If you are outside the EU, this still applies

The Cyber Resilience Act applies to products placed on the EU market, not to companies established in the EU. An Israeli, American or British vendor selling into Europe carries the same reporting duty as a German one.Art. 2⁠(1)⁠

Which authority receives your report

You report to the CSIRT designated as coordinator in the member state where you have your most significant connection, and to ENISA, through the single reporting platform.Art. 14⁠(7)⁠ The connection is decided in order:

  1. 1

    Your authorised representative

    If you have appointed one, their member state decides.

  2. 2

    Your importer

    Failing a representative, the member state where your importer is established.

  3. 3

    Your distributor

    Failing an importer, where your distributor or reseller is established.

  4. 4

    Your users

    Failing all of those, the member state where the largest number of your users are.

In practice this means a vendor with no EU entity but a German distributor reports to Germany, and one selling only direct to customers reports wherever most of those customers are. It is worth settling this before you need it: working it out under a 24-hour clock is not the moment.

The 27 coordinators

Work out yours in five questions

Run the scope check

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.