprises most shops: an importer or distributor is considered a manufacturer and is subject to the duties of Articles 13 and 14 where it places a product on the market under its own name or trademark, or carries out a substantial modification of a product already placed on the market (Regulation 2024/2847). Private labels, relabelled sensors and self-configured bundles fall under this quickly.

Spotting products with digital elements in the assortment

The scope is broader than the term "cybersecurity" suggests. It covers hardware and software products whose intended use includes a direct or indirect data connection to a device or network. In a technical B2B assortment that means considerably more articles than the obvious ones: routers and switches of course, but also sensors with a radio module, operating panels, drive controllers, charging stations, scales with a network port, firmware downloads and the configuration software sitting next to the device in the catalogue. How closely this interlocks with other rulebooks is shown by the article on NIS2 and IT security in the B2B shop: there the subject is the security of the operator, here it is the security of the product.

  • Does the article have a network, Bluetooth, Wi-Fi, mobile or USB data connection in its intended operation?
  • Is software, firmware or an update offered as a separate article or as a download?
  • Do you sell the article under your own name, your own trademark or as a self-configured bundle?
  • Do you source the article directly from a manufacturer established outside the Union?
  • Does the article fall under Annex III as an important product or under Annex IV as a critical product?
  • Do you make changes to the article that touch its cybersecurity properties?

For radio equipment there is an additional back story that explains the timetable. Delegated Regulation (EU) 2022/30 puts the cybersecurity requirements of the Radio Equipment Directive into effect; its start of application was moved from 1 August 2024 to 1 August 2025 (Delegated Regulation 2023/2444) because the harmonised standards were not finished in time. Anyone carrying connected radio products has therefore been working under a cybersecurity regime since 2025 and gets no new subject with the CRA, but a wider circle. For the assortment analysis that means: classify first, prioritise second.

What has to appear on the product detail page

Annex II lists nine items that have to accompany a product with digital elements. Article 13(18) adds that this information has to be in a language easily understood by users and market surveillance authorities and has to remain available for at least ten years (Regulation 2024/2847) after the product was placed on the market - explicitly including information provided online. That turns the product detail page from a sales surface into a filing location with a retention period. How data sheets, certificates and downloads can be structured cleanly there is covered by the article on the B2B product detail page with data sheets.

Manufacturer identity

Name, registered trade name or trademark, postal address, email address or other digital contact route, and the website where one exists. In the shop a record at the manufacturer, not a text block per article.

Contact point for vulnerabilities

The single point to which vulnerabilities can be reported, together with where the coordinated disclosure policy can be found. A field of its own, because it is not the general service address.

Unique identification

Name, type and any further detail identifying the product unambiguously. In practice the manufacturer number, type designation and product line - fields that ought to exist in the shop anyway.

Intended purpose and security environment

What the product is intended for, in which security environment it is meant to run, which main functions and security properties it has - and which foreseeable misuse creates risk.

Address of the declaration of conformity

The internet address at which the EU declaration of conformity can be accessed. Maintained as a field at the article, not as a PDF attachment without versioning.

Type of support and end date

The type of technical security support offered and the end date of the support period, up to which users can expect vulnerability handling and security updates.

Alongside these six, Annex II also holds the detailed instructions on commissioning, update installation, secure decommissioning and data deletion, plus the note on where the software bill of materials can be accessed if the manufacturer provides one. All nine items are structured data, not running text. They belong in a product information system and are pushed from there into the shop - a route described in the article on product data and data quality in the PIM. Written into description texts instead, they are neither filterable nor verifiable nor reliably updatable.

The core question for your data model

Can you answer today, by filter, which articles in your assortment are products with digital elements, in which role you place them on the market and when their support period ends? If yes, CRA preparation is mostly editorial work. If no, it is a data model project first.

The support period as a product attribute

Article 13(8) requires the manufacturer to determine the support period so that it reflects the length of time the product is expected to be in use, naming reasonable user expectations, the type of product and relevant Union law as criteria. Independently of that it runs for at least five years (Regulation 2024/2847); where the product is in use for less time, it matches the expected time in use. For industrial control systems, network technology and operating systems the regulation explicitly assumes longer periods. Under paragraph 9, security updates have to remain available for at least ten years after they were issued, or for the remaining support period, whichever is longer.

Paragraph 19 is the sentence with the most immediate effect on a shop: the end date has to be stated clearly and understandably in an easily accessible manner at the time of purchase, at least with the month and the year. "At the time of purchase" in online trade means: visible before the order is submitted, so on the product detail page and sensibly in the basket too. An end date that only appears in the enclosed manual does not meet this. Technically this is a date field at the article - comparable to the data points required by the digital product passport under ESPR, and with the same consequence: a field maintained only in part creates gaps that get noticed.

  • A date field instead of free text: month and year as a structured value, so that expiring articles can be filtered, sorted and monitored in stock.
  • Derivation per variant: different product lines from the same article master can carry different end dates; the field belongs at the level where the firmware differs.
  • Check the batch reference: where production lots carry different firmware states, linking to batches and serial numbers helps assign the correct end date.
  • Display in the ordering process: visible on the product detail page, repeated in the basket, carried into the order confirmation and the invoice.
  • Expiry warning in the catalogue: articles whose support period ends within the next twelve months need a marker - for purchasing as much as for the customer.

Evidence towards business customers

The second driver is not the authority but your customers' purchasing departments. Anyone falling under NIS2 themselves or running an information security management system asks for supplier evidence - and the fastest route there is a shop that supplies the documents without a query. B2B internet trade by manufacturers and wholesalers in Germany most recently stood at 509 billion euros (ECC KÖLN) with growth of 7 percent (ECC KÖLN); the share of procurement that runs without personal contact keeps growing. The more of it happens self-service, the more the data situation in the shop decides whether an article makes the shortlist at all.

In practice that means: the EU declaration of conformity, safety information and support details belong in an area that logged-in customers can reach permanently - months after the order too, when the audit comes round. A customer portal with self-service is the fitting place, because it connects order history and documents. Anyone who already has regulatory checks in the ordering process knows the pattern from sanctions screening in export control: the evidence is worthless unless it is stored with the transaction. That the need is real is shown by the damage figures: 70 percent (Bitkom) of the total damage to German companies is now attributed to cyber attacks.

Evidence at the transaction, not at the article alone

For every order line, store which version of the declaration of conformity and which end date of the support period applied at the time of the order. Article master data changes; an audit asks about the state back then. This snapshot costs one field per line and saves the reconstruction later.

Reporting under Article 14: what concerns the shop

The manufacturer reports, not the shop. If you are a distributor, your duty ends at Article 20(4): as soon as you learn of a vulnerability you inform the manufacturer without delay; where the product presents a significant cybersecurity risk, you also inform the market surveillance authorities of the member states in which you made it available (Regulation 2024/2847). For importers the same rule applies in substance in Article 19(5). That sounds like little, but it has a precondition that sits in the shop: you have to know who your customers are for the affected article and through which route you receive that information at all. An unattended catch-all address does not cover it.

Article 69(2) exempts products placed on the market before 11 December 2027 from the requirements in principle - unless they undergo a substantial modification after that date. Paragraph 3 makes an important exception to this: the duties of Article 14 apply to all products within the scope that were placed on the market before that date (Regulation 2024/2847). For a warehouse full of long-lived technology this is the central sentence. Anyone tracking their software states systematically has it easier; the mindset matches the one described in the article on the maintenance strategy for Shopware 6.7 for your own platform - applied to the assortment instead of the shop.

Penalties and market surveillance

Article 64 grades the upper limits for administrative fines by the type of infringement. The member states lay down the specific rules; the regulation sets the ceilings. Paragraph 10 is worth noting: by way of derogation from paragraphs 3 to 9, the fines set out there do not apply to manufacturers that qualify as micro or small enterprises as far as the early warning deadline under Article 14(2)(a) or (4)(a) is concerned - that is, the 24 hours - and equally do not apply to open-source software stewards for any infringement of the regulation (Regulation 2024/2847).

InfringementAbsolute ceilingTurnover-based ceiling
Essential requirements in Annex I and obligations under Articles 13 and 1415 000 000 euros2.5 percent of worldwide annual turnover for the preceding financial year
Obligations under Articles 18 to 23 and 28, individual paragraphs of Articles 30 to 33, and Articles 39, 41, 47, 49 and 5310 000 000 euros2 percent of worldwide annual turnover for the preceding financial year
Incorrect, incomplete or misleading information supplied to bodies and authorities5 000 000 euros1 percent of worldwide annual turnover for the preceding financial year

The higher amount applies in each case. For a distributor the risk therefore does not sit with the product-related requirements but with the information and verification duties of Articles 18 to 23 - that is, exactly with the fields maintained in the shop. Under Article 52(16) the market surveillance authorities also monitor how manufacturers applied the criteria for determining the support period. Handling this kind of requirement is familiar from other rulebooks: with accessibility under the BFSG too, what matters is less the individual entry than whether it is generated systematically or by hand.

What gets prepared in the shop now

Up to 11 September 2026 the task is manageable, up to December 2027 it no longer is. The sequence follows from the dependencies: without classifying the assortment no role can be assigned, without a role no set of duties, without a set of duties no field requirement. Given an average of 119 (BSI) new vulnerabilities per day, the reporting chain is hardly a theoretical case.

  1. Classify the assortment: record per article whether it is a product with digital elements, and whether Annex III or Annex IV applies.
  2. Determine the role per article: manufacturer, importer or distributor - with particular attention to private labels and self-configured bundles under Article 21.
  3. Create the fields: end date of the support period, contact point for vulnerabilities, address of the EU declaration of conformity, language versions of the Annex II information.
  4. Set up the reporting route: a named address for incoming vulnerability reports, a defined route to the manufacturer and an assignment of who responds internally within 24 hours.
  5. Request supplier data: ask the upstream supplier for the Annex II information in a structured form instead of transcribing it from PDF files later - the same discipline a print catalogue from shop data requires.
  6. Prepare customer communication: anyone selling services and maintenance contracts in the shop can describe support periods and security updates as part of the service promise.

On 27 July 2026 the Commission published practical guidance intended to help manufacturers, developers and businesses of all sizes meet their obligations (European Commission). For the shop side the guidance changes nothing about the basic task: the details the CRA asks for are product data. They originate in purchasing, live in the product information system and become visible in the shop. Whoever builds this chain cleanly once also serves the next rulebooks with it - and can move conversations about evidence duties that today still happen at the trade fair stand into the shop, as the article on trade show leads in the B2B shop describes for sales.

Sources and studies

This article draws on data from [Regulation (EU) 2024/2847], [European Commission], [BSI], [Bitkom], [Delegated Regulation (EU) 2023/2444] and [ECC KÖLN]. The figures cited refer to the state of the respective publication.

Related Articles

Law & compliance

Hazardous Substances in the B2B Shop: Labelling and SDS

Pictograms, hazard and precautionary statements, safety data sheets per language and version, supply blocks: how to map hazardous substance data in a B2B shop.

15 min read
Operations, performance & security

IT Security and NIS2 for Your B2B Shop

What NIS2, GDPR and PCI-DSS mean for B2B store operators: scope assessment, reporting deadlines, supply-chain security, MFA and technical hardening.

13 min read
Law & compliance

VAT in the B2B shop: validating VAT IDs correctly

Checking VAT IDs in the B2B shop: simple and qualified confirmation, 26 status messages of the interface, reverse charge wording and the evidence to retain.

15 min read