Skip to service information
1 of 1

EaseCert | GPSR Compliance

EU Cyber Resilience Act Authorised Representative and Compliance Service

EU Cyber Resilience Act Authorised Representative and Compliance Service

Regular price €1.050,00 EUR
Regular price Sale price €1.050,00 EUR
Sale Sold out
One-time fee. No subscription. Taxes included. A Setup & Documentation Fee may apply depending on service scope. It covers onboarding, review of existing compliance materials, document verification, and technical documentation checks for EU GPSR compliance.

EU Cybersecurity Compliance and Authorised Representation

EaseCert supports manufacturers with compliance under the EU Cyber Resilience Act (CRA) and acts as their EU Authorised Representative for the products with digital elements covered by the agreed service scope.

The Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements placed on the European Union market. Manufacturers must address cybersecurity throughout the product lifecycle, maintain technical documentation, establish vulnerability-handling procedures, provide security updates, and meet applicable reporting and post-market obligations.

This service is designed for manufacturers established outside the European Union that require both CRA compliance support and an EU-based Authorised Representative.

Following completion of the documentation review and signature of the written mandate, EaseCert GmbH is appointed as the manufacturer’s EU Authorised Representative under the Cyber Resilience Act.

Within the scope of the mandate, EaseCert:

  • Acts as the EU-based regulatory contact for the covered products
  • Keeps the EU Declaration of Conformity and technical documentation available for market surveillance authorities
  • Responds to reasoned requests for compliance information and documentation
  • Cooperates with EU market surveillance authorities regarding products covered by the mandate
  • Supports regulatory communication, documentation requests, and traceability checks

The manufacturer remains responsible for the design, development, production, cybersecurity, conformity assessment, vulnerability handling, security updates, incident reporting, and continued compliance of the product.

Suitable Product Categories

  • Smart home devices
  • Internet of Things (IoT) products
  • Consumer electronics
  • Connected household appliances
  • Wearable devices
  • Smart lighting products
  • Network equipment
  • Security cameras
  • Connected toys
  • Industrial IoT equipment
  • Smart sensors
  • Wireless devices
  • Battery-powered connected products
  • Software supplied with connected hardware
  • Standalone software products
  • Other products with digital elements

The EU Cyber Resilience Act Compliance and EAR Process in Five Steps

  1. Map the Product, Software, and Digital Environment

    We document how the product or software is supplied, installed, accessed, connected, updated, and maintained. The review covers software and firmware versions, operating environments, cloud dependencies, APIs, network interfaces, user roles, authentication methods, data flows, deployment models, supported platforms, external services, and connections to other devices or systems.

  2. Review the Cybersecurity Lifecycle and CRA Scope

    We assess the product’s intended use, digital functions, cybersecurity architecture, conformity assessment route, and applicable CRA obligations. We also review the manufacturer’s secure development lifecycle, including source-code controls, dependency management, change approval, security testing, release procedures, issue tracking, patch development, access controls, and internal cybersecurity responsibilities.

  3. Assess Risks, Dependencies, Vulnerabilities, and the SBOM

    We review the cybersecurity risk assessment, software components, open-source libraries, third-party packages, cloud services, and external dependencies. Where available, we assess the Software Bill of Materials (SBOM), vulnerability records, dependency inventory, severity-assessment process, remediation workflow, coordinated vulnerability disclosure procedure, security-update process, and support-period commitments.

  4. Prepare and Review the CRA Compliance Documentation

    EaseCert prepares, reviews, or organizes the agreed regulatory documentation. This may include the cybersecurity risk assessment, product and software architecture description, technical documentation, SBOM records, vulnerability-handling procedure, coordinated vulnerability disclosure policy, software update procedure, support-period statement, security information for users, incident-reporting workflow, traceability information, and EU Declaration of Conformity.

  5. Appoint EaseCert as EU Authorised Representative

    After the compliance review is completed and the written mandate is signed, EaseCert GmbH is appointed as the manufacturer’s EU Authorised Representative for the covered products. EaseCert retains the EU Declaration of Conformity and technical documentation, responds to reasoned requests from market surveillance authorities, and cooperates with authorities regarding compliance risks and corrective actions. The appointment remains subject to the agreed mandate, service terms, and continued compliance of the covered products.

EU Authorised Representative Service

The EU Authorised Representative service is included for manufacturers established outside the European Union.

The appointment is formalized through a written mandate identifying the manufacturer, the covered products, and the regulatory tasks assigned to EaseCert.

EaseCert’s EAR Responsibilities

  • Act as the appointed EU Authorised Representative under the Cyber Resilience Act
  • Maintain a copy of the signed written mandate
  • Keep the EU Declaration of Conformity available to market surveillance authorities
  • Keep the required technical documentation available to market surveillance authorities
  • Provide compliance information and documentation following a reasoned authority request
  • Cooperate with authorities regarding risks presented by covered products
  • Support regulatory communication and documentation requests
  • Support traceability checks concerning the manufacturer and covered products
  • Inform the manufacturer of relevant regulatory inquiries received by EaseCert

Manufacturer Responsibilities

The appointment of EaseCert does not transfer the manufacturer’s core obligations under the Cyber Resilience Act.

The manufacturer remains responsible for:

  • Designing and developing compliant products and software
  • Performing and maintaining the cybersecurity risk assessment
  • Meeting the essential cybersecurity requirements
  • Conducting the applicable conformity assessment
  • Preparing and maintaining accurate technical documentation
  • Signing the EU Declaration of Conformity
  • Affixing the CE marking where required
  • Monitoring and addressing vulnerabilities
  • Providing security updates during the support period
  • Reporting actively exploited vulnerabilities and severe security incidents
  • Taking corrective action where a product is non-compliant or presents a cybersecurity risk
  • Informing EaseCert of relevant product, software, ownership, or compliance changes

What Is Included

  • Cyber Resilience Act applicability assessment
  • Product and software scope review
  • Review of the conformity assessment route
  • Review of existing technical documentation
  • Review of cybersecurity documentation
  • Cybersecurity compliance gap analysis
  • Review of the secure software development lifecycle
  • Review of product identification and traceability
  • Review of product labelling and CE marking information
  • Review of user documentation and security instructions
  • Review of vulnerability-handling procedures
  • Review of software update and maintenance procedures
  • Review of the Software Bill of Materials, if available
  • Review of support-period documentation
  • EU Declaration of Conformity review
  • Written compliance report and recommendations
  • Written EU Authorised Representative mandate
  • Appointment of EaseCert GmbH as EU Authorised Representative
  • Retention of the EU Declaration of Conformity and technical documentation
  • EU-based regulatory point of contact
  • Support with market surveillance authority requests
  • Regulatory guidance throughout the project

Required Documentation

Manufacturer Information

  • Legal company name
  • Registered business address
  • Company registration number
  • Contact person
  • Email address
  • Telephone number
  • Website
  • EU importer information, if applicable

Product Information

  • Product name
  • Brand name
  • Model number
  • SKU or product identifier
  • Technical specifications
  • Product photographs
  • Intended purpose and intended users
  • Communication technologies
  • User manual
  • Packaging artwork
  • Product labels
  • CE marking information

Software and Cybersecurity Information

  • Firmware and software versions
  • Software and hardware architecture
  • Communication protocols
  • Network interfaces
  • Cloud services and external dependencies
  • Authentication and access-control methods
  • Encryption methods, where applicable
  • Software update mechanism
  • Security update and patching process
  • Vulnerability-handling procedure
  • Coordinated vulnerability disclosure policy
  • Support period
  • Software Bill of Materials, if available
  • Secure development lifecycle documentation
  • Incident-reporting procedure

Existing Compliance Documentation

  • EU Declaration of Conformity
  • Technical documentation
  • Cybersecurity risk assessment
  • Applicable CE test reports
  • Software and firmware documentation
  • Existing cybersecurity test reports
  • Penetration test reports, if available
  • Vulnerability scan reports, if available
  • Certification reports, if available
  • Existing authorised representative agreements, if applicable

Service Limitations

EaseCert provides regulatory consulting, compliance assessment, documentation support, and EU Authorised Representative services within the scope of the signed mandate.

Unless separately agreed in writing, the service does not include:

  • Penetration testing
  • Source-code review
  • Vulnerability scanning
  • Ethical hacking
  • Laboratory testing
  • Cybersecurity certification
  • Notified Body conformity assessment
  • Development or modification of software
  • Software remediation or vulnerability correction
  • Continuous technical vulnerability monitoring
  • Security operations centre services
  • Technical incident response
  • Product or software redesign
  • Submission of manufacturer reports unless expressly included in the written mandate and legally permitted

Where technical cybersecurity testing is required, EaseCert can help define the testing scope and coordinate with a qualified cybersecurity laboratory or technical provider.

EaseCert’s appointment as EU Authorised Representative does not constitute product certification, approval, or confirmation that the product is free from cybersecurity vulnerabilities.

The manufacturer remains legally responsible for the cybersecurity, conformity, accuracy of the documentation, and continued compliance of its products.

Processing Time

Most initial compliance reviews are completed within approximately 5 to 10 business days after receipt of all required documentation.

The EU Authorised Representative appointment becomes effective after the documentation review has been completed, the covered products have been accepted by EaseCert, and the written mandate has been signed by both parties.

Processing times may vary depending on product complexity, the number of product groups, the completeness of the submitted documentation, the conformity assessment route, and whether additional technical testing is required.

Frequently Asked Questions

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements placed on the European Union market. It addresses cybersecurity throughout the product lifecycle, including design, development, vulnerability handling, security updates, technical documentation, conformity assessment, and post-market monitoring.

Does this service include an EU Authorised Representative?

Yes. Appointment of EaseCert GmbH as the manufacturer’s EU Authorised Representative under the Cyber Resilience Act is included for the products accepted within the agreed service scope.

The appointment becomes effective after the compliance review is completed and the written mandate is signed by the manufacturer and EaseCert.

What does EaseCert do as the EU Authorised Representative?

EaseCert keeps the EU Declaration of Conformity and technical documentation available for market surveillance authorities, responds to reasoned requests for compliance information, and cooperates with authorities regarding products covered by the written mandate.

Does appointing EaseCert transfer the manufacturer’s responsibilities?

No. The manufacturer remains responsible for product design, software development, cybersecurity risk management, conformity assessment, technical documentation, vulnerability handling, security updates, incident reporting, corrective action, and continued compliance.

Must the appointment be documented?

Yes. The appointment is established through a written mandate identifying the manufacturer, EaseCert GmbH, the covered products, and the regulatory tasks assigned to EaseCert.

Which products are covered by the Cyber Resilience Act?

The regulation generally applies to hardware and software products with digital elements that connect directly or indirectly to another device or network. This may include connected consumer products, IoT devices, network equipment, industrial digital products, embedded software, and standalone software.

Does the Cyber Resilience Act apply to standalone software?

In many cases, yes. Standalone software placed on the EU market may fall within the scope of the Cyber Resilience Act, depending on how it is supplied, its intended purpose, and whether an exclusion applies.

When do the Cyber Resilience Act requirements apply?

The Cyber Resilience Act entered into force on 10 December 2024. The main requirements apply from 11 December 2027. The vulnerability and severe incident-reporting obligations apply from 11 September 2026.

What is a Software Bill of Materials?

A Software Bill of Materials (SBOM) is a structured inventory of software components, libraries, dependencies, and third-party elements used in a product. It helps manufacturers determine whether a product is affected when a vulnerability is identified.

Do I need cybersecurity testing?

Testing requirements depend on the product, cybersecurity risks, applicable standards, product classification, and conformity assessment route. EaseCert reviews the available evidence and identifies whether additional testing or third-party assessment may be required.

Does EaseCert perform penetration testing?

No. Penetration testing, source-code analysis, vulnerability scanning, and specialist cybersecurity testing must be performed by a qualified technical provider. EaseCert can assist with defining and coordinating the required testing scope.

Does EaseCert certify the product?

No. EaseCert provides regulatory compliance support and acts as the EU Authorised Representative. EaseCert does not issue cybersecurity certificates, perform laboratory testing, or act as a Notified Body.

Can EaseCert prepare the required documentation?

Yes. Depending on the agreed scope, EaseCert can prepare, review, or organize CRA documentation, including the cybersecurity risk assessment, technical documentation, vulnerability-handling procedure, software update process, support-period documentation, user security information, and EU Declaration of Conformity.

Can several models be covered by one appointment?

Models sharing the same software platform, firmware, hardware architecture, connectivity, update mechanism, intended purpose, and cybersecurity controls may sometimes be grouped together. EaseCert reviews the product range before confirming the scope.

Does the service include continuous vulnerability monitoring?

No. The standard service does not include continuous technical monitoring, security operations, software maintenance, or incident response. The manufacturer must maintain suitable post-market cybersecurity processes throughout the applicable support period.

How long does the service take?

Most initial reviews are completed within approximately 5 to 10 business days after all required documentation has been received. The EAR appointment begins once the review is complete and the written mandate has been signed.

Start Your EU Cybersecurity Compliance and EAR Project

Place your order and EaseCert will contact you by email with the required documentation list, written mandate, and next steps for the Cyber Resilience Act compliance review and EU Authorised Representative appointment.

View full details

Get in Touch with EaseCert