← HomeREP27All categories

Connected devices and software with digital elements

Digital and connected products

In short
Authorised representative in the Union under the Cyber Resilience Act, appointed by written mandate

Who has to appoint one

Manufacturers established outside the Union that place products with digital elements on the EU market. 'Products with digital elements' covers hardware whose intended purpose includes a data connection — cameras, routers, smart appliances, industrial sensors, wearables — and software supplied separately, whether sold, licensed or monetised indirectly. Importers and distributors have their own duties and step into the manufacturer's shoes if they market the product under their own name. Where the manufacturer is outside the Union and has no importer established there, the authorised representative is the entity the authorities address.

Thresholds and exemptions

No turnover or size threshold applies to the substantive obligations. Free and open-source software developed or supplied outside the course of a commercial activity is out of scope, and open-source stewards have a lighter regime. Microenterprises and small enterprises get procedural relief on some documentation, not an exemption. Products already covered by equivalent sectoral cybersecurity rules — medical devices, motor vehicles, civil aviation, marine equipment — are excluded to avoid duplication.

What must appear on the label

The manufacturer's name, registered trade name or trade mark and postal address, and the same for the authorised representative, on the product, its packaging or an accompanying document. A single point of contact for reporting vulnerabilities, which must be easy to find and machine-readable where practicable. The CE marking once the conformity obligations apply from December 2027. Information for the user on the support period during which security updates will be provided, on how updates are delivered, and on the intended purpose and known risks.

Marketplace fields

No dedicated marketplace field exists yet, but the compliance fields already used for CE-marked goods will carry these details, and enterprise procurement in the Union now routinely asks who the CRA representative is and what the declared support period is. Expect marketplaces to add a support-period field as December 2027 approaches, in the way they added the GPSR responsible person field in 2024.

Documentation you must hold

Technical documentation covering the design, development and vulnerability handling processes. A cybersecurity risk assessment, updated over the support period, which drives which of the Annex I essential requirements apply and how. A software bill of materials in a commonly used machine-readable format, covering at minimum the top-level dependencies. A coordinated vulnerability disclosure policy, publicly available. Records of vulnerabilities and their remediation. The EU declaration of conformity. Where the product falls in an important or critical class under Annex III or IV, the notified body certificate or the relevant scheme certification.

Standards and testing

Conformity assessment routes depend on the class. Default products can use internal control against the essential requirements. Important products in class I can self-assess if harmonised standards are applied in full, otherwise a third party is required. Class II always requires a third party. Critical products may require European cybersecurity certification. Harmonised standards under the CRA are still being developed, which means self-assessment currently rests on documented reasoning against Annex I rather than on a standard number.

Language requirements

Instructions and user information, including the support period and the vulnerability contact point, in a language easily understood by users in each member state where the product is placed on the market, as determined by that state.

When it applies

Three dates matter. From 11 September 2026 the reporting obligations in Article 14 apply: actively exploited vulnerabilities and severe incidents must be reported through the single reporting platform. From 11 December 2027 the remaining obligations apply in full, including CE marking, conformity assessment and the essential requirements. Products placed on the market before that date are generally not caught retroactively unless substantially modified afterwards, but the reporting duties attach earlier.

How long records are kept

Technical documentation and the EU declaration of conformity for at least ten years after the product was placed on the market, or the length of the support period, whichever is longer. The support period must be at least five years unless the expected use is shorter, and the reasoning for a shorter period must be documented.

What happens if you do not comply

Up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaches of the essential requirements or the manufacturer's core obligations. Up to €10 million or 2% for most other obligations, and up to €5 million or 1% for supplying incorrect or misleading information to a notified body or authority. Beyond fines, authorities can order withdrawal from the market, prohibit or restrict making the product available, and require recalls.

Who enforces it

National market surveillance authorities designated for the CRA, ENISA, and the CSIRTs designated as coordinators for the reporting obligations. The Commission has enforcement powers for products presenting a significant cybersecurity risk across several member states.

Where the boundary lies

Most business software is caught, but there are edges worth knowing. A product sold only outside the Union is out of scope; making the same software downloadable to EU users is not. SaaS is generally outside the CRA unless it is a remote data processing solution integral to a product's functions, in which case it comes in through the product. Medical devices, vehicles and aviation follow their own cybersecurity regimes. And the CRA sits alongside NIS2 rather than replacing it: NIS2 is about incidents affecting your service as an entity, the CRA is about vulnerabilities in the product you place on the market.

Questions we are asked

We are a small software company — does this really apply to us?
Yes, if the software is supplied commercially to users in the Union. There is no SME exemption, only some procedural simplification. What changes with size is the depth of documentation expected, not whether the obligations exist.
Is our SaaS platform in scope?
Usually not on its own. It comes into scope where it is a remote data processing solution whose absence would prevent a product with digital elements from performing its functions, in which case it is assessed as part of that product.
Do we need CE marking now?
Not yet. CE marking and conformity assessment apply from 11 December 2027. The reporting duties under Article 14 apply from 11 September 2026, which is the nearer deadline and the one most manufacturers are unprepared for.
What counts as the support period?
The period during which you provide security updates, which must reflect how long users can reasonably expect to use the product and be at least five years unless a shorter period is justified and documented. It must be declared to users before purchase.
CRA representative · on request

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category