Cyber Resilience Act

CRA Authorised Representative Obligations: Mandate, Documentation, and Authority Cooperation

Learn what a CRA authorised representative can do, which manufacturer duties cannot be delegated, what the written mandate must cover, and what evidence must remain available.

  • CRA authorised representative requirements
  • Cyber Resilience Act authorised representative
  • CRA authorised representative mandate
  • CRA technical documentation representative
  • CRA Article 18 authorised representative
AA-sec cover graphic for a practical guide to CRA authorised representative mandates, document retention and market-surveillance cooperation.

Under the Cyber Resilience Act (CRA), a manufacturer may appoint an authorised representative established in the European Union to perform specified tasks on its behalf. The appointment is useful for documentation and market-surveillance cooperation, but it does not transfer the manufacturer's core product-security responsibilities.

Article 18 makes that boundary explicit. The relationship must be based on a written mandate, the representative may perform only the tasks specified in that mandate, and several central manufacturer obligations are excluded from delegation. For manufacturers outside Austria or elsewhere in the EU that use an authorised representative, the practical objective is therefore to define a narrow, auditable mandate and make sure the representative can actually retrieve the evidence and contacts needed when an authority asks.

The CRA's main obligations, including Article 18, apply from 11 December 2027. Reporting obligations under Article 14 apply earlier, from 11 September 2026. An authorised-representative arrangement should not be used to blur those dates or the manufacturer's continuing responsibility for obligations that Article 18 excludes from the mandate.

Start with the legal role, not the job title

The CRA defines an authorised representative as a natural or legal person established within the Union that has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks.

Three elements matter operationally:

  • the representative must be established in the EU;
  • the appointment must be made through a written mandate; and
  • the mandate must identify the tasks the representative is authorised to perform.

A commercial agent, distributor, consultant or group company does not become a CRA authorised representative merely because it communicates with customers or authorities. The Article 18 role follows from the written mandate and its defined scope.

For governance, record the legal entities on both sides, the effective date, the products or product families covered, the authorised tasks, responsible contacts and the process for updating or terminating the mandate.

Core manufacturer duties cannot be delegated

Article 18(2) excludes important manufacturer obligations from the authorised representative's mandate. The obligations in Article 13(1) to (11), Article 13(12), first subparagraph, and Article 13(14) cannot form part of the mandate.

That boundary is substantial. It means the representative cannot take over the manufacturer's responsibility for the core CRA product-security work covered by those provisions. Among other things, the manufacturer remains responsible for ensuring that products are designed, developed and produced in accordance with the essential cybersecurity requirements, performing and documenting the cybersecurity risk assessment, determining the support period, handling vulnerabilities during that period, and fulfilling the manufacturer-side reporting obligation referenced by Article 13(14).

A mandate should therefore avoid broad wording such as "the representative is responsible for CRA compliance." That language is operationally ambiguous and can suggest a transfer of duties that Article 18 does not permit.

Instead, map each delegated task to a specific CRA activity and identify the manufacturer owner who remains accountable for the underlying product-security decision or evidence.

The mandate must cover at least three tasks

Article 18(3) requires the representative to perform the tasks specified in the mandate and sets a minimum content for that mandate. At minimum, the representative must be enabled to retain specified conformity evidence, provide information and documentation following a reasoned authority request, and cooperate with market-surveillance authorities on actions to eliminate risks posed by covered products.

These minimum tasks should be translated into concrete operating procedures rather than copied into a contract without implementation detail.

Keep the EU declaration and technical documentation available

The mandate must allow the authorised representative to keep the EU declaration of conformity under Article 28 and the technical documentation under Article 31 at the disposal of market-surveillance authorities.

The retention period is at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.

This creates a product-specific evidence requirement. A representative needs more than a generic folder labelled "CRA documentation." It should be able to determine which declaration and technical-documentation baseline applies to the exact product or release covered by an authority request.

A practical evidence index can include:

  • product name, model, variant and relevant release identifiers;
  • manufacturer legal entity and contact owner;
  • EU declaration of conformity identifier and revision;
  • technical-documentation package identifier and revision;
  • date the product was placed on the market;
  • applicable support-period end date;
  • storage or retrieval location; and
  • the person or function authorised to release the records to an authority.

Where the manufacturer keeps the master technical file in its own controlled system, the representative still needs a tested retrieval path. Article 18 is concerned with the ability to keep the information at the disposal of authorities, not with creating uncontrolled duplicate document repositories.

Prepare for reasoned market-surveillance requests

The mandate must allow the representative, following a reasoned request from a market-surveillance authority, to provide all information and documentation necessary to demonstrate conformity of the product with digital elements.

The operational challenge is response quality and scope. A request may concern one product, release, market or security issue. Teams should be able to identify the affected product and retrieve the corresponding evidence without mixing documentation from another variant or silently substituting a newer technical file for the historical state that was actually placed on the market.

A response procedure should define:

  1. who receives and authenticates the authority request;
  2. how the affected product and market scope are identified;
  3. who at the manufacturer owns the requested evidence;
  4. how document versions and release context are verified;
  5. who reviews the response before submission; and
  6. what record is retained of what was supplied, when and to whom.

The representative should also preserve the original request and the response package. That creates a defensible history if follow-up questions arrive later.

Build cooperation into the mandate

Article 18 also requires the mandate to allow the representative to cooperate with market-surveillance authorities, at their request, on actions taken to eliminate risks posed by a product covered by the mandate.

This is broader than document forwarding. A market-surveillance case can require coordination with the manufacturer about technical findings, corrective measures, affected product scope, withdrawal or recall decisions, or evidence that a risk has been addressed.

The representative therefore needs an escalation path into the manufacturer's product-security, engineering and regulatory functions. Define contacts before an authority request arrives, including backups for absence and a process for urgent security matters.

The representative should not make technical or legal decisions outside its mandate merely to respond quickly. The workflow should distinguish information relay and coordination from decisions that remain with the manufacturer or another responsible economic operator.

Keep the mandate itself retrievable

Article 18 requires the authorised representative to provide a copy of the mandate to market-surveillance authorities upon request.

Treat the mandate as controlled evidence. Keep the signed version, amendments, effective dates and product scope accessible. If the mandate changes, preserve enough history to show which version applied to a product or authority interaction at a particular time.

This is particularly important where a representative covers only selected product families or where responsibilities are split across several legal entities. An authority should not have to infer scope from an organisational chart or email history.

Separate authorised-representative duties from importer duties

An authorised representative and an importer are distinct CRA roles. An importer is an EU-established person that places on the market a product bearing the name or trademark of a person established outside the Union. Article 19 gives importers their own verification, identification, post-market and authority-cooperation duties.

Appointing an authorised representative does not automatically remove or replace importer obligations where an importer exists in the supply chain. Map the actual economic operators for each product flow and document which legal entity is acting in each role.

This matters for multinational groups where a European subsidiary may perform several commercial functions. The same organisation can have different responsibilities depending on the legal role it performs for a particular product and transaction.

Design a clean handover process

Authorised-representative arrangements can change during a product's support period. Even when the commercial relationship changes, the manufacturer still needs continuity for conformity evidence and authority cooperation.

A controlled handover should identify all covered products, open authority requests, retained declarations, technical-documentation references, support-period dates and relevant contacts. Do not rely on individual mailboxes or personal knowledge to preserve this history.

Where documents are transferred, verify completeness and access rather than assuming that a bulk export contains the required product-specific evidence. Preserve a record of the handover and the effective date of the new arrangement.

Test the arrangement before it is needed

A mandate can be legally precise but operationally ineffective if the representative cannot retrieve the right records. A simple readiness exercise can expose gaps early.

Select one covered product and simulate a reasoned market-surveillance request. Ask the representative to identify the applicable mandate, retrieve the EU declaration of conformity and technical-documentation reference, identify the manufacturer's responsible contact, and assemble a controlled response package.

Record how long the retrieval takes, which dependencies fail and whether the evidence clearly matches the selected product state. The purpose is not to invent an SLA required by the CRA; it is to verify that the documented process actually works.

Repeat the exercise after major organisational, repository or product-portfolio changes. A retrieval path that worked when the mandate was signed may fail years later if ownership or systems have changed.

Keep representative evidence connected to product context

Authorised-representative work becomes difficult to audit when mandates, declarations, technical-documentation references and authority correspondence are stored independently of the product they concern. The practical requirement is durable traceability: teams need to know which evidence supported which product state and which response decision.

AA-sec is designed around traceability between requirements, security evidence, decisions and exact product or lifecycle context. That model can support internal organisation of CRA evidence and authority-response history while the manufacturer and its authorised representative retain responsibility for their own legal roles, decisions and communications.

Key takeaway

A CRA authorised representative is a defined delegation mechanism, not a transfer of the manufacturer's core cybersecurity responsibilities. Use a written, product-scoped mandate; keep excluded manufacturer duties clearly outside it; and ensure the representative can retain conformity evidence, answer reasoned requests and cooperate with market-surveillance authorities.

The strongest implementation is one that can be demonstrated in practice. Keep the mandate and evidence versioned, map every record to the exact product context, define escalation contacts and periodically test whether the representative can retrieve and deliver the required information.

Official sources

Official sources