Source: OJ L 2024/2847, 20.11.2024

Current language: SV

Artikel 22 Andra fall där tillverkarnas skyldigheter gäller


Summary What does Article 22 of the CRA regulation say?

This article closes a potential loophole by capturing third parties — those who are not already manufacturers, importers, or distributors — who substantially modify a product with digital elements and then place it back on the market.

It does so by reclassifying such a person as a manufacturer for the purposes of this Regulation, thereby triggering the full suite of manufacturer obligations.

It connects directly to Article 21, which applies the same logic to importers and distributors, together forming a coherent framework that ensures no actor can escape manufacturer-level responsibility simply by virtue of their original role in the supply chain.

Important points:

  • Any third party that substantially modifies a product with digital elements and makes it available on the market is treated as a manufacturer under this Regulation.
  • Such persons are subject to the obligations in Articles 13 and 14, at minimum for the modified part of the product.
  • If the substantial modification affects the cybersecurity of the product as a whole, the obligations apply to the entire product, not just the modified portion.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. En fysisk eller juridisk person, annan än tillverkaren, importören eller distributören, som utför en väsentlig ändring av en produkt med digitala element och tillhandahåller den produkten på marknaden ska anses som tillverkare vid tillämpningen av denna förordning.

    1. Den person som avses i punkt 1 i denna artikel ska omfattas av de skyldigheter som fastställs i artiklarna 13 och 14 när det gäller den del av produkten med digitala element som påverkas av den väsentliga ändringen eller, om den väsentliga ändringen påverkar cybersäkerheten för produkten med digitala element som helhet, för hela produkten.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod