{"product_id":"eu-cyber-resilience-act-compliance-service","title":"EU Cyber Resilience Act Authorised Representative and Compliance Service","description":"\u003ch2\u003eEU Cybersecurity Compliance and Authorised Representation\u003c\/h2\u003e\n\u003cp\u003eEaseCert supports manufacturers with compliance under the EU Cyber Resilience Act (CRA) and acts as their EU Authorised Representative for the products with digital elements covered by the agreed service scope.\u003c\/p\u003e\n\u003cp\u003eThe Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements placed on the European Union market. Manufacturers must address cybersecurity throughout the product lifecycle, maintain technical documentation, establish vulnerability-handling procedures, provide security updates, and meet applicable reporting and post-market obligations.\u003c\/p\u003e\n\u003cp\u003eThis service is designed for manufacturers established outside the European Union that require both CRA compliance support and an EU-based Authorised Representative.\u003c\/p\u003e\n\u003cp\u003eFollowing completion of the documentation review and signature of the written mandate, EaseCert GmbH is appointed as the manufacturer’s EU Authorised Representative under the Cyber Resilience Act.\u003c\/p\u003e\n\u003cp\u003eWithin the scope of the mandate, EaseCert:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eActs as the EU-based regulatory contact for the covered products\u003c\/li\u003e\n\u003cli\u003eKeeps the EU Declaration of Conformity and technical documentation available for market surveillance authorities\u003c\/li\u003e\n\u003cli\u003eResponds to reasoned requests for compliance information and documentation\u003c\/li\u003e\n\u003cli\u003eCooperates with EU market surveillance authorities regarding products covered by the mandate\u003c\/li\u003e\n\u003cli\u003eSupports regulatory communication, documentation requests, and traceability checks\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThe manufacturer remains responsible for the design, development, production, cybersecurity, conformity assessment, vulnerability handling, security updates, incident reporting, and continued compliance of the product.\u003c\/p\u003e\n\u003ch2\u003eSuitable Product Categories\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSmart home devices\u003c\/li\u003e\n\u003cli\u003eInternet of Things (IoT) products\u003c\/li\u003e\n\u003cli\u003eConsumer electronics\u003c\/li\u003e\n\u003cli\u003eConnected household appliances\u003c\/li\u003e\n\u003cli\u003eWearable devices\u003c\/li\u003e\n\u003cli\u003eSmart lighting products\u003c\/li\u003e\n\u003cli\u003eNetwork equipment\u003c\/li\u003e\n\u003cli\u003eSecurity cameras\u003c\/li\u003e\n\u003cli\u003eConnected toys\u003c\/li\u003e\n\u003cli\u003eIndustrial IoT equipment\u003c\/li\u003e\n\u003cli\u003eSmart sensors\u003c\/li\u003e\n\u003cli\u003eWireless devices\u003c\/li\u003e\n\u003cli\u003eBattery-powered connected products\u003c\/li\u003e\n\u003cli\u003eSoftware supplied with connected hardware\u003c\/li\u003e\n\u003cli\u003eStandalone software products\u003c\/li\u003e\n\u003cli\u003eOther products with digital elements\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003e\u003cstrong\u003eThe EU Cyber Resilience Act Compliance and EAR Process in Five Steps\u003c\/strong\u003e\u003c\/h3\u003e\n\u003cstyle\u003e\n  #cra-process-block {\n    --ease-green: #edffa7;\n    --ease-purple: #9B046F;\n    --ease-pink: #ffe5e5;\n    --ease-homebg: #f9f9f9;\n    --ease-accent: #36454F;\n    --step-badge-color: #36454F;\n    --step-left-pad: 32px;\n    background: transparent;\n    border: 0 solid #ddd;\n    border-radius: 0;\n    padding: 0;\n    margin: 0 0 60px 0;\n    font-size: 1.5rem;\n  }\n  #cra-process-block h3,\n  #cra-process-block .cra-step-card p:first-of-type \u003e b {\n    color: var(--ease-accent);\n    font-size: 1.5rem;\n  }\n  #cra-process-block ol.cra-steps {\n    list-style: none;\n    padding: 0;\n    margin: 0;\n    counter-reset: cra-step;\n  }\n  #cra-process-block ol.cra-steps \u003e li {\n    counter-increment: cra-step;\n    margin: 30px 15px;\n  }\n  #cra-process-block .cra-step-card {\n    position: relative;\n    background: var(--ease-homebg);\n    border: 1px solid #ddd;\n    border-radius: 10px;\n    padding: 16px 16px 16px var(--step-left-pad);\n  }\n  #cra-process-block .cra-step-card::before {\n    content: \"STEP \" counter(cra-step);\n    position: absolute;\n    left: 16px;\n    top: 0;\n    transform: translateY(-50%);\n    height: 22px;\n    line-height: 22px;\n    padding: 0 8px;\n    border-radius: 9999px;\n    color: var(--step-badge-color);\n    border: 1px solid var(--step-badge-color);\n    background: #fff;\n    font-weight: 600;\n    font-size: 10px;\n    letter-spacing: 0.04em;\n    text-transform: uppercase;\n    opacity: 0.88;\n    z-index: 1;\n  }\n  @media (max-width: 480px) {\n    #cra-process-block {\n      font-size: 1.1rem;\n    }\n    #cra-process-block .cra-step-card {\n      padding-left: calc(var(--step-left-pad) + 4px);\n    }\n  }\n  #cra-process-block p {\n    margin: 0;\n    color: #1f2937;\n  }\n  #cra-process-block p + p {\n    margin-top: 8px;\n  }\n  #cra-process-block a {\n    text-decoration: underline;\n    color: #1f2937;\n  }\n\u003c\/style\u003e\n\u003csection id=\"cra-process-block\"\u003e\n\u003col class=\"cra-steps\"\u003e\n\u003cli\u003e\n\u003cdiv class=\"cra-step-card\"\u003e\n\u003cp\u003e\u003cb\u003eMap the Product, Software, and Digital Environment\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eWe document how the product or software is supplied, installed, accessed, connected, updated, and maintained. The review covers software and firmware versions, operating environments, cloud dependencies, APIs, network interfaces, user roles, authentication methods, data flows, deployment models, supported platforms, external services, and connections to other devices or systems.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cdiv class=\"cra-step-card\"\u003e\n\u003cp\u003e\u003cb\u003eReview the Cybersecurity Lifecycle and CRA Scope\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eWe assess the product’s intended use, digital functions, cybersecurity architecture, conformity assessment route, and applicable CRA obligations. We also review the manufacturer’s secure development lifecycle, including source-code controls, dependency management, change approval, security testing, release procedures, issue tracking, patch development, access controls, and internal cybersecurity responsibilities.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cdiv class=\"cra-step-card\"\u003e\n\u003cp\u003e\u003cb\u003eAssess Risks, Dependencies, Vulnerabilities, and the SBOM\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eWe review the cybersecurity risk assessment, software components, open-source libraries, third-party packages, cloud services, and external dependencies. Where available, we assess the Software Bill of Materials (SBOM), vulnerability records, dependency inventory, severity-assessment process, remediation workflow, coordinated vulnerability disclosure procedure, security-update process, and support-period commitments.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cdiv class=\"cra-step-card\"\u003e\n\u003cp\u003e\u003cb\u003ePrepare and Review the CRA Compliance Documentation\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eEaseCert prepares, reviews, or organizes the agreed regulatory documentation. This may include the cybersecurity risk assessment, product and software architecture description, technical documentation, SBOM records, vulnerability-handling procedure, coordinated vulnerability disclosure policy, software update procedure, support-period statement, security information for users, incident-reporting workflow, traceability information, and EU Declaration of Conformity.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cdiv class=\"cra-step-card\"\u003e\n\u003cp\u003e\u003cb\u003eAppoint EaseCert as EU Authorised Representative\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003eAfter the compliance review is completed and the written mandate is signed, EaseCert GmbH is appointed as the manufacturer’s EU Authorised Representative for the covered products. EaseCert retains the EU Declaration of Conformity and technical documentation, responds to reasoned requests from market surveillance authorities, and cooperates with authorities regarding compliance risks and corrective actions. The appointment remains subject to the agreed mandate, service terms, and continued compliance of the covered products.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/li\u003e\n\u003c\/ol\u003e\n\u003c\/section\u003e\n\u003ch2\u003eEU Authorised Representative Service\u003c\/h2\u003e\n\u003cp\u003eThe EU Authorised Representative service is included for manufacturers established outside the European Union.\u003c\/p\u003e\n\u003cp\u003eThe appointment is formalized through a written mandate identifying the manufacturer, the covered products, and the regulatory tasks assigned to EaseCert.\u003c\/p\u003e\n\u003ch3\u003eEaseCert’s EAR Responsibilities\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAct as the appointed EU Authorised Representative under the Cyber Resilience Act\u003c\/li\u003e\n\u003cli\u003eMaintain a copy of the signed written mandate\u003c\/li\u003e\n\u003cli\u003eKeep the EU Declaration of Conformity available to market surveillance authorities\u003c\/li\u003e\n\u003cli\u003eKeep the required technical documentation available to market surveillance authorities\u003c\/li\u003e\n\u003cli\u003eProvide compliance information and documentation following a reasoned authority request\u003c\/li\u003e\n\u003cli\u003eCooperate with authorities regarding risks presented by covered products\u003c\/li\u003e\n\u003cli\u003eSupport regulatory communication and documentation requests\u003c\/li\u003e\n\u003cli\u003eSupport traceability checks concerning the manufacturer and covered products\u003c\/li\u003e\n\u003cli\u003eInform the manufacturer of relevant regulatory inquiries received by EaseCert\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eManufacturer Responsibilities\u003c\/h3\u003e\n\u003cp\u003eThe appointment of EaseCert does not transfer the manufacturer’s core obligations under the Cyber Resilience Act.\u003c\/p\u003e\n\u003cp\u003eThe manufacturer remains responsible for:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDesigning and developing compliant products and software\u003c\/li\u003e\n\u003cli\u003ePerforming and maintaining the cybersecurity risk assessment\u003c\/li\u003e\n\u003cli\u003eMeeting the essential cybersecurity requirements\u003c\/li\u003e\n\u003cli\u003eConducting the applicable conformity assessment\u003c\/li\u003e\n\u003cli\u003ePreparing and maintaining accurate technical documentation\u003c\/li\u003e\n\u003cli\u003eSigning the EU Declaration of Conformity\u003c\/li\u003e\n\u003cli\u003eAffixing the CE marking where required\u003c\/li\u003e\n\u003cli\u003eMonitoring and addressing vulnerabilities\u003c\/li\u003e\n\u003cli\u003eProviding security updates during the support period\u003c\/li\u003e\n\u003cli\u003eReporting actively exploited vulnerabilities and severe security incidents\u003c\/li\u003e\n\u003cli\u003eTaking corrective action where a product is non-compliant or presents a cybersecurity risk\u003c\/li\u003e\n\u003cli\u003eInforming EaseCert of relevant product, software, ownership, or compliance changes\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eWhat Is Included\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCyber Resilience Act applicability assessment\u003c\/li\u003e\n\u003cli\u003eProduct and software scope review\u003c\/li\u003e\n\u003cli\u003eReview of the conformity assessment route\u003c\/li\u003e\n\u003cli\u003eReview of existing technical documentation\u003c\/li\u003e\n\u003cli\u003eReview of cybersecurity documentation\u003c\/li\u003e\n\u003cli\u003eCybersecurity compliance gap analysis\u003c\/li\u003e\n\u003cli\u003eReview of the secure software development lifecycle\u003c\/li\u003e\n\u003cli\u003eReview of product identification and traceability\u003c\/li\u003e\n\u003cli\u003eReview of product labelling and CE marking information\u003c\/li\u003e\n\u003cli\u003eReview of user documentation and security instructions\u003c\/li\u003e\n\u003cli\u003eReview of vulnerability-handling procedures\u003c\/li\u003e\n\u003cli\u003eReview of software update and maintenance procedures\u003c\/li\u003e\n\u003cli\u003eReview of the Software Bill of Materials, if available\u003c\/li\u003e\n\u003cli\u003eReview of support-period documentation\u003c\/li\u003e\n\u003cli\u003eEU Declaration of Conformity review\u003c\/li\u003e\n\u003cli\u003eWritten compliance report and recommendations\u003c\/li\u003e\n\u003cli\u003eWritten EU Authorised Representative mandate\u003c\/li\u003e\n\u003cli\u003eAppointment of EaseCert GmbH as EU Authorised Representative\u003c\/li\u003e\n\u003cli\u003eRetention of the EU Declaration of Conformity and technical documentation\u003c\/li\u003e\n\u003cli\u003eEU-based regulatory point of contact\u003c\/li\u003e\n\u003cli\u003eSupport with market surveillance authority requests\u003c\/li\u003e\n\u003cli\u003eRegulatory guidance throughout the project\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eRequired Documentation\u003c\/h2\u003e\n\u003ch3\u003eManufacturer Information\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLegal company name\u003c\/li\u003e\n\u003cli\u003eRegistered business address\u003c\/li\u003e\n\u003cli\u003eCompany registration number\u003c\/li\u003e\n\u003cli\u003eContact person\u003c\/li\u003e\n\u003cli\u003eEmail address\u003c\/li\u003e\n\u003cli\u003eTelephone number\u003c\/li\u003e\n\u003cli\u003eWebsite\u003c\/li\u003e\n\u003cli\u003eEU importer information, if applicable\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eProduct Information\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eProduct name\u003c\/li\u003e\n\u003cli\u003eBrand name\u003c\/li\u003e\n\u003cli\u003eModel number\u003c\/li\u003e\n\u003cli\u003eSKU or product identifier\u003c\/li\u003e\n\u003cli\u003eTechnical specifications\u003c\/li\u003e\n\u003cli\u003eProduct photographs\u003c\/li\u003e\n\u003cli\u003eIntended purpose and intended users\u003c\/li\u003e\n\u003cli\u003eCommunication technologies\u003c\/li\u003e\n\u003cli\u003eUser manual\u003c\/li\u003e\n\u003cli\u003ePackaging artwork\u003c\/li\u003e\n\u003cli\u003eProduct labels\u003c\/li\u003e\n\u003cli\u003eCE marking information\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eSoftware and Cybersecurity Information\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFirmware and software versions\u003c\/li\u003e\n\u003cli\u003eSoftware and hardware architecture\u003c\/li\u003e\n\u003cli\u003eCommunication protocols\u003c\/li\u003e\n\u003cli\u003eNetwork interfaces\u003c\/li\u003e\n\u003cli\u003eCloud services and external dependencies\u003c\/li\u003e\n\u003cli\u003eAuthentication and access-control methods\u003c\/li\u003e\n\u003cli\u003eEncryption methods, where applicable\u003c\/li\u003e\n\u003cli\u003eSoftware update mechanism\u003c\/li\u003e\n\u003cli\u003eSecurity update and patching process\u003c\/li\u003e\n\u003cli\u003eVulnerability-handling procedure\u003c\/li\u003e\n\u003cli\u003eCoordinated vulnerability disclosure policy\u003c\/li\u003e\n\u003cli\u003eSupport period\u003c\/li\u003e\n\u003cli\u003eSoftware Bill of Materials, if available\u003c\/li\u003e\n\u003cli\u003eSecure development lifecycle documentation\u003c\/li\u003e\n\u003cli\u003eIncident-reporting procedure\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eExisting Compliance Documentation\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEU Declaration of Conformity\u003c\/li\u003e\n\u003cli\u003eTechnical documentation\u003c\/li\u003e\n\u003cli\u003eCybersecurity risk assessment\u003c\/li\u003e\n\u003cli\u003eApplicable CE test reports\u003c\/li\u003e\n\u003cli\u003eSoftware and firmware documentation\u003c\/li\u003e\n\u003cli\u003eExisting cybersecurity test reports\u003c\/li\u003e\n\u003cli\u003ePenetration test reports, if available\u003c\/li\u003e\n\u003cli\u003eVulnerability scan reports, if available\u003c\/li\u003e\n\u003cli\u003eCertification reports, if available\u003c\/li\u003e\n\u003cli\u003eExisting authorised representative agreements, if applicable\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003eService Limitations\u003c\/h2\u003e\n\u003cp\u003eEaseCert provides regulatory consulting, compliance assessment, documentation support, and EU Authorised Representative services within the scope of the signed mandate.\u003c\/p\u003e\n\u003cp\u003eUnless separately agreed in writing, the service does not include:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003ePenetration testing\u003c\/li\u003e\n\u003cli\u003eSource-code review\u003c\/li\u003e\n\u003cli\u003eVulnerability scanning\u003c\/li\u003e\n\u003cli\u003eEthical hacking\u003c\/li\u003e\n\u003cli\u003eLaboratory testing\u003c\/li\u003e\n\u003cli\u003eCybersecurity certification\u003c\/li\u003e\n\u003cli\u003eNotified Body conformity assessment\u003c\/li\u003e\n\u003cli\u003eDevelopment or modification of software\u003c\/li\u003e\n\u003cli\u003eSoftware remediation or vulnerability correction\u003c\/li\u003e\n\u003cli\u003eContinuous technical vulnerability monitoring\u003c\/li\u003e\n\u003cli\u003eSecurity operations centre services\u003c\/li\u003e\n\u003cli\u003eTechnical incident response\u003c\/li\u003e\n\u003cli\u003eProduct or software redesign\u003c\/li\u003e\n\u003cli\u003eSubmission of manufacturer reports unless expressly included in the written mandate and legally permitted\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eWhere technical cybersecurity testing is required, EaseCert can help define the testing scope and coordinate with a qualified cybersecurity laboratory or technical provider.\u003c\/p\u003e\n\u003cp\u003eEaseCert’s appointment as EU Authorised Representative does not constitute product certification, approval, or confirmation that the product is free from cybersecurity vulnerabilities.\u003c\/p\u003e\n\u003cp\u003eThe manufacturer remains legally responsible for the cybersecurity, conformity, accuracy of the documentation, and continued compliance of its products.\u003c\/p\u003e\n\u003ch2\u003eProcessing Time\u003c\/h2\u003e\n\u003cp\u003eMost initial compliance reviews are completed within approximately 5 to 10 business days after receipt of all required documentation.\u003c\/p\u003e\n\u003cp\u003eThe EU Authorised Representative appointment becomes effective after the documentation review has been completed, the covered products have been accepted by EaseCert, and the written mandate has been signed by both parties.\u003c\/p\u003e\n\u003cp\u003eProcessing times may vary depending on product complexity, the number of product groups, the completeness of the submitted documentation, the conformity assessment route, and whether additional technical testing is required.\u003c\/p\u003e\n\u003cdiv id=\"faq\" style=\"background-color: #f9f9f9; padding: 24px; border: 1px solid #ddd; border-radius: 8px; margin-top: 40px; margin-bottom: 40px;\"\u003e\n\u003ch2 style=\"margin-top: 0;\"\u003eFrequently Asked Questions\u003c\/h2\u003e\n\u003ch3\u003eWhat is the EU Cyber Resilience Act?\u003c\/h3\u003e\n\u003cp\u003eThe EU Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements placed on the European Union market. It addresses cybersecurity throughout the product lifecycle, including design, development, vulnerability handling, security updates, technical documentation, conformity assessment, and post-market monitoring.\u003c\/p\u003e\n\u003ch3\u003eDoes this service include an EU Authorised Representative?\u003c\/h3\u003e\n\u003cp\u003eYes. Appointment of EaseCert GmbH as the manufacturer’s EU Authorised Representative under the Cyber Resilience Act is included for the products accepted within the agreed service scope.\u003c\/p\u003e\n\u003cp\u003eThe appointment becomes effective after the compliance review is completed and the written mandate is signed by the manufacturer and EaseCert.\u003c\/p\u003e\n\u003ch3\u003eWhat does EaseCert do as the EU Authorised Representative?\u003c\/h3\u003e\n\u003cp\u003eEaseCert keeps the EU Declaration of Conformity and technical documentation available for market surveillance authorities, responds to reasoned requests for compliance information, and cooperates with authorities regarding products covered by the written mandate.\u003c\/p\u003e\n\u003ch3\u003eDoes appointing EaseCert transfer the manufacturer’s responsibilities?\u003c\/h3\u003e\n\u003cp\u003eNo. The manufacturer remains responsible for product design, software development, cybersecurity risk management, conformity assessment, technical documentation, vulnerability handling, security updates, incident reporting, corrective action, and continued compliance.\u003c\/p\u003e\n\u003ch3\u003eMust the appointment be documented?\u003c\/h3\u003e\n\u003cp\u003eYes. The appointment is established through a written mandate identifying the manufacturer, EaseCert GmbH, the covered products, and the regulatory tasks assigned to EaseCert.\u003c\/p\u003e\n\u003ch3\u003eWhich products are covered by the Cyber Resilience Act?\u003c\/h3\u003e\n\u003cp\u003eThe regulation generally applies to hardware and software products with digital elements that connect directly or indirectly to another device or network. This may include connected consumer products, IoT devices, network equipment, industrial digital products, embedded software, and standalone software.\u003c\/p\u003e\n\u003ch3\u003eDoes the Cyber Resilience Act apply to standalone software?\u003c\/h3\u003e\n\u003cp\u003eIn many cases, yes. Standalone software placed on the EU market may fall within the scope of the Cyber Resilience Act, depending on how it is supplied, its intended purpose, and whether an exclusion applies.\u003c\/p\u003e\n\u003ch3\u003eWhen do the Cyber Resilience Act requirements apply?\u003c\/h3\u003e\n\u003cp\u003eThe Cyber Resilience Act entered into force on 10 December 2024. The main requirements apply from 11 December 2027. The vulnerability and severe incident-reporting obligations apply from 11 September 2026.\u003c\/p\u003e\n\u003ch3\u003eWhat is a Software Bill of Materials?\u003c\/h3\u003e\n\u003cp\u003eA Software Bill of Materials (SBOM) is a structured inventory of software components, libraries, dependencies, and third-party elements used in a product. It helps manufacturers determine whether a product is affected when a vulnerability is identified.\u003c\/p\u003e\n\u003ch3\u003eDo I need cybersecurity testing?\u003c\/h3\u003e\n\u003cp\u003eTesting requirements depend on the product, cybersecurity risks, applicable standards, product classification, and conformity assessment route. EaseCert reviews the available evidence and identifies whether additional testing or third-party assessment may be required.\u003c\/p\u003e\n\u003ch3\u003eDoes EaseCert perform penetration testing?\u003c\/h3\u003e\n\u003cp\u003eNo. Penetration testing, source-code analysis, vulnerability scanning, and specialist cybersecurity testing must be performed by a qualified technical provider. EaseCert can assist with defining and coordinating the required testing scope.\u003c\/p\u003e\n\u003ch3\u003eDoes EaseCert certify the product?\u003c\/h3\u003e\n\u003cp\u003eNo. EaseCert provides regulatory compliance support and acts as the EU Authorised Representative. EaseCert does not issue cybersecurity certificates, perform laboratory testing, or act as a Notified Body.\u003c\/p\u003e\n\u003ch3\u003eCan EaseCert prepare the required documentation?\u003c\/h3\u003e\n\u003cp\u003eYes. Depending on the agreed scope, EaseCert can prepare, review, or organize CRA documentation, including the cybersecurity risk assessment, technical documentation, vulnerability-handling procedure, software update process, support-period documentation, user security information, and EU Declaration of Conformity.\u003c\/p\u003e\n\u003ch3\u003eCan several models be covered by one appointment?\u003c\/h3\u003e\n\u003cp\u003eModels sharing the same software platform, firmware, hardware architecture, connectivity, update mechanism, intended purpose, and cybersecurity controls may sometimes be grouped together. EaseCert reviews the product range before confirming the scope.\u003c\/p\u003e\n\u003ch3\u003eDoes the service include continuous vulnerability monitoring?\u003c\/h3\u003e\n\u003cp\u003eNo. The standard service does not include continuous technical monitoring, security operations, software maintenance, or incident response. The manufacturer must maintain suitable post-market cybersecurity processes throughout the applicable support period.\u003c\/p\u003e\n\u003ch3\u003eHow long does the service take?\u003c\/h3\u003e\n\u003cp\u003eMost initial reviews are completed within approximately 5 to 10 business days after all required documentation has been received. The EAR appointment begins once the review is complete and the written mandate has been signed.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003ch2\u003eStart Your EU Cybersecurity Compliance and EAR Project\u003c\/h2\u003e\n\u003cp\u003ePlace your order and EaseCert will contact you by email with the required documentation list, written mandate, and next steps for the Cyber Resilience Act compliance review and EU Authorised Representative appointment.\u003c\/p\u003e","brand":"EaseCert | GPSR Compliance","offers":[{"title":"Default Title","offer_id":50521237618917,"sku":"EC-CRA-EAR","price":1050.0,"currency_code":"EUR","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0731\/2565\/8853\/files\/EU_Cyber_Resilience_Act_Compliance_and_Authorised_Representative_Service.heic?v=1784678619","url":"https:\/\/easecert.com\/products\/eu-cyber-resilience-act-compliance-service","provider":"EaseCert | GPSR Compliance","version":"1.0","type":"link"}