Manufacturers outside the EU may appoint an EU-based authorised representative under the Cyber Resilience Act — it is voluntary, not mandatory. CRA-Portal acts as your representative — backed by a real compliance platform.
From 11 December 2027 — from that date manufacturers outside the EU can appoint an EU authorised representative as a single point of contact that keeps the CRA documentation for 10 years and responds to market surveillance authorities. Reporting duties already apply from 11 September 2026. CRA-Portal is your preferred EU authorised representative: mandate plus compliance platform in one.
Book an intro callUnder Article 18 of the CRA, a manufacturer established outside the EU appoints an EU-based authorised representative through a written mandate. We become your point of contact for EU market surveillance authorities. You remain responsible for your product's conformity; we handle the EU-facing obligations on your behalf.
If you manufacture products with digital elements outside the EU and place them on the EU market, you may voluntarily appoint an EU authorised representative under Article 18 CRA — it is optional, not a legal requirement. This covers connected hardware and software — from industrial systems to consumer devices.
We keep your EU Declaration of Conformity and technical documentation available to market surveillance authorities for the statutory period — 10 years or the support period, whichever is longer.
On a reasoned request, we provide authorities with all information and documentation needed to demonstrate your product's conformity.
We cooperate with authorities on any action to eliminate risks posed by the products covered under the mandate.
Unlike a mailbox address, CRA-Portal combines the legal representative role with a secure platform that stores your technical documentation, declarations, SBOMs and incident records — auditable, retained for the full period, and instantly retrievable when an authority asks.
Your documentation stored, versioned and retained for the full statutory period.
A defined process and SLA for responding to reasoned requests, with a complete audit trail.
Your representative's name and address, ready to appear on your product and documentation.
As your authorised representative we hold your conformity documentation — which may contain trade secrets — for the statutory period. Here is how we keep it secure.
Application and database are hosted in the EU (Germany), within the EU/EEA.
Sensitive data is encrypted with AES-256 at rest and all connections use TLS. Passwords are stored only as salted one-way hashes.
Role-based access — each client sees only its own data — with a complete audit trail of authority requests and a tamper-evident 10-year retention lock on statutory documents.
GDPR-compliant with a Data Processing Agreement; a confidentiality clause in every mandate and an NDA on request. Our practices follow the principles of ISO/IEC 27001.
Beyond representation, we make Article 14 reporting actually work: a self-service builder for your 24h/72h reporting process — RACI, workflow, SOP and evidence checklist — plus a tabletop drill to rehearse it under pressure.
Tell us about your products and we'll propose a mandate and terms tailored to your situation.
Contact us