EU Cyber Resilience Act (Regulation 2024/2847) · Article 19 & 20

Automate CRA Supplier Verification for Retailers & Marketplaces

Under the EU Cyber Resilience Act, distributors must act with due care and verify that connected products have active vulnerability handling channels. CVD Portal provides a free 3-minute setup for suppliers and 1-click verification for compliance officers.

Supplier portal lookup

Check whether a supplier runs a CVD portal

Enter a supplier's portal slug or verified portal domain. The result reports what the supplier has published and declared here. CVD Portal does not audit the supplier.

Try the sample portal:
Distributor Compliance Architecture

How CVD Portal Protects Retail Platforms

1

Zero Cost for Sellers

Marketplace sellers create an active vulnerability portal and machine-readable security.txt in 3 minutes on our free tier.

2

1-Click Compliance Proof

Sellers submit their unique Trust URL into your vendor onboarding system. Compliance staff click the link to verify active intake and 48-hour SLA metrics.

3

Instant Pre-Screening

Compliance teams use scan.cvdportal.com to scan any vendor domain for security headers and CRA readiness gaps.

4

Free CRA Academy

Train your vendor quality officers and seller network with free interactive modules, quizzes, and verifiable Open Badges on CRA obligations.

5

Private-Label Protection

Under Article 21, in-house brands (e.g. BlueBuilt, Koenic, PEAQ) legally deem retailers as manufacturers. We provide full whitelabel CVD infrastructure with 48-hour SLA tracking and ENISA SRP-ready export packages.

Executive Regulatory Brief

EU Cyber Resilience Act: Distributor Liabilities

Key articles impacting online marketplaces, retail chains, and catalog distributors.

Article 19 & 20

Obligations of Distributors & Due Diligence

Distributors must verify that products with digital elements bear the CE marking and that the manufacturer has established a vulnerability handling policy. If a distributor has reason to believe a product does not conform, it must not make the product available on the market.

Article 21

Cases Where Importers & Distributors Become Manufacturers

When a retailer or distributor places a product on the market under its own name or trademark, it is legally deemed the manufacturer. It assumes full responsibility under Article 13 and 14, including operating a public vulnerability disclosure channel and ENISA reporting.

Article 64

Penalties and Administrative Fines

Non-compliance with distributor obligations or manufacturing duties carries administrative fines of up to €10,000,000 or 2% of the total worldwide annual turnover for the preceding financial year.

Plug-and-Play Merchant Guide Snippet

Ready for Partner Portals

Copy this snippet directly into your seller help center (e.g. Bol Partnerplatform, Coolblue Partner Portal, MediaMarkt Seller Hub):

## EU Cyber Resilience Act (CRA) Requirements for Sellers

All sellers offering connected products or software must maintain an active Coordinated Vulnerability Disclosure (CVD) process.

Quick 3-Minute Compliance Setup (Free):
1. Register your free portal at: https://cvdportal.com/register?source=marketplace
2. Set up your automated security policy and public intake channel.
3. Submit your live verification URL (cvdportal.com/verify/<slug>) in your seller compliance profile.

CVD Portal basic registration and verification are free for all platform sellers.

Need a Briefing for Your Compliance Team?

Schedule a 15-minute briefing or request a free private-label brand CVD audit.

Schedule 15-Min Briefing