CRA Article 18

Your EU Authorised Representative under the CRA

Manufacturers outside the EU may appoint an EU-based authorised representative under the Cyber Resilience Act — it is voluntary, not mandatory. CRA-Portal acts as your representative — backed by a real compliance platform.

From 11 December 2027 — from that date manufacturers outside the EU can appoint an EU authorised representative as a single point of contact that keeps the CRA documentation for 10 years and responds to market surveillance authorities. Reporting duties already apply from 11 September 2026. CRA-Portal is your preferred EU authorised representative: mandate plus compliance platform in one.

Book an intro call

What an authorised representative does

Under Article 18 of the CRA, a manufacturer established outside the EU appoints an EU-based authorised representative through a written mandate. We become your point of contact for EU market surveillance authorities. You remain responsible for your product's conformity; we handle the EU-facing obligations on your behalf.

EU representation

Do you need an authorised representative?

If you manufacture products with digital elements outside the EU and place them on the EU market, you may voluntarily appoint an EU authorised representative under Article 18 CRA — it is optional, not a legal requirement. This covers connected hardware and software — from industrial systems to consumer devices.

The Article 18(3) tasks we cover

Retain documentation

We keep your EU Declaration of Conformity and technical documentation available to market surveillance authorities for the statutory period — 10 years or the support period, whichever is longer.

Respond to authorities

On a reasoned request, we provide authorities with all information and documentation needed to demonstrate your product's conformity.

Cooperate on risk

We cooperate with authorities on any action to eliminate risks posed by the products covered under the mandate.

Representation backed by a compliance platform

Unlike a mailbox address, CRA-Portal combines the legal representative role with a secure platform that stores your technical documentation, declarations, SBOMs and incident records — auditable, retained for the full period, and instantly retrievable when an authority asks.

Secure 10-year archive

Your documentation stored, versioned and retained for the full statutory period.

Authority-request handling

A defined process and SLA for responding to reasoned requests, with a complete audit trail.

EU contact published

Your representative's name and address, ready to appear on your product and documentation.

Your documentation, protected

As your authorised representative we hold your conformity documentation — which may contain trade secrets — for the statutory period. Here is how we keep it secure.

EU hosting

Application and database are hosted in the EU (Germany), within the EU/EEA.

Encryption at rest and in transit

Sensitive data is encrypted with AES-256 at rest and all connections use TLS. Passwords are stored only as salted one-way hashes.

Access and audit trail

Role-based access — each client sees only its own data — with a complete audit trail of authority requests and a tamper-evident 10-year retention lock on statutory documents.

Governance and confidentiality

GDPR-compliant with a Data Processing Agreement; a confidentiality clause in every mandate and an NDA on request. Our practices follow the principles of ISO/IEC 27001.

How we protect your data →

Ready-to-run incident process & drill

Beyond representation, we make Article 14 reporting actually work: a self-service builder for your 24h/72h reporting process — RACI, workflow, SOP and evidence checklist — plus a tabletop drill to rehearse it under pressure.

Open the incident-response tool

Appoint CRA-Portal as your EU representative

Tell us about your products and we'll propose a mandate and terms tailored to your situation.

Contact us
CRA Assistent