Automate CRA Supplier Verification for Retailers & Marketplaces
Under the EU Cyber Resilience Act, distributors must act with due care and verify that connected products have active vulnerability handling channels. CVD Portal provides a free 3-minute setup for suppliers and 1-click verification for compliance officers.
Check whether a supplier runs a CVD portal
Enter a supplier's portal slug or verified portal domain. The result reports what the supplier has published and declared here. CVD Portal does not audit the supplier.
How CVD Portal Protects Retail Platforms
Zero Cost for Sellers
Marketplace sellers create an active vulnerability portal and machine-readable security.txt in 3 minutes on our free tier.
1-Click Compliance Proof
Sellers submit their unique Trust URL into your vendor onboarding system. Compliance staff click the link to verify active intake and 48-hour SLA metrics.
Instant Pre-Screening
Compliance teams use scan.cvdportal.com to scan any vendor domain for security headers and CRA readiness gaps.
Free CRA Academy
Train your vendor quality officers and seller network with free interactive modules, quizzes, and verifiable Open Badges on CRA obligations.
Private-Label Protection
Under Article 21, in-house brands (e.g. BlueBuilt, Koenic, PEAQ) legally deem retailers as manufacturers. We provide full whitelabel CVD infrastructure with 48-hour SLA tracking and ENISA SRP-ready export packages.
EU Cyber Resilience Act: Distributor Liabilities
Key articles impacting online marketplaces, retail chains, and catalog distributors.
Obligations of Distributors & Due Diligence
Distributors must verify that products with digital elements bear the CE marking and that the manufacturer has established a vulnerability handling policy. If a distributor has reason to believe a product does not conform, it must not make the product available on the market.
Cases Where Importers & Distributors Become Manufacturers
When a retailer or distributor places a product on the market under its own name or trademark, it is legally deemed the manufacturer. It assumes full responsibility under Article 13 and 14, including operating a public vulnerability disclosure channel and ENISA reporting.
Penalties and Administrative Fines
Non-compliance with distributor obligations or manufacturing duties carries administrative fines of up to €10,000,000 or 2% of the total worldwide annual turnover for the preceding financial year.
Plug-and-Play Merchant Guide Snippet
Ready for Partner PortalsCopy this snippet directly into your seller help center (e.g. Bol Partnerplatform, Coolblue Partner Portal, MediaMarkt Seller Hub):
## EU Cyber Resilience Act (CRA) Requirements for Sellers All sellers offering connected products or software must maintain an active Coordinated Vulnerability Disclosure (CVD) process. Quick 3-Minute Compliance Setup (Free): 1. Register your free portal at: https://cvdportal.com/register?source=marketplace 2. Set up your automated security policy and public intake channel. 3. Submit your live verification URL (cvdportal.com/verify/<slug>) in your seller compliance profile. CVD Portal basic registration and verification are free for all platform sellers.
Need a Briefing for Your Compliance Team?
Schedule a 15-minute briefing or request a free private-label brand CVD audit.