Independent information resource Product security · EU CRA
CRA enforcement / 11

CRA Enforcement for Non-EU Manufacturers

How CRA enforcement works for manufacturers established outside the EU, including importer obligations, authorised representatives, the EU-established economic operator requirement, market-surveillance cooperation and corrective measures.

IN BRIEF

CRA enforcement for a third-country manufacturer is built around EU market access and the economic operators that place or make the product available in the Union. Authorities can obtain evidence and require cooperation from EU-based importers or authorised representatives within their legal roles, while manufacturers remain responsible for obligations that the CRA does not allow them to delegate. Corrective measures can affect whether the product continues to be sold in the EU market.

01 / 10

The CRA Follows the Product Into the Union Market

The relevant question is not simply where the manufacturer is incorporated. A product with digital elements placed on the Union market is subject to the CRA when it falls within the Regulation's scope. A manufacturer established in a third country therefore needs a compliance model that works with the EU importer, authorised representative where appointed, distributors and the market-surveillance framework.

02 / 10

The Importer Is an EU-Established Economic Operator

The CRA defines an importer as a natural or legal person established in the Union that places on the market a product bearing the name or trademark of a person established outside the Union. Article 19 requires importers to place on the market only products meeting the applicable cybersecurity requirements and to verify specified conformity, documentation and marking steps before market placement.

03 / 10

The Market Surveillance Regulation Requires an EU-Established Responsible Operator

Regulation (EU) 2019/1020 requires covered products to have an economic operator established in the Union responsible for specified market-surveillance tasks. Depending on the supply chain, that operator can be an EU manufacturer, an importer, an authorised representative with the required mandate or, where no other listed operator exists, a fulfilment service provider for the products it handles.

04 / 10

An Authorised Representative Does Not Replace the Manufacturer

Article 18 allows a manufacturer to appoint an authorised representative by written mandate, but core manufacturer obligations listed in Article 18(2) cannot form part of that mandate. Representation therefore creates an EU contact and cooperation mechanism without transferring all manufacturer responsibility away from the third-country company.

05 / 10

The Mandate Must Cover Authority Cooperation Tasks

At minimum, the authorised representative's mandate must allow it to keep the EU declaration of conformity and technical documentation available for the required period, provide information and documentation necessary to demonstrate conformity following a reasoned authority request, and cooperate with market surveillance authorities on action taken to eliminate product risks covered by the mandate.

06 / 10

Importers Have Their Own Enforcement Exposure

An importer is not merely a forwarding address for the manufacturer. Article 19 gives the importer independent duties, including verifying required manufacturer steps and responding when it believes the product is non-compliant or presents a significant cybersecurity risk. Importer failures are also among the obligations referenced in Article 64's penalty framework.

07 / 10

Corrective Measures Can Stop EU Market Access

Where a CRA investigation identifies non-compliance or significant risk, market surveillance authorities can require corrective action and can restrict or prohibit market availability, withdrawal or recall where the statutory conditions are met. For a non-EU manufacturer, those measures can have immediate commercial effect because the importer and other EU economic operators cannot continue supplying a product that remains subject to justified restrictive measures.

08 / 10

Authorities Can Request Product and Compliance Evidence

The CRA and Regulation (EU) 2019/1020 provide routes for authorities to obtain conformity information, technical documentation and other evidence from relevant economic operators. A third-country manufacturer should therefore ensure that its EU supply chain can retrieve the correct declaration, technical file, product-version evidence and risk information rather than relying on records that remain inaccessible outside the Union.

09 / 10

Non-EU Status Does Not Remove Article 13 and Article 14 Responsibilities

The manufacturer remains responsible for the CRA obligations that apply to it, including the essential cybersecurity requirements, vulnerability-handling obligations and Article 14 reporting where applicable. An authorised representative can perform only tasks that the CRA permits to be included in the mandate, so the manufacturer needs its own operational capability for secure development, vulnerability handling and regulatory reporting.

10 / 10

Build an Enforcement-Ready EU Market File

A practical non-EU enforcement file should identify the manufacturer, importer, authorised representative where appointed, product models, relevant declarations, technical documentation location, support-period information, vulnerability-reporting process and responsibility for authority requests. Clear ownership helps avoid delay when an EU authority asks which entity can supply evidence or carry out corrective action.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.