If you are outside the EU, this still applies
The Cyber Resilience Act applies to products placed on the EU market, not to companies established in the EU. An Israeli, American or British vendor selling into Europe carries the same reporting duty as a German one.Art. 2(1)
Which authority receives your report
You report to the CSIRT designated as coordinator in the member state where you have your most significant connection, and to ENISA, through the single reporting platform.Art. 14(7) The connection is decided in order:
- 1
Your authorised representative
If you have appointed one, their member state decides.
- 2
Your importer
Failing a representative, the member state where your importer is established.
- 3
Your distributor
Failing an importer, where your distributor or reseller is established.
- 4
Your users
Failing all of those, the member state where the largest number of your users are.
In practice this means a vendor with no EU entity but a German distributor reports to Germany, and one selling only direct to customers reports wherever most of those customers are. It is worth settling this before you need it: working it out under a 24-hour clock is not the moment.
The 27 coordinators
- AT Austria
- BE Belgium
- BG Bulgaria
- HR Croatia
- CY Cyprus
- CZ Czechia
- DK Denmark
- EE Estonia
- FI Finland
- FR France
- DE Germany
- GR Greece
- HU Hungary
- IE Ireland
- IT Italy
- LV Latvia
- LT Lithuania
- LU Luxembourg
- MT Malta
- NL Netherlands
- PL Poland
- PT Portugal
- RO Romania
- SK Slovakia
- SI Slovenia
- ES Spain
- SE Sweden
Work out yours in five questions
Run the scope checkThis produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.