Defined EU regulatory anchor
Establish a deliberate EU-based representative structure for CRA regulatory interaction rather than relying solely on changing importer, distributor or user-location arrangements.
EU CYBER RESILIENCE ACT
Article 18 representation for manufacturers of products with digital elements that choose to establish a defined EU regulatory interface under the Cyber Resilience Act.
OSTRAI supports manufacturers preparing for Article 18 representation and will act as EU-established Cyber Resilience Act Authorised Representative under defined written mandates from 11 December 2027.
Our service combines Article 18 representation, regulatory-documentation arrangements, market-surveillance communications, authority cooperation and a structured EU regulatory interface, backed by broader Cyber Resilience Act advisory capability.
No main establishment in the Union? From 11 December 2027, an Article 18 appointment can also provide a defined EU regulatory anchor for CRA reporting and regulatory coordination.
Explore Cyber Resilience Act AdvisoryARTICLE 18
The Cyber Resilience Act does not require every manufacturer, including every manufacturer established outside the Union, to appoint an authorised representative.
Article 18 allows a manufacturer to appoint an EU-established authorised representative by written mandate.
The manufacturer chooses whether to establish an Article 18 representative structure.
The authorised representative performs the tasks specified in the written mandate and must be empowered to carry out the minimum functions required by Article 18.
A CRA authorised representative must be established within the European Union. The manufacturer itself may be established inside or outside the Union.
Discuss whether Article 18 is useful for your structureWHY ARTICLE 18?
Article 18 appointment is voluntary. For manufacturers operating across the Union, particularly manufacturers with no main establishment in the EU, it can nevertheless create a more controlled, predictable and operationally coherent regulatory structure.
Establish a deliberate EU-based representative structure for CRA regulatory interaction rather than relying solely on changing importer, distributor or user-location arrangements.
From 11 December 2027, where a manufacturer has no main establishment in the Union, the relevant Article 18 authorised representative can become the first reference point in the Article 14(7) hierarchy used to determine the reporting endpoint.
Route CRA documentation requests and market-surveillance communications through a defined representative familiar with the manufacturer, its products and its conformity structure.
Maintain a stable regulatory interface even where importers, distributors, sales channels or product-market arrangements change.
Use the representative for the Article 18 documentation role and, where legally permitted and included in the mandate, additional conformity-related functions on the manufacturer’s behalf.
Structure the representative relationship around agreed products or product families and maintain a consistent regulatory interface across the manufacturer’s represented EU portfolio.
FOR MANUFACTURERS WITHOUT AN EU MAIN ESTABLISHMENT
From 11 December 2027, the relevant Article 18 authorised representative can become the first reference point ahead of the importer, distributor and user-location fallbacks in the Article 14(7) reporting hierarchy.
It therefore allows the manufacturer to structure its initial EU reporting interface deliberately rather than allowing that structure to arise incidentally from its distribution footprint.
ARTICLE 14(7)
For Article 14 reporting, the CRA first looks to the Member State of the manufacturer’s main establishment in the Union.
Where the manufacturer has no main establishment in the Union, the relevant reporting Member State is determined through the following statutory order.
WHY THIS MATTERS
Without an authorised representative, a third-country manufacturer’s reporting nexus may depend on its importer, distributor or user footprint.
Once Article 18 applies, an appropriate representative structure makes the authorised representative the first reference point in the statutory hierarchy.
The Member State where the authorised representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements is established.
The Member State where the importer placing the highest number of the manufacturer’s products with digital elements on the market is established.
The Member State where the distributor making available the highest number of the manufacturer’s products with digital elements is established.
The Member State in which the highest number of users of the manufacturer’s products with digital elements is located.
Where a manufacturer has several authorised representatives, Article 14(7) refers to the representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements.
CURRENT APPLICATION
Chapter IV applies.
Article 14 manufacturer reporting obligations apply.
The CRA applies in full, including Article 18.
OSTRAI can support manufacturers now with Article 14 reporting, CRA readiness and preparation of future Article 18 representative structures.
The current Article 14(7) reporting structure must be assessed against the manufacturer’s existing EU arrangements. Preparing a future Article 18 appointment does not automatically change the current reporting nexus before Article 18 applies on 11 December 2027.
Prepare for CRA applicationCRA / SCOPE
This can include software, hardware and relevant remote data processing.
If yes
CRA does not apply on this basis.
If yes
No CRA market-placement trigger on this basis.
If yes
Outside the general Article 2(1) scope.
If no
Assess the relevant exclusion or sector-specific regime.
Article 18 appointment is voluntary. CRA scope and representation are separate assessments.
PRODUCT SCOPE
Products with digital elements can include standalone software, hardware and combined hardware/software products. Remote data processing can form part of the product where it is designed and developed by, or under the responsibility of, the manufacturer and its absence would prevent a product function.
Standalone SaaS or cloud services are not products with digital elements merely because they are remotely accessed.
The product architecture and remote-data-processing relationship must be assessed.
Explore CRA AdvisoryECONOMIC OPERATOR
The manufacturer is the natural or legal person that develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark.
Manufacturer, authorised representative, importer and distributor are distinct legal roles under the CRA.
Assess your CRA roleDIFFERENT EU ROLES
ARTICLE 18
ARTICLE 19
A manufacturer may have both an importer and an authorised representative. The two roles are legally distinct.
Appointment of OSTRAI does not remove the obligations of an importer where an importer exists.
Map your EU market structureARTICLE 18 MANDATE
The authorised representative performs the tasks specified in the written mandate.
Article 18 requires the mandate to allow the representative to perform at least the following functions.
Keep at the disposal of market-surveillance authorities:
Following a reasoned request from a market-surveillance authority, provide all information and documentation necessary to demonstrate conformity of the product with digital elements.
Cooperate with market-surveillance authorities, at their request, on actions taken to eliminate risks posed by products covered by the mandate.
Provide a copy of the written mandate to market-surveillance authorities upon request.
DELEGABLE FUNCTIONS
The written mandate may include additional CRA functions where the Regulation permits those functions to be performed by an authorised representative.
Examples may include, depending on the applicable conformity route and the terms of the mandate:
The scope must be assessed against the applicable CRA provisions and conformity route.
Design the Article 18 mandateSTATUTORY LIMITS
Article 18 expressly prevents specified Article 13 obligations from being transferred to the authorised representative through the representative mandate.
That does not prevent OSTRAI from separately advising or supporting the manufacturer in fulfilling those obligations.
REMAINS THE MANUFACTURER’S LEGAL RESPONSIBILITY
Including core manufacturer responsibilities concerning, among other matters:
Drawing up the Article 31 technical documentation before placing the product on the market.
Procedures ensuring products forming part of a series remain in conformity.
OSTRAI CAN STILL SUPPORT
Through OSTRAI’s CRA advisory practice, we can assist with:
The manufacturer retains the underlying statutory responsibility.
The distinction is between legal responsibility and professional support.
OSTRAI does not assume the manufacturer’s non-delegable obligations through the Article 18 mandate, but can support the manufacturer in fulfilling them.
ARTICLE 18 + CRA ADVISORY
OSTRAI can support the same manufacturer in two legally distinct capacities.
As Article 18 Authorised Representative, OSTRAI performs the regulatory-interface functions contained in the written mandate.
Through OSTRAI’s broader Cyber Resilience Act advisory practice, we can also support the manufacturer with substantive CRA compliance work that remains legally the manufacturer’s responsibility.
ARTICLE 18
The legal capacities remain distinct.
The manufacturer retains statutory responsibilities that cannot be delegated, while OSTRAI can nevertheless advise and support the manufacturer in fulfilling those responsibilities.
RESPONSIBILITY
OSTRAI can support the manufacturer both as Article 18 Authorised Representative and as CRA adviser.
The legal responsibilities remain allocated to the manufacturer where required by the Regulation.
STATUTORY RESPONSIBILITY
ARTICLE 18 REPRESENTATION
CRA ADVISORY & IMPLEMENTATION SUPPORT
The manufacturer retains the statutory responsibility.
OSTRAI can nevertheless provide substantive advisory and implementation support in helping the manufacturer fulfil it.
ESSENTIAL CYBERSECURITY REQUIREMENTS
ANNEX I · PART I
Risk-based requirements address secure design, configuration, access, data protection, resilience and security-update capability.
ANNEX I · PART II
Requirements address component documentation, vulnerability identification and remediation, testing, coordinated disclosure and secure updates.
The substantive Annex I obligations remain the manufacturer’s statutory responsibility and are not transferred to OSTRAI through the Article 18 mandate.
OSTRAI can nevertheless support Annex I assessment, gap analysis, implementation planning, documentation and related CRA compliance work.
Explore Cyber Resilience Act AdvisoryARTICLE 13
The manufacturer’s cybersecurity risk assessment informs the planning, design, development, production, delivery and maintenance of the product with digital elements.
The cybersecurity risk assessment remains the manufacturer’s statutory responsibility and cannot be transferred to OSTRAI through the Article 18 representative mandate.
OSTRAI can nevertheless support the manufacturer with the preparation, performance, structuring and review of the CRA cybersecurity risk assessment through its broader CRA advisory practice.
Get CRA compliance supportThe assessment considers intended purpose and foreseeable use, operating environment, protected assets, product lifetime, components, dependencies and the threat landscape.
IMPORTANT & CRITICAL PRODUCTS
Products fall into the default category, important Class I or Class II categories under Annex III, or critical categories under Annex IV. Classification affects the applicable conformity-assessment route.
The product’s core functionality drives classification.
Integrating an important or critical component into another product does not automatically make that wider product important or critical.
Classify your productFROM PRODUCT TO MARKET
OSTRAI does not act as a notified body and does not perform third-party conformity assessment in its Article 18 representative capacity.
CONFORMITY ASSESSMENT SUPPORT
The applicable conformity route depends on the product category, the relevant standards or specifications and, where applicable, the required level of independent third-party assessment.
OSTRAI can support the manufacturer in determining and preparing for the appropriate route.
Determine the applicable Article 32 conformity-assessment route for the product.
Prepare and review the regulatory evidence supporting conformity, including technical documentation, cybersecurity risk assessment, Annex I mapping and relevant standards.
Where independent assessment is required or chosen, coordinate engagement with an appropriately scoped notified body or, where applicable, certification body.
Support the manufacturer in understanding questions, findings, evidence requests and regulatory remediation arising during the assessment process.
ARTICLE 18 / ARTICLE 31
MANUFACTURER CAPACITY
The manufacturer remains legally responsible for drawing up the Article 31 technical documentation.
CRA ADVISORY CAPACITY
OSTRAI can assist with preparation, structuring, review, gap analysis and conformity-readiness of the technical documentation.
ARTICLE 18 CAPACITY
Where appointed as authorised representative, OSTRAI can maintain the required documentation at the disposal of market-surveillance authorities and coordinate access within the representative mandate.
LIVE SINCE 11 SEPTEMBER 2026
Article 14 applies before the CRA’s full application date.
Manufacturers must report relevant actively exploited vulnerabilities and severe incidents through the CRA reporting architecture.
Article 14 reporting remains the manufacturer’s statutory responsibility.
Through OSTRAI’s broader CRA advisory practice, we can nevertheless support the reporting workflow, including:
This work sits outside the core Article 18 statutory mandate unless expressly included in an appropriate additional service scope.
PRODUCT LIFECYCLE
The Article 18 documentation-retention period is at least 10 years after the product has been placed on the market or for the support period, whichever is longer.
SUPPORT PERIOD
REGULATORY INTERFACE
CRA ARTICLE 18 AUTHORISED REPRESENTATIVE
OSTRAI acts within the written mandate.
The Article 18 representative provides a defined EU interface but does not prevent authorities elsewhere in the Union or the European Commission from exercising their CRA powers.
YOUR REPRESENTATION SERVICE
Determine whether the relevant product falls within CRA scope and whether an Article 18 structure would add regulatory and operational value.
For manufacturers without a main establishment in the Union, assess the current Article 14(7) hierarchy and the effect of a future Article 18 appointment taking effect from 11 December 2027.
Written appointment of OSTRAI Limited as CRA Authorised Representative within the agreed mandate once Article 18 applies.
Define the products, product families and legally delegable CRA tasks covered by OSTRAI’s mandate.
Secure arrangements for the Article 28 EU declaration of conformity and Article 31 technical documentation.
A monitored OSTRAI channel for communications relating to the representative mandate.
A defined OSTRAI contact responsible for coordination of the representative relationship and material escalations.
Receipt and coordination of communications connected with OSTRAI’s Article 18 role.
Management of reasoned market-surveillance requests for conformity information and documentation.
Cooperation with market-surveillance authorities concerning products covered by the mandate.
Coordination with the manufacturer where authorities require measures to eliminate product risks.
Additional functions permitted under the CRA and expressly included in the written mandate.
Defined manufacturer contacts and procedures for urgent or material regulatory matters.
Ongoing review of products, product families, support periods, documentation, EU market arrangements and mandate scope.
Structure the Article 18 relationship around agreed products or product families, with defined documentation, contacts, support periods and escalation arrangements across the represented portfolio. Coverage remains defined by the written mandate.
CONTROLLED ACCEPTANCE
Before accepting an Article 18 mandate, OSTRAI reviews the manufacturer, relevant product or product family, CRA scope, manufacturer status, Union market structure, product classification, technical documentation, conformity-assessment route, EU declaration of conformity, vulnerability-handling framework, support-period arrangements, Article 14 reporting structure, regulatory history and operational readiness.
For manufacturers with no EU main establishment, OSTRAI also reviews:
Where product compliance, cybersecurity risk assessment, technical documentation, vulnerability handling, conformity readiness or other substantive CRA work is required, OSTRAI can support that work:
Keeping the legal scopes distinct preserves the allocation of responsibilities required by the CRA while allowing OSTRAI to support the manufacturer across the wider compliance lifecycle.
The manufacturer’s compliance position, product structure and operational readiness determine whether OSTRAI can accept the mandate.
Discuss whether OSTRAI can accept the mandateONBOARDING
OPERATIONAL READINESS
Effective Article 18 representation depends on OSTRAI being able to obtain accurate conformity information, documentation and instructions when regulatory issues arise.
OSTRAICRA ARTICLE 18 AUTHORISED REPRESENTATIVE
TRANSITION
Products with digital elements placed on the market before 11 December 2027 are generally subject to the CRA requirements only where they undergo a substantial modification from that date.
Article 14 reporting follows a separate rule and already applies to in-scope products.
Assess an existing productPRODUCT CHANGE
Security updates solely reducing cybersecurity risk without changing intended purpose or introducing new risks, and minor functionality changes that do not alter purpose or materially change risk, are generally not substantial modifications.
Changes to intended purpose, new or increased cybersecurity risks, or changes affecting Annex I conformity may be substantial.
Substantial-modification analysis is product-specific and should not be reduced to whether an update is technically large or small.
Assess a product modificationCROSS-REGULATORY PRODUCT COMPLIANCE
Relevant intersections may include the AI Act, Machinery Regulation, Radio Equipment Directive, General Product Safety Regulation, Data Act, GDPR, European Health Data Space, Product Liability Directive and NIS2 supply-chain requirements.
CRA compliance does not necessarily replace obligations arising under other applicable EU product, cybersecurity, digital or data legislation.
OSTRAI’s broader regulatory practice can support cross-regulatory analysis.
Explore Cyber Resilience Act AdvisorySTANDARDS
Where applicable harmonised standards whose references are published in the Official Journal cover relevant CRA requirements, their correct application can support a presumption of conformity.
The manufacturer remains responsible for:
Identifying product risks and applicable requirements, assessing standards coverage, implementing any additional measures and documenting the conformity position.
CYBERSECURITY & PRODUCT REGULATION
OSTRAI’s Article 18 Authorised Representative service sits within a broader Cyber Resilience Act, cybersecurity and EU product-regulation practice.
The distinction between representative and manufacturer obligations does not prevent OSTRAI from supporting both sides of the compliance architecture.
Within the Article 18 mandate, OSTRAI performs the regulatory-interface and authorised-representative functions permitted by the CRA.
Through our broader CRA advisory practice, OSTRAI can also support manufacturers with:
This allows a manufacturer to maintain one coordinated regulatory relationship while preserving the legal allocation of responsibilities required by the CRA.
WHY OSTRAI
A representative structure designed around the actual statutory mandate.
A defined EU interface for manufacturers operating across the Union, including manufacturers with no main establishment in the EU.
Authority communications understood within the wider CRA cybersecurity framework.
Understanding of conformity, documentation and market-surveillance structures.
Mandates reviewed against product scope, conformity evidence, reporting architecture and operational readiness before appointment.
Understanding of harmonised standards, conformity evidence and cybersecurity standardisation.
QUESTIONS & ANSWERS
No.
Article 18 provides that a manufacturer may appoint an authorised representative by written mandate. Appointment is not automatically mandatory because the manufacturer is established outside the Union.
Yes.
Article 18 is not restricted to third-country manufacturers.
Within the European Union.
Appointment can provide a defined EU regulatory interface for documentation, market-surveillance communications and legally delegable CRA functions.
From 11 December 2027, once Article 18 applies, the relevant authorised representative can also sit first in the Article 14(7) hierarchy used to determine the Member State reporting endpoint.
No.
From 11 December 2027, where Article 14(7)(a) applies, the establishment of the relevant authorised representative can determine the Member State used for the initial Article 14 reporting endpoint.
It does not create exclusive jurisdiction or restrict the powers of other Member State market-surveillance authorities, relevant CSIRTs, ENISA or the European Commission.
Article 18 does not require appointment.
Where a manufacturer has no main establishment in the Union, Article 14(7) determines the reporting Member State through its statutory hierarchy: authorised representative, importer, distributor and, ultimately, user location.
For the Article 14(7) hierarchy, the CRA refers to the Member State of the authorised representative acting on behalf of the manufacturer for the highest number of that manufacturer’s products with digital elements.
No.
The authorised representative and importer are separate CRA economic-operator roles with different statutory functions and obligations.
Yes.
The existence of an importer does not prevent the manufacturer from appointing a separate Article 18 authorised representative.
The mandate must at least allow the representative to keep the EU declaration of conformity and technical documentation available to market-surveillance authorities, respond to reasoned authority requests and cooperate with authorities on actions taken to eliminate product risks.
Potentially yes.
Additional CRA functions may be included where the Regulation permits delegation and the function is expressly included in the written mandate.
Article 18 expressly excludes the obligations in Article 13(1)–(11), Article 13(12) first subparagraph and Article 13(14) from the representative mandate.
That does not prevent OSTRAI from separately advising or supporting the manufacturer in fulfilling those obligations. The manufacturer retains the underlying statutory responsibility.
At least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.
OSTRAI does not itself act as a notified body or independent certification body and does not issue certificates reserved to those independent assessment or certification functions.
We can, however, support the manufacturer throughout the conformity-assessment process, including identifying the applicable conformity route; conformity-readiness assessment; cybersecurity risk assessment support; preparation and review of technical documentation; Annex I and standards mapping; coordination of evidence and testing; engagement with an appropriately scoped notified body or, where applicable, certification body; coordination of questions and findings; and remediation support.
OSTRAI maintains professional relationships with relevant conformity-assessment and certification organisations and can coordinate appropriate independent third-party assessment where required.
The independent assessment and any certificate remain the responsibility of the relevant independent body.
Yes.
Article 14 applies from 11 September 2026.
Yes.
Incident and vulnerability assessment, reporting preparation and regulatory coordination can be separately scoped from the standard Article 18 mandate.
Article 14 reporting remains the manufacturer’s statutory responsibility.
OSTRAI can provide support and coordination under an additional CRA service scope where appropriate.
Yes.
OSTRAI’s broader Cyber Resilience Act Advisory service can support scope, product classification, cybersecurity risk assessment, technical documentation, conformity readiness, vulnerability handling, reporting, standards and regulatory response.
Explore Cyber Resilience Act AdvisoryThe CRA applies in full from 11 December 2027.
The CRA contains transitional rules.
Products already placed on the market generally become subject to the broader CRA product requirements where they undergo a substantial modification from the full application date.
Article 14 reporting follows its separate rule and already applies.
Potentially.
The mandate should clearly identify the relevant products or product families and the functions delegated to OSTRAI.
Yes.
Article 18 determines which legal responsibilities may form part of the authorised-representative mandate.
It does not prevent OSTRAI from advising or supporting the manufacturer in fulfilling obligations that remain legally with the manufacturer.
Yes.
The two capacities are legally distinct.
OSTRAI can act under the Article 18 representative mandate while also supporting the manufacturer through its broader CRA advisory practice.
The manufacturer continues to retain responsibility for obligations that the CRA does not permit it to transfer.
Yes.
OSTRAI can support the preparation, performance, structuring and review of the CRA cybersecurity risk assessment through its broader CRA advisory practice.
The statutory responsibility remains with the manufacturer and is not transferred through the Article 18 mandate.
Yes.
OSTRAI can support preparation, structuring and review of Article 31 technical documentation.
The manufacturer remains legally responsible for drawing up the documentation.
Where OSTRAI is also appointed as Article 18 Authorised Representative, OSTRAI can then maintain the required documentation for market-surveillance purposes within the representative mandate.
Yes.
The underlying legal obligations remain with the manufacturer, but OSTRAI can support vulnerability assessment, reporting preparation, regulatory coordination and post-notification follow-up through its broader CRA advisory practice.
Yes.
OSTRAI can support the process from conformity-route analysis and readiness through documentation, standards mapping, independent-body coordination, assessment questions and remediation.
Where independent third-party assessment or certification is required, the assessment itself is performed by the relevant notified body or, where applicable, certification body.
EU CYBER RESILIENCE ACT AUTHORISED REPRESENTATIVE
OSTRAI supports manufacturers with Article 18 representation and the wider CRA compliance work behind the mandate.
From regulatory-anchor and reporting-nexus analysis to mandate design, documentation, market-surveillance interaction and continuing representation, OSTRAI provides a structured EU interface.
Our broader CRA practice can also support scope, cybersecurity risk assessment, Annex I compliance, technical documentation, vulnerability handling, conformity assessment, independent-body coordination, reporting and regulatory response.