wolfssl-examples/cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representativ...

64 lines
3.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters!

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

# EU Authorised Representative — wolfSSL Inc.
**Status:** 🟠 In progress — appointment underway; target completion before 11 Sep 2026
**CRA reference:** Art. 18
## Why an EU AR is required
wolfSSL Inc. is established in the **United States** (Edmonds, Washington). CRA
Art. 18 requires manufacturers established outside the EU to appoint, **in
writing**, an Authorised Representative inside the EU before placing a product
on the EU market. The AR:
- Receives correspondence from EU market surveillance authorities and ENISA on the manufacturer's behalf.
- Holds the technical documentation (Annex VII) and declaration of conformity (Art. 28) for **10 years** post-placement, available to authorities on request.
- Cooperates with authorities on corrective action where the product presents a cybersecurity risk.
The AR does **not** transfer manufacturer obligations — wolfSSL Inc. remains
the manufacturer and bears the substantive obligations. The AR is a single
point of contact in the EU.
## Current state
🟠 **wolfSSL Inc. is finalising the EU AR appointment.** Two paths were evaluated:
1. **Use an existing wolfSSL EU presence.** wolfSSL has business operations in
the DACH region (Germany / Austria / Switzerland). Nominating an existing
EU-resident wolfSSL legal entity as the AR is the simplest path if such an
entity exists with the appropriate legal capacity to act as AR.
2. **Contract a third-party AR service.** Several vendors (e.g. Obelis, Authrep,
Casa Group) offer AR-as-a-service across CE-marking regulations. Cost is
typically EUR 15004000/year per regulation; lead time 46 weeks.
The internal decision is being finalised by wolfSSL leadership. The written
mandate will be in place before 11 Sep 2026 (Art. 14 vulnerability reporting
onset) and certainly before 11 Dec 2027 (full CRA applicability).
## Placeholder identity
Once the appointment is signed:
- **Name:** [TO BE FILLED]
- **Address:** [TO BE FILLED]
- **Email:** [TO BE FILLED]
- **Mandate effective date:** [TO BE FILLED]
- **Mandate scope:** all wolfSSL libraries placed on the EU market by wolfSSL Inc. under CRA.
## What this means for customers
If your company is established **outside the EU** (US / UK post-Brexit / Asia /
elsewhere), you face the same Art. 18 obligation. wolfSSL's choice of AR does
not satisfy your obligation — you appoint your own.
The single-most-important advice we can give: **start now**. AR appointments
take weeks to months including legal review on both sides; the lead time
compounds with conformity assessment timelines and is the most common
last-minute blocker for non-EU manufacturers.
## References
- CRA Art. 18 (Authorised Representative)
- CRA Art. 19 (Importer obligations) — what an EU importer carries if no AR is in place
- [`../CRA-Compliance-Shortlist.md`](../CRA-Compliance-Shortlist.md) — "Beyond this kit"
- [`../CRA-Supply-Chain-Glossary.md`](../CRA-Supply-Chain-Glossary.md) — EU Authorised Representative