Regulation (EU) 2024/2847 · Chapter
Article 19 — Obligations of importers
Importers: the gatekeeping duties before a product enters the EU market.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
1.1. Importers shall place on the market only products with digital elements that comply with the essential cybersecurity requirements set out in Part I of Annex I and where the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I.
2.2. Before placing a product with digital elements on the market, importers shall ensure that:
(a) the appropriate conformity assessment procedures as referred to in Article 32 have been carried out by the manufacturer;
(b) the manufacturer has drawn up the technical documentation;
(c) the product with digital elements bears the CE marking referred to in Article 30 and is accompanied by the EU declaration of conformity referred to in Article 13(20) and the information and instructions to the user as set out in Annex II in a language which can be easily understood by users and market surveillance authorities;
(d) the manufacturer has complied with the requirements set out in Article 13(15), (16) and (19).
For the purposes of this paragraph, importers shall be able to provide the necessary documents proving the fulfilment of the requirements set out in this Article.
3.3. Where an importer considers or has reason to believe that a product with digital elements or the processes put in place by the manufacturer are not in conformity with this Regulation, the importer shall not place the product on the market until that product or the processes put in place by the manufacturer have been brought into conformity with this Regulation. Furthermore, where the product with digital elements presents a significant cybersecurity risk, the importer shall inform the manufacturer and the market surveillance authorities to that effect.
Where an importer has reason to believe that a product with digital elements may present a significant cybersecurity risk in light of non-technical risk factors, the importer shall inform the market surveillance authorities to that effect. Upon receipt of such information, the market surveillance authorities shall follow the procedures referred to in Article 54(2).
4.4. Importers shall indicate their name, registered trade name or registered trademark, the postal address, email address or other digital contact as well as, where applicable, the website at which they can be contacted on the product with digital elements or on its packaging or in a document accompanying the product with digital elements. The contact details shall be in a language easily understood by users and market surveillance authorities.
5.5. Importers who know or have reason to believe that a product with digital elements which they have placed on the market is not in conformity with this Regulation shall immediately take the corrective measures necessary to ensure that the product with digital elements is brought into conformity with this Regulation, or to withdraw or recall the product, if appropriate.
Upon becoming aware of a vulnerability in the product with digital elements, importers shall inform the manufacturer without undue delay about that vulnerability. Furthermore, where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market to that effect, giving details, in particular, of non-compliance and of any corrective measures taken.
6.6. Importers shall, for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer, keep a copy of the EU declaration of conformity at the disposal of the market surveillance authorities and ensure that the technical documentation can be made available to those authorities, upon request.
7.7. Importers shall, further to a reasoned request from a market surveillance authority, provide it with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I as well as of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Part II of Annex I in a language that can be easily understood by that authority. They shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by a product with digital elements, which they have placed on the market.
8.8. Where the importer of a product with digital elements becomes aware that the manufacturer of that product has ceased its operations and, as result, is not able to comply with the obligations laid down in this Regulation, the importer shall inform the relevant market surveillance authorities about this situation, as well as, by any means available and to the extent possible, the users of the products with digital elements placed on the market.
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 19 makes the importer a checkpoint: importers place only compliant products on the market, verifying that the manufacturer ran conformity assessment, drew up the technical documentation, affixed the CE marking and provided the declaration of conformity F-012 F-027 F-021.
Why this article matters commercially
Because an importer needs to be able to produce documents proving these checks, it may ask its manufacturers for that evidence, for example through contract terms. For a non-EU manufacturer, the practical effect is that Article 19 reaches you through your customers before an authority ever does.
Verified facts this page relies on
- F-012 Importers place only compliant products on the market; verify conformity assessment, technical documentation, CE marking and manufacturer identification; indicate their own name and address; report known vulnerabilities to the manufacturer; keep the declaration of conformity; cooperate with authorities. Art. 19
- F-027 CE marking is affixed visibly, legibly and indelibly to the product, or where not possible to the packaging or the declaration of conformity/accompanying documents; for software, on the declaration of conformity or the website accompanying the product. Art. 29–30
- F-021 EU declaration of conformity (Annex V) and simplified declaration (Annex VI). Art. 28, Art. 13(12), (20), Annex V, Annex VI
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.