Appoint us
Connected hardware covered by the EU Cyber Resilience Act

REP27 · CRA · Authorised representative

Regulation (EU) 2024/2847 · article 18 · article 14

CRA authorised representative: optional, and decisive.

Most compliance pages would tell you this appointment is mandatory. It is not, and saying otherwise would be the fastest way to lose your trust. Article 18 says a manufacturer may, by written mandate, appoint an authorised representative. What makes it matter is Article 14: when a manufacturer has no main establishment in the Union, the CSIRT that receives the 24-hour report is determined first by the Member State of the authorised representative, then the importer, then the distributor. Without a mandate, the one thing you have to do in 24 hours starts with a question about where to send it.

Article 18Article 1424 hours11 September 2026Optional

Request this service   Ask a question

Why an optional appointment matters

The order in Article 14 CRA that determines which CSIRT receives a report
The order in Article 14 CRA that determines which CSIRT receives a report

Read the last row. A manufacturer outside the Union with no representative, no importer and no distributor of record has no predictable route, and the clock is 24 hours. The mandate is not a legal requirement; it is the difference between a procedure and a scramble.

The five steps

The five steps to appoint an authorised representative under Article 18 CRA
The five steps to appoint an authorised representative under Article 18 CRA
  1. Confirm scope

    A product with digital elements made available on the Union market, whose intended or reasonably foreseeable use includes a data connection. Medical devices, motor vehicles, aviation and marine equipment have their own regimes and are excluded.

  2. Classify

    Default, important class I or II, or critical, from Annexes III and IV. The class decides whether you self-assess or go through a notified body, and no representative changes that.

  3. Decide on the mandate

    Optional under Article 18(1). The reason to sign is Article 14(8) and the reason not to is if you already have a main establishment in the Union.

  4. Sign it

    A written mandate with an entity established in the Union, accepting at least the tasks in Article 18(3).

  5. Keep the documentation reachable

    The EU declaration of conformity and the technical documentation at the disposal of market surveillance for ten years or the support period, whichever is longer.

What Article 18(3) actually puts in the mandate

TaskWhat it means in practice
Keep the EU declaration of conformity availableWe hold the copy you give us and produce it on a reasoned request
Keep the technical documentation availableSame, for ten years or the support period, whichever is longer
Provide information on a reasoned requestEverything necessary to demonstrate conformity, in the language of the authority
Cooperate on corrective actionOn any measure taken to eliminate the risks of the product covered by the mandate
Produce the mandate itselfTo market surveillance authorities on request
Article 18(2) is as important as what is included: the substantive obligations of Article 13(1) to (11), (12) first subparagraph and (14) cannot be part of the mandate. Designing a secure product, running vulnerability handling and drawing up the documentation stay with the manufacturer, by law, and no provider can take them.

The dates

  1. Entered into force

    December 2024, with a phased application that is the reason for the confusion in the market.

  2. 11 September 2026

    The reporting obligations apply: actively exploited vulnerabilities and severe incidents, through the single reporting platform run by ENISA.

  3. 11 June 2026

    The provisions on notified bodies apply, which is what allows conformity assessment bodies to be designated in time.

  4. 11 December 2027

    The regulation applies in full: essential requirements, CE marking, technical documentation, the lot.

  5. Products already on the market

    Reporting obligations reach products made available before December 2027 as well. That surprises people, and it is in the text.

The practical consequence for a manufacturer outside the Union is that the reporting route needs to exist before September 2026, while the full conformity work has until the end of 2027. Those are different projects with different lead times, and treating them as one is why teams start late on both.

Who should sign the mandate, and who should not

Should

A manufacturer outside the Union with no main establishment there, selling products with digital elements into Europe, whether hardware with firmware or software sold commercially.

Should

A company whose European route to market is through resellers or marketplaces, where no single importer would obviously receive a report.

Should

Anyone who has read Article 14(8) and does not want the first 24 hours of an incident spent identifying an authority.

Should not

A manufacturer with a real main establishment in the Union. The reporting route already runs through that Member State.

Should not

Products excluded from the regulation: medical devices, in vitro diagnostics, motor vehicles, civil aviation and marine equipment, each with their own regime.

Probably not yet

Free and open-source software developed or supplied outside a commercial activity, which is largely outside the regulation.

What we do and what we refuse to claim

We doWe do not
Sign the Article 18 mandate within 24 hours of the intake callPerform conformity assessment: that is a notified body's role for important class II and critical products
Hold the declaration of conformity and technical documentationDraw them up. Article 18(2) puts that with the manufacturer
Produce them to market surveillance on a reasoned requestReport your vulnerabilities: the 24-hour warning needs facts only your team has
Cooperate on corrective measuresDesign your security or generate your SBOM
Issue a certificate with a verification codeIssue a CE mark or anything resembling one
Answer in eight languages, same working dayAdvise on national implementing measures

The short version

The appointment is optional and it is the cheapest insurance in the regulation. It costs €490 a year, takes 24 hours, and it fixes in advance the single question you cannot afford to research during an incident: which CSIRT receives the report. Everything else the CRA asks of you — secure design, vulnerability handling, the SBOM, the support period, the documentation, the reporting itself — stays inside your company, and any provider telling you otherwise has not read Article 18(2).

Where the CRA sits among your other European duties

A manufacturer selling a connected device into Europe rarely has only this obligation. Seeing them together prevents the two classic mistakes: paying twice for the same thing, and discovering the fourth one during an audit.

RegulationWhat it governsRepresentativeWhere it shows
Cyber Resilience ActSecurity of the product with digital elementsOptional, Article 18Technical documentation and the reporting route
GPSR 2023/988Physical safety of the productMandatory, Article 16Printed on the label
GDPR 2016/679Personal data of people in the UnionMandatory, Article 27Privacy notice
Data Act 2023/2854Access to data generated by product useMandatory if not established in the UnionPre-contractual information
NIS2 2022/2555Security of services you operateMandatory, Article 26(3)Entity registration

Only one of those five is optional, and it is this one. That is worth saying plainly, because a market that describes every mandate as compulsory eventually gets ignored. The reason to sign the CRA mandate is operational, not legal: it removes a variable from the worst 24 hours your team will have.

What an intake call establishes

  1. What you place on the Union market

    Hardware, firmware, standalone software, and whether any remote data processing is integral to the product.

  2. The class

    Default, important I or II, critical, from Annexes III and IV. This decides your assessment route and your timeline, not the mandate.

  3. Whether you are established in the Union

    If a real entity of yours is, the reporting route already runs through it and you do not need this.

  4. Your route to market

    Direct, through resellers, through marketplaces. Where no single importer of record exists, the mandate matters more.

  5. What else you hold

    Article 27, Article 16, NIS2 or Data Act designations, so that renewal dates and correspondence land in one place.

Two objections we hear, answered

"If it is optional, why bother?"

Because Article 14(8) does not leave the question open. Without a representative, your report is routed through the importer or the distributor's Member State, meaning a CSIRT you did not choose, in a language you may not operate in, reached through a partner you now depend on during an incident. The mandate replaces that chain with one known address, decided calmly in advance.

"Our distributor can handle it"

A distributor can be the routing point by default, but it has not agreed to be your compliance interface, it holds none of your technical documentation and it has no duty to answer market surveillance about your product. Relying on it is relying on somebody else's goodwill on the worst day of your year.

The short version

The Cyber Resilience Act does not require you to appoint anyone, and we will not pretend otherwise. What it does is decide, in Article 14(8), that a manufacturer without an establishment in the Union reports through the Member State of its authorised representative, failing that its importer, failing that its distributor. Signing the Article 18 mandate replaces a chain you do not control with one address you chose. It costs €490 a year, takes 24 hours, covers retention of your documentation and cooperation with market surveillance, and expressly cannot cover the design, vulnerability handling and documentation duties that Article 18(2) leaves with you.

Classifying a product with digital elements under the Cyber Resilience Act
Classifying a product with digital elements under the Cyber Resilience Act
Prague seat of the authorised representative appointed under Article 18 CRA

Questions we are actually asked

Is the CRA authorised representative mandatory?

No. Article 18(1) says a manufacturer may appoint one by written mandate. It differs from the medical devices and radio equipment regimes, where the appointment is required.

Why appoint one if it is optional?

Article 14(8): where a manufacturer has no main establishment in the Union, the CSIRT receiving the 24-hour report is determined first by the Member State of the authorised representative.

What tasks are in the mandate?

Keeping the declaration of conformity and technical documentation available for ten years or the support period, providing information on reasoned request, cooperating on corrective measures, and producing the mandate itself.

What cannot be delegated?

Article 18(2) excludes the substantive manufacturer obligations in Article 13. Secure design, vulnerability handling and drawing up the documentation stay with you.

When do the reporting duties start?

11 September 2026. The regulation applies in full from 11 December 2027.

What has to be reported?

Actively exploited vulnerabilities and severe incidents affecting the security of the product, through the single reporting platform.

Does it cover products already on the market?

The reporting obligations reach products with digital elements made available on the market, including those placed before December 2027.

Which products are excluded?

Medical devices, in vitro diagnostics, motor vehicles, civil aviation and marine equipment, which are covered by their own legislation.

What are the fines?

Up to €15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and the manufacturer obligations.

Do we still need a notified body?

For important class II and critical products, yes. Default products are self-assessed under module A. The representative has no role in assessment.

Is an SBOM required?

Yes, as part of the vulnerability handling requirements in Annex I, part II. It is generated by your build process, not by us.

How long is the support period?

At least five years, unless the expected product lifetime is shorter, and it must be communicated to the user.

Can the representative report on our behalf?

No. The early warning needs facts only your team holds, and the platform is designed for the manufacturer to use.

Does the CRA overlap with NIS2?

They apply to different things: the CRA to products you sell, NIS2 to services you operate. A company can be caught by both.

What about open-source software?

Software developed or supplied outside a commercial activity is largely outside the regulation, with a lighter regime for open-source stewards.

Which Member State should the representative be in?

Any Member State. It becomes the state whose CSIRT coordinates your reporting, so consistency with your other mandates helps.

How fast can it be signed?

Within 24 hours of a short intake call confirming the product class and scope.

What does it cost?

€490 a year for the CRA mandate, with a combined price when held with the other designations.

Related: the reporting clock · what is in scope

A reporting route decided in advance

Europe Services, SE in Prague as your Article 18 authorised representative, signed within 24 hours, holding your documentation and answering market surveillance in eight languages.

Request this service