The short answer
The Cyber Resilience Act attaches to the product, not to where the company is. If a product with digital elements is made available on the EU market in the course of a commercial activity, the Regulation applies to it — whether the manufacturer is in Frankfurt, Manchester, St Peter Port, Zurich or Austin.
Being outside the EU changes who else in the chain holds obligations and which authority you deal with. It does not reduce what the product itself must meet.
Which role you hold
Your obligations follow from your role, and your role follows from how the product reaches EU users. Most non-EU software vendors are simply the manufacturer.
| How it reaches EU users | Your role | What that means |
|---|---|---|
| Sold or downloaded directly — your website, an app store, an agent shipped with your SaaS | Manufacturer | Every manufacturer obligation falls on you: essential requirements, risk assessment, technical file, declaration, CE marking, reporting. |
| Bought by an EU company and resold under your brand | Manufacturer | The EU company is the importer. Before selling, it must check your conformity assessment, technical file and CE marking — so expect it to ask for them. |
| Sold by an EU company under its own name or trademark | Supplier to a manufacturer | The EU company becomes the manufacturer and takes on the full set of obligations. Expect contractual requirements to support it. |
| Through an EU distributor or reseller | Manufacturer | The distributor checks the CE marking and documents are present. It will not sell a product it has reason to believe does not conform. |
Would rather not write the technical file and declaration for a non-EU manufacturer from scratch? CRA Bureau drafts it from your own product, free to start.
Try it freeThe authorised representative
A manufacturer may appoint an authorised representative in the EU by written mandate. Under the CRA this is an option rather than an obligation, but for a non-EU vendor it is usually worth having: it gives market surveillance authorities someone to contact, it decides which CSIRT you report to, and EU business customers increasingly ask for one during procurement.
What a representative cannot do is take over the substance. Designing the product to meet the essential requirements and drawing up the technical documentation remain yours. The mandate covers holding the declaration and technical file at the authorities’ disposal, answering reasoned requests, and cooperating on corrective action.
Who you report to under Article 14
An EU manufacturer notifies the coordinating CSIRT of the member state where it has its main establishment. A manufacturer with no EU establishment works down a cascade instead, and it needs to know the answer before the first 24-hour clock starts rather than during it.
| If you have… | You notify the CSIRT of… |
|---|---|
| An authorised representative | The member state where the representative is established |
| No representative, but an importer | The member state where the importer is established |
| Neither, but a distributor | The member state where the distributor is established |
| None of these | The member state with the most users of your product |
How it compares with the UK PSTI regime
UK companies already selling consumer connected devices at home will know the Product Security and Telecommunications Infrastructure regime, which has applied in the UK since 29 April 2024. It is a useful starting point, but it covers a thin slice of what the CRA asks.
| UK PSTI | EU CRA | |
|---|---|---|
| Scope | Consumer connectable products | All products with digital elements — consumer and business, hardware and software |
| Applies from | 29 April 2024 | Reporting from 11 Sep 2026; everything else from 11 Dec 2027 |
| Default passwords | Universal defaults banned | Covered by secure-by-default and access control, Annex I |
| Vulnerability disclosure | Published policy required | Policy required, plus handling, SBOM and security updates |
| Support period | Minimum update period published | At least five years unless expected use is shorter |
| Incident reporting | None | 24-hour, 72-hour and final reports to CSIRT and ENISA |
| Documentation | Statement of compliance | Annex VII technical file, EU declaration, CE marking |
| Maximum penalty | £10m or 4% of worldwide revenue | €15m or 2.5% of worldwide turnover |
What to do, in order
- Confirm scope and product class for each product you sell into the EU. Classification decides whether you can self-assess at all.
- Put an Article 14 procedure in place now: who decides, which CSIRT, and how the awareness timestamp is recorded. This duty already applies.
- Decide whether to appoint an authorised representative, and name them in the procedure if you do.
- Build the SBOM and start continuous vulnerability monitoring — it feeds both the reporting duty and the technical file.
- Write the risk assessment and the technical file, then issue the declaration and affix CE marking before 11 December 2027.
- Tell your EU importers and resellers what they can expect from you and when. They will be asking.