CRA – who is responsible?

A WTG (Wind Turbine Generator) manufacturer asks a supplier to design a sub-component in accordance with its specifications. How is the CRA responsibility split between the WTG manufacturer and the sub-component supplier?

The sub-component is here assumed to be a component/product with digital elements and network connectivity.

This is a typical CRA grey zone, but the Regulation is very clear once you apply the definitions of manufacturer, supplier, integrator, and product with digital elements (PwDE).

Scenario #1: The sub-component placed on the EU market as its own product

Examples could include

    • A network-connected pitch controller sold to multiple turbine OEMs
    • A digital sensor module with its own firmware and connectivity
    • PLC-based subsystem with its own CE marking

Here, the supplier assumes the role of the Manufacturer under CRA. They must fulfill all obligations in Articles 13–20, including, e.g., 

    • Secure by design & secure by default (Annex I Part I)
    • Vulnerability handling & reporting (Annex I Part II + Art. 13(3))
    • SBOM / component inventory
    • Security updates for the declared support period
    • Technical documentation (Art. 31)
    • CE marking & DoC
    • Incident reporting to ENISA (Art. 14)

The WTG manufacturer assumes the role of Integrator/downstream manufacturer and must

    • Verify supplier conformity (Art. 13(2))
    • Ensure integration does not break security
    • Maintain system-level vulnerability handling
    • Include the component in their own SBOM
    • Ensure system-level documentation and CE marking for the turbine

Both parties have CRA obligations, but the supplier carries the full manufacturer burden for the subcomponent.

Scenario #2: The sub-component is custom made only for this WTG

Examples could include:

    • A bespoke controller designed only for one turbine model
    • A custom networked sensor with no independent market presence
    • A firmware-driven module that only exists inside the turbine

The WTG manufacturer assumes the role of Manufacturer under CRA for the entire product. They must fulfill all CRA obligations, including for the subcomponent.

The sub-component Supplier serves as the Contracted design house / OEM supplier. They are not a CRA manufacturer, but they must:

    • Provide all security-relevant design artifacts
    • Support SBOM creation
    • Support vulnerability handling
    • Provide update mechanisms
    • Provide evidence for conformity assessment

The WTG manufacturer carries the legal responsibility. The supplier carries the technical responsibility.

Scenario #3: The sub-component supplier does not develop and add software

The WTG manufacturer develops and loads the software, and the supplier provides only hardware, a preinstalled OS, and network device firmware. The WTG manufacturer here becomes the CRA Manufacturer for the entire sub‑component.

Thus, the supplier is not a CRA Manufacturer. They are a hardware supplier and contracted integrator.

Even if the WTG manufacturer provides the supplier with software for testing purposes, the WTG manufacturer remains the CRA Manufacturer.

To conclude

The CRA assigns responsibility based on who places the product on the market in their name (Art. 3(21)):

    • If the supplier’s name is on the subcomponent → supplier = manufacturer
    • If the WTG manufacturer’s name is on the final product → WTG manufacturer = manufacturer
    • If the component is not marketed independently → only the WTG manufacturer is the manufacturer

Note: This is identical to the way the Machinery Regulation, RED, and EMC directives work.

CRA ObligationSupplier (standalone PWDE)Supplier (custom-only)WTG Manufacturer
CE-marking✔️-✔️
Declaration of Conformity✔️-✔️
Annex I security requirements✔️Shared✔️
Vulnerability handling✔️Shared✔️
SBOM / component inventory✔️Shared✔️
Security updates✔️Shared✔️
Incident reporting (ENISA)✔️-✔️
Technical documentation (Art. 31)✔️Shared✔️
Integration security--✔️

The CRA establishes a shared responsibility model, but legal liability always follows the “placed on the market” rule.