Independent information resource Product security · EU CRA
CRA reporting / 10

How to Determine the Correct CSIRT for CRA Reporting

Learn how Article 14(7) determines the CSIRT designated as coordinator for CRA reporting, including the main-establishment test and the fallback rules for manufacturers without an EU main establishment.

IN BRIEF

The correct CRA CSIRT is determined by Article 14(7), not by convenience. The first question is where product-cybersecurity decisions are predominantly taken. Only when that cannot be determined does the employee-count fallback apply. Manufacturers without an EU main establishment follow a different four-step cascade.

01 / 07

The Manufacturer Must Select the Correct CSIRT

The CRA Single Reporting Platform uses national electronic notification endpoints associated with CSIRTs designated as coordinators. ENISA currently states that the manufacturer is responsible for identifying the correct CSIRT under Article 14(7) and selecting it when submitting through the SRP. This is not merely a user-interface choice. ENISA also warns that selecting the wrong CSIRT can lead to the notification being invalidated and needing to be resubmitted to the correct CSIRT. Organisations should therefore determine their routing position before an Article 14 deadline is running wherever possible.

  • The manufacturer determines the correct coordinating CSIRT.
  • The selection is made in the SRP.
  • Base the decision on Article 14(7).
  • Document the analysis before reporting.
  • A wrong selection can require resubmission.
02 / 07

Start With the Main Establishment Test

For CRA reporting, main establishment has a specific meaning. Article 14(7) considers the manufacturer to have its main establishment in the Member State where decisions related to the cybersecurity of its products with digital elements are predominantly taken. This means the analysis should focus on product-cybersecurity governance and decision-making rather than automatically using the legal incorporation address, tax residence, largest sales office or location of the largest engineering team. The manufacturer should identify where the relevant cybersecurity decisions are actually and predominantly made.

  • Identify where product-cybersecurity decisions are predominantly taken.
  • Do not automatically use the registered office.
  • Do not automatically use the largest market.
  • Do not automatically use the largest engineering location.
  • Preserve evidence supporting the conclusion.
03 / 07

Employee Count Is a Fallback, Not the First Test

If the Member State where product-cybersecurity decisions are predominantly taken cannot be determined, Article 14(7) provides a fallback. The main establishment is then considered to be in the Member State where the manufacturer has the establishment with the highest number of employees in the Union. The order matters. A manufacturer should not jump directly to employee count simply because it is easier to measure. The cybersecurity decision-making test comes first, and the employee-count rule is used only when that location cannot be determined.

  • Apply the cybersecurity decision-making test first.
  • Use employee count only if the first test cannot determine the Member State.
  • Compare EU establishments, not the manufacturer's worldwide headcount.
  • Document why the first test could not determine the location.
04 / 07

Manufacturers Without an EU Main Establishment Use a Four-Step Order

Where a manufacturer has no main establishment in the Union, Article 14(7) specifies an ordered cascade based on the information available to the manufacturer. First comes the Member State where the authorised representative acting for the highest number of the manufacturer's products with digital elements is established. If that does not apply, the next test concerns the importer placing the highest number of those products on the market. The next fallback is the distributor making the highest number available. If none of those applies, the relevant Member State is the one where the highest number of users of the manufacturer's products with digital elements are located.

  • First: authorised representative.
  • Second: importer.
  • Third: distributor.
  • Fourth: highest number of users.
  • Apply the order rather than choosing freely between the four.
05 / 07

Assigned Representative and Authorised Representative Mean Different Things

The Article 14(7) fallback uses the CRA legal term authorised representative. ENISA's platform separately uses the term Assigned Representative, abbreviated AR, for an individual who operates the SRP on behalf of a manufacturer. These concepts should not be merged. The Member State used under Article 14(7)(a) depends on the manufacturer's authorised representative acting for the highest number of products, where applicable. The person who logs into the SRP as the Assigned Representative may be someone else entirely.

  • Authorised representative is part of the Article 14(7) legal routing cascade.
  • Assigned Representative is an SRP user role.
  • An Assigned Representative does not automatically determine the manufacturer's routing Member State.
  • Use precise terminology in internal procedures.
06 / 07

The User-Based Fallback Has a Continuity Rule

Article 14(7) contains an additional rule where the manufacturer reaches the final fallback based on the Member State with the highest number of users. For that specific branch, the manufacturer may submit notifications concerning subsequent actively exploited vulnerabilities or severe incidents to the same CSIRT designated as coordinator to which it first reported. This can create continuity once the manufacturer has reached the point (d) user-based route. The rule should not be generalized to manufacturers whose CSIRT was determined through the authorised-representative, importer or distributor branches.

  • The continuity provision is tied to the user-based fallback.
  • Record which Article 14(7) branch was used.
  • Record the first coordinating CSIRT used under point (d).
  • Do not apply the point (d) continuity rule automatically to the other branches.
07 / 07

Recheck the Routing Analysis When Corporate Facts Change

Cybersecurity governance, corporate structure and market routes can change. A manufacturer may move its product-security leadership, establish a new EU entity, appoint an authorised representative, change import arrangements or materially shift its market footprint. The Article 14 routing analysis should therefore be treated as maintained compliance information rather than a decision made once and forgotten. The most useful internal record identifies the applicable Article 14(7) branch, the evidence supporting it, the selected coordinating CSIRT and the date on which the determination was last reviewed.

  • Record the Article 14(7) branch used.
  • Record supporting evidence.
  • Record the selected coordinating CSIRT.
  • Review the decision after relevant organisational changes.
  • Keep Assigned Representatives informed of the current routing conclusion.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.