EU CYBER RESILIENCE ACT

EU Cyber Resilience Act Authorised Representative

Article 18 representation for manufacturers of products with digital elements that choose to establish a defined EU regulatory interface under the Cyber Resilience Act.

CRA
ARTICLE
18AUTHORISED REPRESENTATION

OSTRAI supports manufacturers preparing for Article 18 representation and will act as EU-established Cyber Resilience Act Authorised Representative under defined written mandates from 11 December 2027.

Our service combines Article 18 representation, regulatory-documentation arrangements, market-surveillance communications, authority cooperation and a structured EU regulatory interface, backed by broader Cyber Resilience Act advisory capability.

No main establishment in the Union? From 11 December 2027, an Article 18 appointment can also provide a defined EU regulatory anchor for CRA reporting and regulatory coordination.

Explore Cyber Resilience Act Advisory

ARTICLE 18

A voluntary appointment.
A defined statutory role.

The Cyber Resilience Act does not require every manufacturer, including every manufacturer established outside the Union, to appoint an authorised representative.

Article 18 allows a manufacturer to appoint an EU-established authorised representative by written mandate.

  1. Voluntary appointment

    The manufacturer chooses whether to establish an Article 18 representative structure.

  2. Statutory role once appointed

    The authorised representative performs the tasks specified in the written mandate and must be empowered to carry out the minimum functions required by Article 18.

A CRA authorised representative must be established within the European Union. The manufacturer itself may be established inside or outside the Union.

Discuss whether Article 18 is useful for your structure

WHY ARTICLE 18?

One EU regulatory interface
across your CRA obligations.

Article 18 appointment is voluntary. For manufacturers operating across the Union, particularly manufacturers with no main establishment in the EU, it can nevertheless create a more controlled, predictable and operationally coherent regulatory structure.

Defined EU regulatory anchor

Establish a deliberate EU-based representative structure for CRA regulatory interaction rather than relying solely on changing importer, distributor or user-location arrangements.

Article 14 reporting predictability

From 11 December 2027, where a manufacturer has no main establishment in the Union, the relevant Article 18 authorised representative can become the first reference point in the Article 14(7) hierarchy used to determine the reporting endpoint.

Centralised market-surveillance interface

Route CRA documentation requests and market-surveillance communications through a defined representative familiar with the manufacturer, its products and its conformity structure.

Continuity across EU distribution

Maintain a stable regulatory interface even where importers, distributors, sales channels or product-market arrangements change.

Conformity & documentation coordination

Use the representative for the Article 18 documentation role and, where legally permitted and included in the mandate, additional conformity-related functions on the manufacturer’s behalf.

Portfolio coordination

Structure the representative relationship around agreed products or product families and maintain a consistent regulatory interface across the manufacturer’s represented EU portfolio.

FOR MANUFACTURERS WITHOUT AN EU MAIN ESTABLISHMENT

From 11 December 2027, the relevant Article 18 authorised representative can become the first reference point ahead of the importer, distributor and user-location fallbacks in the Article 14(7) reporting hierarchy.

It therefore allows the manufacturer to structure its initial EU reporting interface deliberately rather than allowing that structure to arise incidentally from its distribution footprint.

Discuss the benefits of Article 18 representation

ARTICLE 14(7)

Where there is no EU main establishment, the CRA creates a hierarchy.

For Article 14 reporting, the CRA first looks to the Member State of the manufacturer’s main establishment in the Union.

Where the manufacturer has no main establishment in the Union, the relevant reporting Member State is determined through the following statutory order.

WHY THIS MATTERS

Without an authorised representative, a third-country manufacturer’s reporting nexus may depend on its importer, distributor or user footprint.

Once Article 18 applies, an appropriate representative structure makes the authorised representative the first reference point in the statutory hierarchy.

  1. Authorised representative

    The Member State where the authorised representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements is established.

  2. Importer

    The Member State where the importer placing the highest number of the manufacturer’s products with digital elements on the market is established.

  3. Distributor

    The Member State where the distributor making available the highest number of the manufacturer’s products with digital elements is established.

  4. Users

    The Member State in which the highest number of users of the manufacturer’s products with digital elements is located.

Where a manufacturer has several authorised representatives, Article 14(7) refers to the representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements.

CURRENT APPLICATION

Reporting is live.
The full CRA follows in 2027.

  1. Chapter IV applies.

  2. Article 14 manufacturer reporting obligations apply.

  3. The CRA applies in full, including Article 18.

OSTRAI can support manufacturers now with Article 14 reporting, CRA readiness and preparation of future Article 18 representative structures.

The current Article 14(7) reporting structure must be assessed against the manufacturer’s existing EU arrangements. Preparing a future Article 18 appointment does not automatically change the current reporting nexus before Article 18 applies on 11 December 2027.

Prepare for CRA application

CRA / SCOPE

First determine whether
the product is inside the CRA.

  1. Is there a product with digital elements?

    This can include software, hardware and relevant remote data processing.

    If yes

    If no →

    CRA does not apply on this basis.

  2. Is the product made available on the Union market?

    If yes

    If no →

    No CRA market-placement trigger on this basis.

  3. Does its intended purpose or reasonably foreseeable use include a direct or indirect logical or physical data connection to a device or network?

    If yes

    If no →

    Outside the general Article 2(1) scope.

  4. Does a statutory exclusion or sector-specific rule apply?

    If no

    If yes →

    Assess the relevant exclusion or sector-specific regime.

Product with digital elements within CRA scope

Article 18 appointment is voluntary. CRA scope and representation are separate assessments.

PRODUCT SCOPE

Hardware, software and
the digital functions behind them.

Products with digital elements can include standalone software, hardware and combined hardware/software products. Remote data processing can form part of the product where it is designed and developed by, or under the responsibility of, the manufacturer and its absence would prevent a product function.

Standalone SaaS or cloud services are not products with digital elements merely because they are remotely accessed.

The product architecture and remote-data-processing relationship must be assessed.

Explore CRA Advisory

ECONOMIC OPERATOR

The CRA follows the manufacturer and the product.

The manufacturer is the natural or legal person that develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark.

Manufacturer, authorised representative, importer and distributor are distinct legal roles under the CRA.

Assess your CRA role
  1. Product
  2. Entity responsible for development / manufacture and marketed under its name or trademark
  3. Manufacturer
  4. CRA obligations

DIFFERENT EU ROLES

A representative
is not an importer.

ARTICLE 18

Authorised representative

  • Established within the Union.
  • Appointed by written mandate.
  • Appointment is voluntary.
  • Acts on behalf of the manufacturer for specified legally delegable tasks.
  • Provides documentation and authority-interface functions.
  • Can perform additional functions where the CRA permits them and they are included in the mandate.

ARTICLE 19

Importer

  • Established within the Union.
  • Places on the Union market a product with digital elements bearing the name or trademark of a manufacturer established outside the Union.
  • Has its own direct CRA obligations.
  • Performs specified pre-market compliance checks.
  • Has its own documentation, cooperation and corrective-action duties.

A manufacturer may have both an importer and an authorised representative. The two roles are legally distinct.

Appointment of OSTRAI does not remove the obligations of an importer where an importer exists.

Map your EU market structure

ARTICLE 18 MANDATE

The mandate creates
a defined EU regulatory interface.

The authorised representative performs the tasks specified in the written mandate.

Article 18 requires the mandate to allow the representative to perform at least the following functions.

Retain

Keep at the disposal of market-surveillance authorities:

  • The Article 28 EU declaration of conformity; and
  • The Article 31 technical documentation
At least 10 years after market placementOR THE PRODUCT SUPPORT PERIODWhichever is longer

Respond

Following a reasoned request from a market-surveillance authority, provide all information and documentation necessary to demonstrate conformity of the product with digital elements.

Cooperate

Cooperate with market-surveillance authorities, at their request, on actions taken to eliminate risks posed by products covered by the mandate.

Mandate availability

Provide a copy of the written mandate to market-surveillance authorities upon request.

DELEGABLE FUNCTIONS

Article 18 sets the minimum, not necessarily the entire mandate.

The written mandate may include additional CRA functions where the Regulation permits those functions to be performed by an authorised representative.

Examples may include, depending on the applicable conformity route and the terms of the mandate:

  • maintaining or providing declarations and conformity records
  • lodging certain applications with notified bodies
  • performing specified declaration or document-retention functions on behalf of the manufacturer
  • coordinating authority communications
  • supporting conformity-documentation workflows
  • other CRA functions expressly capable of performance by an authorised representative

The scope must be assessed against the applicable CRA provisions and conformity route.

Design the Article 18 mandate

STATUTORY LIMITS

The legal responsibility remains with the manufacturer.

Article 18 expressly prevents specified Article 13 obligations from being transferred to the authorised representative through the representative mandate.

That does not prevent OSTRAI from separately advising or supporting the manufacturer in fulfilling those obligations.

REMAINS THE MANUFACTURER’S LEGAL RESPONSIBILITY

Article 13(1)–(11)

Including core manufacturer responsibilities concerning, among other matters:

  • design, development and production in accordance with applicable cybersecurity requirements
  • cybersecurity risk assessment
  • third-party component due diligence
  • vulnerability handling
  • support-period determination
  • security updates
  • lifecycle cybersecurity responsibilities

Article 13(12), first subparagraph

Drawing up the Article 31 technical documentation before placing the product on the market.

Article 13(14)

Procedures ensuring products forming part of a series remain in conformity.

OSTRAI CAN STILL SUPPORT

Non-delegable does not mean unsupported.

Through OSTRAI’s CRA advisory practice, we can assist with:

  • Cybersecurity risk assessment
  • CRA scope and classification
  • Annex I compliance analysis
  • Third-party component due diligence
  • Vulnerability-handling frameworks
  • Support-period analysis
  • Technical-documentation preparation and review
  • Conformity-assessment readiness
  • Regulatory and standards analysis
  • Regulatory response

The manufacturer retains the underlying statutory responsibility.

The distinction is between legal responsibility and professional support.

OSTRAI does not assume the manufacturer’s non-delegable obligations through the Article 18 mandate, but can support the manufacturer in fulfilling them.

Explore Cyber Resilience Act Advisory

ARTICLE 18 + CRA ADVISORY

One provider.
Two distinct functions.

OSTRAI can support the same manufacturer in two legally distinct capacities.

As Article 18 Authorised Representative, OSTRAI performs the regulatory-interface functions contained in the written mandate.

Through OSTRAI’s broader Cyber Resilience Act advisory practice, we can also support the manufacturer with substantive CRA compliance work that remains legally the manufacturer’s responsibility.

ARTICLE 18

Authorised representative

  • Written mandate
  • EU regulatory interface
  • Regulatory-document custody
  • Market-surveillance communications
  • Information requests
  • Authority cooperation
  • Permitted conformity-interface functions
  • Escalation
  • Mandate management

CRA advisory & implementation support

  • CRA scope
  • Economic-operator analysis
  • Product classification
  • Cybersecurity risk assessment
  • Annex I compliance
  • Technical documentation
  • Component due diligence
  • Vulnerability handling
  • Support-period analysis
  • Conformity readiness
  • Article 14 reporting support
  • Standards
  • Regulatory response

The legal capacities remain distinct.

The manufacturer retains statutory responsibilities that cannot be delegated, while OSTRAI can nevertheless advise and support the manufacturer in fulfilling those responsibilities.

Explore Cyber Resilience Act Advisory

RESPONSIBILITY

Representation and CRA advisory are complementary functions.

OSTRAI can support the manufacturer both as Article 18 Authorised Representative and as CRA adviser.

The legal responsibilities remain allocated to the manufacturer where required by the Regulation.

Manufacturer

STATUTORY RESPONSIBILITY

  • CRA scope and status
  • Cybersecurity risk assessment
  • Product design & development
  • Annex I requirements
  • Component due diligence
  • SBOM / component documentation
  • Vulnerability handling
  • Support period
  • Security updates
  • Technical documentation
  • Conformity assessment
  • EU declaration of conformity
  • CE marking
  • Article 14 reporting
  • Corrective measures
  • Lifecycle compliance

OSTRAI

ARTICLE 18 REPRESENTATION

  • Written mandate
  • Regulatory-document custody
  • EU regulatory interface
  • Market-surveillance communications
  • Information-request coordination
  • Authority cooperation
  • Permitted conformity-interface functions
  • Escalation
  • Mandate maintenance
PLUS

OSTRAI

CRA ADVISORY & IMPLEMENTATION SUPPORT

  • Cybersecurity risk assessment support
  • Annex I gap assessment
  • Technical-documentation support
  • Product classification
  • Component due diligence
  • Vulnerability-handling framework
  • Support-period analysis
  • Conformity-readiness support
  • Article 14 reporting support
  • Standards analysis
  • Regulatory response

The manufacturer retains the statutory responsibility.

OSTRAI can nevertheless provide substantive advisory and implementation support in helping the manufacturer fulfil it.

ESSENTIAL CYBERSECURITY REQUIREMENTS

Representation sits alongside the product’s cybersecurity compliance architecture.

ANNEX I · PART I

Product properties

Risk-based requirements address secure design, configuration, access, data protection, resilience and security-update capability.

ANNEX I · PART II

Vulnerability handling

Requirements address component documentation, vulnerability identification and remediation, testing, coordinated disclosure and secure updates.

The substantive Annex I obligations remain the manufacturer’s statutory responsibility and are not transferred to OSTRAI through the Article 18 mandate.

OSTRAI can nevertheless support Annex I assessment, gap analysis, implementation planning, documentation and related CRA compliance work.

Explore Cyber Resilience Act Advisory

ARTICLE 13

The CRA is built
around actual product risk.

The manufacturer’s cybersecurity risk assessment informs the planning, design, development, production, delivery and maintenance of the product with digital elements.

The cybersecurity risk assessment remains the manufacturer’s statutory responsibility and cannot be transferred to OSTRAI through the Article 18 representative mandate.

OSTRAI can nevertheless support the manufacturer with the preparation, performance, structuring and review of the CRA cybersecurity risk assessment through its broader CRA advisory practice.

Get CRA compliance support

The assessment considers intended purpose and foreseeable use, operating environment, protected assets, product lifetime, components, dependencies and the threat landscape.

IMPORTANT & CRITICAL PRODUCTS

Classification changes
the conformity route.

Products fall into the default category, important Class I or Class II categories under Annex III, or critical categories under Annex IV. Classification affects the applicable conformity-assessment route.

The product’s core functionality drives classification.

Integrating an important or critical component into another product does not automatically make that wider product important or critical.

Classify your product

FROM PRODUCT TO MARKET

Cybersecurity compliance
becomes market-access evidence.

  1. CRA scope
  2. Product classification
  3. Cybersecurity risk assessment
  4. Annex I requirements
  5. Article 31 · Technical documentation
  6. Article 32 · Applicable conformity assessment
  7. Article 28 · EU declaration of conformity
  8. Article 30 · CE marking
  9. EU market

OSTRAI does not act as a notified body and does not perform third-party conformity assessment in its Article 18 representative capacity.

CONFORMITY ASSESSMENT SUPPORT

From CRA readiness to independent assessment.

The applicable conformity route depends on the product category, the relevant standards or specifications and, where applicable, the required level of independent third-party assessment.

OSTRAI can support the manufacturer in determining and preparing for the appropriate route.

Route assessment

Determine the applicable Article 32 conformity-assessment route for the product.

Readiness

Prepare and review the regulatory evidence supporting conformity, including technical documentation, cybersecurity risk assessment, Annex I mapping and relevant standards.

Third-party coordination

Where independent assessment is required or chosen, coordinate engagement with an appropriately scoped notified body or, where applicable, certification body.

Findings & remediation

Support the manufacturer in understanding questions, findings, evidence requests and regulatory remediation arising during the assessment process.

ARTICLE 18 / ARTICLE 31

A controlled EU interface
for conformity evidence.

MANUFACTURER CAPACITY

The manufacturer remains legally responsible for drawing up the Article 31 technical documentation.

CRA ADVISORY CAPACITY

OSTRAI can assist with preparation, structuring, review, gap analysis and conformity-readiness of the technical documentation.

ARTICLE 18 CAPACITY

Where appointed as authorised representative, OSTRAI can maintain the required documentation at the disposal of market-surveillance authorities and coordinate access within the representative mandate.

Discuss documentation readiness
  1. Manufacturer draws up / maintains technical documentation
  2. EU declaration of conformity
  3. OSTRAI receives controlled documentation set
  4. Secure documentation custody
  5. 10 YEARS OR SUPPORT PERIOD WHICHEVER IS LONGER
  6. Market-surveillance request
  7. Information & evidence coordination

LIVE SINCE 11 SEPTEMBER 2026

CRA reporting
already applies.

Article 14 applies before the CRA’s full application date.

Manufacturers must report relevant actively exploited vulnerabilities and severe incidents through the CRA reporting architecture.

  1. Actively exploited vulnerability
    OR
    Severe incident
  2. Article 14 assessment
  3. Single Reporting Platform
  4. CSIRT designated as coordinator
    +
    ENISA

Article 14 reporting remains the manufacturer’s statutory responsibility.

Through OSTRAI’s broader CRA advisory practice, we can nevertheless support the reporting workflow, including:

  • Assessment of whether a vulnerability is actively exploited
  • Assessment of whether an incident meets the relevant CRA threshold
  • Notification preparation
  • Reporting coordination
  • Regulatory communications
  • Follow-up information requests
  • Post-notification coordination

This work sits outside the core Article 18 statutory mandate unless expressly included in an appropriate additional service scope.

Discuss CRA reporting support

PRODUCT LIFECYCLE

CRA responsibility continues after market placement.

The Article 18 documentation-retention period is at least 10 years after the product has been placed on the market or for the support period, whichever is longer.

  1. Placement on market
  2. SUPPORT PERIOD

    • Cybersecurity monitoring
    • Vulnerability handling
    • Security updates
    • Risk-assessment updates
    • Product monitoring
    • Corrective action
  3. End of support

REGULATORY INTERFACE

A defined interface between
manufacturer and EU authorities.

Market surveillance authorities

OSTRAI

CRA ARTICLE 18 AUTHORISED REPRESENTATIVE

  • Regulatory contact
  • Mandate interface
  • Documentation availability
  • Information requests
  • Regulatory cooperation
  • Risk-elimination coordination
  • Escalation
  • Mandate management

Represented manufacturer

  • Product cybersecurity
  • Technical documentation
  • Risk assessment
  • Vulnerability handling
  • Support period
  • Conformity assessment
  • EU declaration of conformity
  • CE marking
  • Article 14 reporting
  • Corrective action

OSTRAI acts within the written mandate.

The Article 18 representative provides a defined EU interface but does not prevent authorities elsewhere in the Union or the European Commission from exercising their CRA powers.

YOUR REPRESENTATION SERVICE

A functioning CRA
representative structure.

CRA scope & representation assessment

Determine whether the relevant product falls within CRA scope and whether an Article 18 structure would add regulatory and operational value.

EU regulatory-anchor assessment

For manufacturers without a main establishment in the Union, assess the current Article 14(7) hierarchy and the effect of a future Article 18 appointment taking effect from 11 December 2027.

Formal Article 18 appointment

Written appointment of OSTRAI Limited as CRA Authorised Representative within the agreed mandate once Article 18 applies.

Mandate design

Define the products, product families and legally delegable CRA tasks covered by OSTRAI’s mandate.

Regulatory-document custody

Secure arrangements for the Article 28 EU declaration of conformity and Article 31 technical documentation.

Designated regulatory channel

A monitored OSTRAI channel for communications relating to the representative mandate.

Designated lead

A defined OSTRAI contact responsible for coordination of the representative relationship and material escalations.

Market-surveillance communications

Receipt and coordination of communications connected with OSTRAI’s Article 18 role.

Information-request coordination

Management of reasoned market-surveillance requests for conformity information and documentation.

Regulatory cooperation

Cooperation with market-surveillance authorities concerning products covered by the mandate.

Corrective-action interface

Coordination with the manufacturer where authorities require measures to eliminate product risks.

Permitted conformity-interface functions

Additional functions permitted under the CRA and expressly included in the written mandate.

Escalation protocol

Defined manufacturer contacts and procedures for urgent or material regulatory matters.

Mandate maintenance

Ongoing review of products, product families, support periods, documentation, EU market arrangements and mandate scope.

Product / portfolio coordination

Structure the Article 18 relationship around agreed products or product families, with defined documentation, contacts, support periods and escalation arrangements across the represented portfolio. Coverage remains defined by the written mandate.

Discuss the Article 18 mandate

CONTROLLED ACCEPTANCE

We assess the manufacturer
before appointment.

Before accepting an Article 18 mandate, OSTRAI reviews the manufacturer, relevant product or product family, CRA scope, manufacturer status, Union market structure, product classification, technical documentation, conformity-assessment route, EU declaration of conformity, vulnerability-handling framework, support-period arrangements, Article 14 reporting structure, regulatory history and operational readiness.

For manufacturers with no EU main establishment, OSTRAI also reviews:

  • The Article 14(7) reporting hierarchy
  • Existing authorised-representative arrangements
  • Importer structure
  • Distributor structure
  • Relevant product volumes
  • Relevant EU user footprint where necessary

Where product compliance, cybersecurity risk assessment, technical documentation, vulnerability handling, conformity readiness or other substantive CRA work is required, OSTRAI can support that work:

  • Before appointment;
  • During onboarding; or
  • Throughout the representative relationship.

Keeping the legal scopes distinct preserves the allocation of responsibilities required by the CRA while allowing OSTRAI to support the manufacturer across the wider compliance lifecycle.

The manufacturer’s compliance position, product structure and operational readiness determine whether OSTRAI can accept the mandate.

Discuss whether OSTRAI can accept the mandate

ONBOARDING

The information behind
an effective Article 18 mandate.

Manufacturer
Correct legal entity.
Country of establishment
Manufacturer jurisdiction.
EU main establishment
Whether the manufacturer has a main establishment in the Union and, where relevant, how it is determined.
Article 14 reporting nexus
Current Article 14(7) position.
Authorised representative structure
Existing or proposed representative arrangements.
Importer structure
Relevant EU importers and approximate product volumes.
Distributor structure
Relevant EU distribution arrangements.
EU user footprint
Where relevant to Article 14(7).
Product / product family
Products to be covered by the mandate.
Product type
Software · hardware · component · combined product.
Remote data processing
Relevant remote functions.
Intended purpose
Product purpose and deployment context.
Reasonably foreseeable use
Relevant expected uses and interactions.
CRA scope
Article 2 analysis.
Product classification
Default · important Class I · important Class II · critical.
Cybersecurity risk assessment
Status, version and owner.
Annex I compliance
Relevant essential-requirement position.
Technical documentation
Article 31 / Annex VII status.
Conformity route
Article 32 assessment.
EU declaration of conformity
Article 28 status.
CE marking
Article 30 status.
Notified body
Where applicable.
Support period
Duration and rationale.
Vulnerability handling
CVD · remediation · updates · testing · SBOM.
Article 14 reporting
Current procedures and reporting contacts.
Regulatory history
Market surveillance · ENISA · CSIRT · notified-body interactions where relevant.
Internal contacts
Legal · regulatory · cybersecurity · engineering · product · quality · compliance.
Escalation
Named urgent and executive contacts.
Start CRA Representative onboarding

OPERATIONAL READINESS

The representative needs access to the organisation behind the product.

Effective Article 18 representation depends on OSTRAI being able to obtain accurate conformity information, documentation and instructions when regulatory issues arise.

  • Legal / regulatory
  • Cybersecurity
  • Product
  • Engineering
  • Quality / conformity
  • Vulnerability management
  • Security updates
  • Incident response
  • Supply-chain / component management
  • Executive escalation
  • Notified-body contact where applicable

OSTRAICRA ARTICLE 18 AUTHORISED REPRESENTATIVE

TRANSITION

Products already on the market require a different analysis.

Products with digital elements placed on the market before 11 December 2027 are generally subject to the CRA requirements only where they undergo a substantial modification from that date.

Article 14 reporting follows a separate rule and already applies to in-scope products.

Assess an existing product
  1. Product placed on market before 11 December 2027
  2. Substantial modification on or after that date?

    NO →General CRA product requirements are not triggered solely on that basis.
    YES →Assess CRA compliance for the modified product.

PRODUCT CHANGE

Not every update creates
a new compliance event.

Security updates solely reducing cybersecurity risk without changing intended purpose or introducing new risks, and minor functionality changes that do not alter purpose or materially change risk, are generally not substantial modifications.

Changes to intended purpose, new or increased cybersecurity risks, or changes affecting Annex I conformity may be substantial.

Substantial-modification analysis is product-specific and should not be reduced to whether an update is technically large or small.

Assess a product modification

CROSS-REGULATORY PRODUCT COMPLIANCE

One product can sit inside
several EU regulatory frameworks.

Relevant intersections may include the AI Act, Machinery Regulation, Radio Equipment Directive, General Product Safety Regulation, Data Act, GDPR, European Health Data Space, Product Liability Directive and NIS2 supply-chain requirements.

CRA compliance does not necessarily replace obligations arising under other applicable EU product, cybersecurity, digital or data legislation.

OSTRAI’s broader regulatory practice can support cross-regulatory analysis.

Explore Cyber Resilience Act Advisory

STANDARDS

Standards can support conformity. They do not replace the risk assessment.

Where applicable harmonised standards whose references are published in the Official Journal cover relevant CRA requirements, their correct application can support a presumption of conformity.

The manufacturer remains responsible for:

Identifying product risks and applicable requirements, assessing standards coverage, implementing any additional measures and documenting the conformity position.

CYBERSECURITY & PRODUCT REGULATION

Representation backed
by substantive CRA capability.

OSTRAI’s Article 18 Authorised Representative service sits within a broader Cyber Resilience Act, cybersecurity and EU product-regulation practice.

The distinction between representative and manufacturer obligations does not prevent OSTRAI from supporting both sides of the compliance architecture.

Within the Article 18 mandate, OSTRAI performs the regulatory-interface and authorised-representative functions permitted by the CRA.

Through our broader CRA advisory practice, OSTRAI can also support manufacturers with:

  • CRA scope
  • Economic-operator analysis
  • Product classification
  • Cybersecurity risk assessment
  • Annex I compliance
  • Technical documentation
  • Component due diligence
  • Vulnerability handling
  • Article 14 reporting
  • Conformity assessment
  • Notified-body / certification-body coordination
  • Standards
  • Substantial modification
  • Regulatory response

This allows a manufacturer to maintain one coordinated regulatory relationship while preserving the legal allocation of responsibilities required by the CRA.

WHY OSTRAI

Why OSTRAI for CRA Article 18 representation

Article 18 focus

A representative structure designed around the actual statutory mandate.

EU regulatory anchor

A defined EU interface for manufacturers operating across the Union, including manufacturers with no main establishment in the EU.

Cybersecurity-regulatory capability

Authority communications understood within the wider CRA cybersecurity framework.

Product-regulation architecture

Understanding of conformity, documentation and market-surveillance structures.

Controlled acceptance

Mandates reviewed against product scope, conformity evidence, reporting architecture and operational readiness before appointment.

Standards perspective

Understanding of harmonised standards, conformity evidence and cybersecurity standardisation.

QUESTIONS & ANSWERS

Before
appointment.

No.

Article 18 provides that a manufacturer may appoint an authorised representative by written mandate. Appointment is not automatically mandatory because the manufacturer is established outside the Union.

Yes.

Article 18 is not restricted to third-country manufacturers.

Within the European Union.

Appointment can provide a defined EU regulatory interface for documentation, market-surveillance communications and legally delegable CRA functions.

From 11 December 2027, once Article 18 applies, the relevant authorised representative can also sit first in the Article 14(7) hierarchy used to determine the Member State reporting endpoint.

No.

From 11 December 2027, where Article 14(7)(a) applies, the establishment of the relevant authorised representative can determine the Member State used for the initial Article 14 reporting endpoint.

It does not create exclusive jurisdiction or restrict the powers of other Member State market-surveillance authorities, relevant CSIRTs, ENISA or the European Commission.

Article 18 does not require appointment.

Where a manufacturer has no main establishment in the Union, Article 14(7) determines the reporting Member State through its statutory hierarchy: authorised representative, importer, distributor and, ultimately, user location.

For the Article 14(7) hierarchy, the CRA refers to the Member State of the authorised representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements.

No.

The authorised representative and importer are separate CRA economic-operator roles with different statutory functions and obligations.

Yes.

The existence of an importer does not prevent the manufacturer from appointing a separate Article 18 authorised representative.

The mandate must at least allow the representative to keep the EU declaration of conformity and technical documentation available to market-surveillance authorities, respond to reasoned authority requests and cooperate with authorities on actions taken to eliminate product risks.

Potentially yes.

Additional CRA functions may be included where the Regulation permits delegation and the function is expressly included in the written mandate.

Article 18 expressly excludes the obligations in Article 13(1)–(11), Article 13(12) first subparagraph and Article 13(14) from the representative mandate.

That does not prevent OSTRAI from separately advising or supporting the manufacturer in fulfilling those obligations. The manufacturer retains the underlying statutory responsibility.

At least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.

OSTRAI does not itself act as a notified body or independent certification body and does not issue certificates reserved to those independent assessment or certification functions.

We can, however, support the manufacturer throughout the conformity-assessment process, including identifying the applicable conformity route; conformity-readiness assessment; cybersecurity risk assessment support; preparation and review of technical documentation; Annex I and standards mapping; coordination of evidence and testing; engagement with an appropriately scoped notified body or, where applicable, certification body; coordination of questions and findings; and remediation support.

OSTRAI maintains professional relationships with relevant conformity-assessment and certification organisations and can coordinate appropriate independent third-party assessment where required.

The independent assessment and any certificate remain the responsibility of the relevant independent body.

Yes.

Article 14 applies from 11 September 2026.

Yes.

Incident and vulnerability assessment, reporting preparation and regulatory coordination can be separately scoped from the standard Article 18 mandate.

Article 14 reporting remains the manufacturer’s statutory responsibility.

OSTRAI can provide support and coordination under an additional CRA service scope where appropriate.

Yes.

OSTRAI’s broader Cyber Resilience Act Advisory service can support scope, product classification, cybersecurity risk assessment, technical documentation, conformity readiness, vulnerability handling, reporting, standards and regulatory response.

Explore Cyber Resilience Act Advisory

The CRA applies in full from 11 December 2027.

The CRA contains transitional rules.

Products already placed on the market generally become subject to the broader CRA product requirements where they undergo a substantial modification from the full application date.

Article 14 reporting follows its separate rule and already applies.

Potentially.

The mandate should clearly identify the relevant products or product families and the functions delegated to OSTRAI.

Yes.

Article 18 determines which legal responsibilities may form part of the authorised-representative mandate.

It does not prevent OSTRAI from advising or supporting the manufacturer in fulfilling obligations that remain legally with the manufacturer.

Yes.

The two capacities are legally distinct.

OSTRAI can act under the Article 18 representative mandate while also supporting the manufacturer through its broader CRA advisory practice.

The manufacturer continues to retain responsibility for obligations that the CRA does not permit it to transfer.

Yes.

OSTRAI can support the preparation, performance, structuring and review of the CRA cybersecurity risk assessment through its broader CRA advisory practice.

The statutory responsibility remains with the manufacturer and is not transferred through the Article 18 mandate.

Yes.

OSTRAI can support preparation, structuring and review of Article 31 technical documentation.

The manufacturer remains legally responsible for drawing up the documentation.

Where OSTRAI is also appointed as Article 18 Authorised Representative, OSTRAI can then maintain the required documentation for market-surveillance purposes within the representative mandate.

Yes.

The underlying legal obligations remain with the manufacturer, but OSTRAI can support vulnerability assessment, reporting preparation, regulatory coordination and post-notification follow-up through its broader CRA advisory practice.

Yes.

OSTRAI can support the process from conformity-route analysis and readiness through documentation, standards mapping, independent-body coordination, assessment questions and remediation.

Where independent third-party assessment or certification is required, the assessment itself is performed by the relevant notified body or, where applicable, certification body.

EU CYBER RESILIENCE ACT AUTHORISED REPRESENTATIVE

Establish a defined
EU regulatory interface.

OSTRAI supports manufacturers with Article 18 representation and the wider CRA compliance work behind the mandate.

From regulatory-anchor and reporting-nexus analysis to mandate design, documentation, market-surveillance interaction and continuing representation, OSTRAI provides a structured EU interface.

Our broader CRA practice can also support scope, cybersecurity risk assessment, Annex I compliance, technical documentation, vulnerability handling, conformity assessment, independent-body coordination, reporting and regulatory response.