CRA for agencies: who is the manufacturer?
CRA for digital agencies: when your client is the manufacturer, when you are – and the contract clauses on support, reporting and SBOMs you need now.
Marius Gill6 min readDeutsche Fassung
When an agency builds software on behalf of a client, the client is usually the manufacturer under the Cyber Resilience Act – because the manufacturer is whoever has a product developed and markets it under their own name or trademark. The agency becomes a manufacturer itself when it sells the product under its own name.
In practice much of the work still shifts to you: your client needs SBOMs, vulnerability fixes over years and fast support when reporting. Regulate this clearly in contracts and an obligation becomes a business model. Our CRA overview explains the regulatory framework.
The definition of manufacturer
Under Art. 3(13) CRA a manufacturer is a natural or legal person who develops or manufactures products with digital elements, or has them designed, developed or manufactured, and markets them under their name or trademark, whether for payment or free of charge. What matters is not who writes the code but who puts the product on the market.
Typical scenarios
White-label app
You build an app your client offers under its brand in app stores. The client is the manufacturer. You supply what it needs for conformity and reporting.
Agency-owned product
You sell a plugin, theme or software with a local client under your own name to several customers. Then you are the manufacturer – with all obligations under Art. 13 and 14.
Maintenance contract
You maintain an existing client product. The client remains the manufacturer. But whoever updates dependencies and builds security patches is effectively part of its vulnerability handling – and of its 24h reporting chain.
| Obligation | Client as manufacturer | Agency as provider |
|---|---|---|
| Risk assessment, technical documentation | responsible | provides input |
| SBOM per release | must have | generates and delivers |
| Fix vulnerabilities during support period | responsible | implements (by contract) |
| 24h / 72h reporting | reports | analysis, patch, facts |
| Declaration of conformity, CE | signs | – |
What is at stake
Maximum fines under Art. 64 CRA
| Annex I, Art. 13, 14 (or 2.5% of turnover) | 15 EUR million |
|---|---|
| Other obligations (or 2% of turnover) | 10 EUR million |
| Incorrect information (or 1% of turnover) | 5 EUR million |
Fines hit the manufacturer. Expect clients to try passing liability on by contract – which makes clear boundaries all the more important.
Contract clauses you need now
- Role clause: who is the manufacturer under the CRA? Put it in writing.
- Support period: the manufacturer generally has to provide security updates for at least five years. Who builds them, on what terms?
- Response times: binding times for analysis and patch for actively exploited vulnerabilities – aligned with 24h and 72h.
- SBOM delivery: format (CycloneDX/SPDX), depth, timing – per release.
- Documentation: which evidence on secure development, testing and configuration do you provide?
- Open source: who checks dependencies and licences?
CRA operations as a service
Many mid-sized companies have neither a security team nor processes for five years of product maintenance. Agencies offering SBOMs, vulnerability monitoring and patch readiness as an ongoing service solve a real problem – and create predictable recurring revenue.
Checklist for agencies
- Classify all client projects by role: client manufacturer, agency manufacturer, out of scope.
- Identify your own products for which you are the manufacturer.
- Add CRA clauses to existing maintenance contracts.
- Build SBOM generation into every pipeline.
- Organise incident readiness from September 2026.
Example: maintenance contract in a reporting case
A mid-sized company has had its customer app maintained by an agency for years. In October 2026 a vulnerability in an authentication library it uses is actively exploited. The company, as manufacturer, must submit an early warning within 24 hours – but cannot assess whether its app is affected without the agency. If the contract has no response time, clarification starts on the next working day. With agreed on-call and an up-to-date SBOM, the answer is there within hours.
How to build a CRA service offering
- Review the portfolio: which clients place products on the market that you built or maintain?
- Define a standard package: SBOM per release, vulnerability monitoring, patch readiness with fixed response times, support with reports.
- Set a pricing model: a monthly fee per product rather than hourly billing gives both sides predictability.
- Standardise tooling: one pipeline template and one evidence store for all projects.
- Document boundaries: what the agency delivers and what stays with the manufacturer – e.g. the declaration of conformity.
| Service | Without CRA service | With CRA service |
|---|---|---|
| Dependency updates | Occasionally | Regular and documented |
| Response to exploited vulnerability | When available | Agreed response time |
| SBOM | None | Delivered per release |
| Evidence for the manufacturer | Reconstructed on request | Collected continuously |
Avoid promises only the manufacturer can keep. The agency can supply evidence and run processes; legal responsibility for conformity lies with the manufacturer.
Typical questions in client conversations
- 'Are we affected at all?' Only if the product is made available on the market – clarify it together per project.
- 'Can you do the reporting for us?' You can prepare it; the manufacturer must submit and own it.
- 'How long must you maintain the app?' As long as the support period the manufacturer sets – the contract should reflect that.
Having short written answers ready for these questions looks competent and avoids misunderstandings that become expensive later.
Nuowei for agencies
Nuowei (beta, launch November 2026) offers a multi-client workspace: SBOMs, vulnerabilities and evidence separated per client project, with hand-over to the manufacturer. Details under solutions for agencies.
Only if you place the product on the market under your own name or trademark. For commissioned development it is usually the client.
Reporting is the manufacturer's duty. You should, however, be contractually committed and able to support it quickly with facts.