CRA Bureau writes your technical file, SBOM and declaration of conformity. Free to start · from €99/monthSee what you get
CRA Bureau
All guides

The Cyber Resilience Act for UK and other non-EU companies

8 min readUpdated 22 September 2026Cites Cyber Resilience Act

The short answer

Articles 2(1) and 3
Brexit did not take you out of scope

Which role you hold

Articles 13, 19, 20 and 21
How it reaches EU usersYour roleWhat that means
Sold or downloaded directly — your website, an app store, an agent shipped with your SaaSManufacturerEvery manufacturer obligation falls on you: essential requirements, risk assessment, technical file, declaration, CE marking, reporting.
Bought by an EU company and resold under your brandManufacturerThe EU company is the importer. Before selling, it must check your conformity assessment, technical file and CE marking — so expect it to ask for them.
Sold by an EU company under its own name or trademarkSupplier to a manufacturerThe EU company becomes the manufacturer and takes on the full set of obligations. Expect contractual requirements to support it.
Through an EU distributor or resellerManufacturerThe distributor checks the CE marking and documents are present. It will not sell a product it has reason to believe does not conform.
Try it free

The authorised representative

Article 18

Who you report to under Article 14

Article 14
If you have…You notify the CSIRT of…
An authorised representativeThe member state where the representative is established
No representative, but an importerThe member state where the importer is established
Neither, but a distributorThe member state where the distributor is established
None of theseThe member state with the most users of your product
Decide this now, in writing

How it compares with the UK PSTI regime

Articles 13(8), 14 and 64
UK PSTIEU CRA
ScopeConsumer connectable productsAll products with digital elements — consumer and business, hardware and software
Applies from29 April 2024Reporting from 11 Sep 2026; everything else from 11 Dec 2027
Default passwordsUniversal defaults bannedCovered by secure-by-default and access control, Annex I
Vulnerability disclosurePublished policy requiredPolicy required, plus handling, SBOM and security updates
Support periodMinimum update period publishedAt least five years unless expected use is shorter
Incident reportingNone24-hour, 72-hour and final reports to CSIRT and ENISA
DocumentationStatement of complianceAnnex VII technical file, EU declaration, CE marking
Maximum penalty£10m or 4% of worldwide revenue€15m or 2.5% of worldwide turnover

What to do, in order

  • Confirm scope and product class for each product you sell into the EU. Classification decides whether you can self-assess at all.
  • Put an Article 14 procedure in place now: who decides, which CSIRT, and how the awareness timestamp is recorded. This duty already applies.
  • Decide whether to appoint an authorised representative, and name them in the procedure if you do.
  • Build the SBOM and start continuous vulnerability monitoring — it feeds both the reporting duty and the technical file.
  • Write the risk assessment and the technical file, then issue the declaration and affix CE marking before 11 December 2027.
  • Tell your EU importers and resellers what they can expect from you and when. They will be asking.

Skip the blank page

Draft documents free. Clean, unwatermarked documents from €99 a month. Rather hand it over? We build the file for €2,900.

Not ready to start? Check your own product

Free, no account needed.

Related guides