The authorised representative is a mandated regulatory interface, not a replacement manufacturer. Its powers and duties come from the written mandate, while the CRA expressly prevents several core manufacturer obligations from being transferred through that mandate.
An Authorised Representative Must Be Established in the Union
Article 3 defines an authorised representative as a natural or legal person established within the Union that has received a written mandate from a manufacturer to act on the manufacturer's behalf in relation to specified tasks. The role therefore requires both Union establishment and an actual written mandate. A consultant, reseller or service provider does not become a CRA authorised representative merely by helping a manufacturer with compliance.
Appointment Is Optional Under Article 18
Article 18 states that a manufacturer may appoint an authorised representative by written mandate. The CRA does not convert every non-EU manufacturer's importer or distributor into its authorised representative. The parties need a mandate that expressly identifies the representative and the tasks it is authorised to perform.
Core Manufacturer Obligations Cannot Be Delegated
Article 18 expressly prevents the obligations in Article 13(1) to (11), Article 13(12), first subparagraph, and Article 13(14) from forming part of the authorised representative's mandate. Those provisions include core product-security, risk-assessment, component, vulnerability-handling, support and conformity-preparation responsibilities. Appointment of a representative therefore does not transfer ownership of secure product design and development away from the manufacturer.
The Written Mandate Defines the Representative's Tasks
The authorised representative must perform the tasks specified in the mandate received from the manufacturer and must provide a copy of that mandate to market surveillance authorities upon request. Companies should therefore keep the mandate precise and operational, identifying which products it covers, what documents the representative maintains and who is responsible for answering authority requests.
Conformity Records Must Remain Available
The mandate must allow the authorised representative to keep the EU declaration of conformity and Article 31 technical documentation at the disposal of market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. The representative therefore needs durable access to the required evidence rather than relying on temporary project access.
The Representative Must Answer Reasoned Authority Requests
Article 18 requires the mandate to allow the authorised representative, following a reasoned request from a market surveillance authority, to provide all information and documentation necessary to demonstrate product conformity. A representative should know where the current product evidence is held and how to obtain it quickly from the manufacturer.
Cooperation on Risk-Elimination Measures Is Mandatory
The authorised representative must also be able to cooperate with market surveillance authorities, at their request, on actions taken to eliminate risks posed by products covered by the mandate. This can require coordination between the representative, manufacturer, product-security team and other supply-chain operators when an authority investigates a product.
An Authorised Representative Is Not the Same as an Importer
The authorised representative acts under a manufacturer's written mandate. An importer, by contrast, is an EU-established person that places on the market a product bearing the name or trademark of a person established outside the Union. The same organisation could potentially perform more than one role in an appropriate arrangement, but the legal duties arise from each role separately.
Do Not Use the Representative as a Shortcut Around Manufacturer Responsibility
A practical CRA arrangement should document the manufacturer first, then define the authorised representative's mandate. The manufacturer should retain ownership of the product cybersecurity risk assessment, Annex I implementation, vulnerability handling and conformity preparation that Article 18 does not permit it to delegate. The representative should be equipped to fulfil the regulatory-interface tasks actually assigned to it.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.