Nordchecks
← All guides

Does the CRA apply to non-EU companies?

Yes — the EU Cyber Resilience Act is market-based, not establishment-based. If you sell a product with digital elements into the EU, it applies wherever your company is based.

Nordchecks TeamPublished 8 min

Not sure if you’re in scope?

Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.

Check if the CRA applies to you

In short

Yes. The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is market-based, not establishment-based: it applies to every product with digital elements made available on the EU market, regardless of where the manufacturer is headquartered. A US, UK or Asian company that sells into the EU carries the same obligations — SBOM, monitoring, 24-hour reporting, technical documentation and CE marking — and the same deadlines: 11 September 2026 and 11 December 2027. Non-EU manufacturers also typically need an EU-based authorised representative.

One of the most common misreadings of the Cyber Resilience Act is that it only binds European companies. It does not. The CRA follows the product into the market, not the company that made it. If a device or piece of software with digital elements is placed on or made available on the EU market, it is in scope — whether it was built in San Francisco, Manchester, Shenzhen or Bangalore.

This guide explains what “placed on the EU market” means, how selling into the EU triggers the regulation, which role you occupy in the supply chain, and why most non-EU manufacturers will need an EU-based point of contact.

Not sure the CRA applies to your product? Run the free 3-minute scope check first — it returns your risk class and the deadlines that apply to you.

Is the CRA based on where my company is located?

No — and this is the single most important thing to understand. The CRA is a product regulation under EU single-market law, the same legal family as the CE-marking rules for toys, machinery and radio equipment. Its trigger is a product being made available on the EU market, defined as any supply for distribution or use in the course of a commercial activity, whether for payment or free of charge.

That means your headquarters, your incorporation, your tax residence and the location of your servers are all irrelevant to scope. What matters is a single question: does your product with digital elements reach EU users? If yes, you are in scope.

What does “placed on the EU market” mean?

“Placing on the market” is the first time a product is made available on the EU market. “Making available” is any subsequent supply. Both are commercial acts, and the CRA reaches all of them. In practice, you sell into the EU — and therefore fall in scope — through three main channels, and every one of them counts:

  • Direct sales. You ship hardware to EU customers, or EU users download and install your software or firmware directly from you.
  • Through distributors or importers. An EU-based importer or distributor resells your product. You are still the manufacturer; they take on their own duties (see below).
  • Through an online marketplace. Listing a product that ships to EU buyers on a marketplace is making it available on the EU market. The marketplace being non-EU does not change that.

If any of these describe you, the regulation applies to your product regardless of your company’s location.

Does the CRA apply to US companies?

Yes. A US company selling into the EU is treated exactly like an EU manufacturer. Consider a US IoT maker shipping a Wi-Fi security camera to European buyers through its own webstore and through Amazon: the camera is a product with digital elements made available on the EU market, so the full obligation set attaches — a Software Bill of Materials, vulnerability monitoring, the 24-hour ENISA reporting readiness, technical documentation per Annex VII, and CE marking. There is no US carve-out, and compliance with US frameworks (NIST, FCC, state IoT laws) does not substitute for the CRA.

What about UK companies after Brexit?

Also yes. Leaving the EU changed nothing about the CRA’s reach — if anything, it made UK companies clearly “non-EU” for these purposes. A UK software vendor whose desktop application or firmware is downloaded and installed by customers in Germany, France or the Netherlands is placing a product with digital elements on the EU market. The obligations and deadlines are identical to those facing an EU-based vendor, and a UK company will typically need an EU-based authorised representative just as a US or Asian one would. UK conformity marking (UKCA) is separate and does not satisfy the CRA.

Which role do I have — and what does each role owe?

The CRA assigns duties by role in the supply chain, not by nationality. A non-EU company can occupy more than one role at once.

RoleWho it isCore duties
ManufacturerWhoever develops the product, or has it developed, and markets it under their nameThe full set: risk assessment, SBOM, vulnerability handling, 24h/72h reporting, technical documentation, CE marking
Authorised representativeAn EU-based party the manufacturer appoints in writingHolds documentation, cooperates with market surveillance authorities, acts as the EU point of contact
ImporterAn EU-based party placing a non-EU manufacturer’s product on the marketVerify the manufacturer did the conformity work, CE marking and documentation exist; do not place non-compliant products; keep records
DistributorAnyone further down the chain making the product availableAct with due care; check CE marking and documentation are present; stop distribution if they learn a product is non-compliant

The practical consequence for a non-EU manufacturer: you carry the manufacturer’s obligations in full, and you generally need an EU-based authorised representative as a point of contact for market surveillance authorities. Your EU importers and distributors do not absorb your obligations — they add their own verification duties on top, and increasingly they will refuse to stock a product whose documentation and SBOM are not in order, because non-compliance exposes them too.

A non-EU manufacturer carries the full CRA obligation set from outside the EU — SBOM, monitoring, 24-hour reporting and the technical file — while EU importers demand evidence before they will stock the product.

Nordchecks builds and maintains that evidence for you: SBOM per product, daily vulnerability matching and pre-filled ENISA notifications, ready to hand to your authorised representative and importers.

Try Nordchecks free

Are the obligations and deadlines any different for non-EU companies?

No. This is worth stating plainly because teams outside the EU often hope for a lighter regime. There is none. The same substantive requirements apply — a Software Bill of Materials in CycloneDX or SPDX, continuous vulnerability monitoring, the reporting sequence (early warning within 24 hours, vulnerability notification within 72 hours, final report within 14 days, weekends included, to ENISA and the relevant national CSIRT), Annex VII technical documentation, and CE marking — and the same two deadlines govern the timeline:

  • 11 September 2026 — the 24-hour vulnerability and incident reporting obligation begins, including for products already on the EU market.
  • 11 December 2027 — full compliance, including SBOM, technical documentation and CE marking, is required to place a product on the EU market.

Enforcement reaches non-EU companies through the same mechanisms: market surveillance authorities can order non-compliant products off the EU market, and fines run up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. “Worldwide turnover” means a non-EU company’s global revenue is the base, not just its EU sales.

What should a non-EU company do first?

Work in the same order an EU manufacturer would, with one addition at the front:

  1. Confirm scope and class. Establish that your product is in scope and which risk class it falls into (roughly 90% of products are default class and self-assess). Our deadlines guide maps what each date requires.
  2. Appoint an EU-based authorised representative. Put the mandate in writing before December 2027; importers and authorities will ask for it.
  3. Build the compliance core. SBOM, monitoring, reporting readiness, technical documentation. The CRA compliance checklist sequences every step, and much of it can be run by dedicated CRA compliance software rather than assembled by hand.

If part of what you sell is a pure cloud service, note that the SaaS boundary works the same way for non-EU companies as for EU ones — our guide on whether the CRA applies to SaaS walks that line. Scope follows the market either way: your headquarters never puts you outside it.

Three minutes to certainty: check whether your product is in scope — no signup, based on the regulation text.

Does the CRA apply to your product?

Find out in three minutes — your risk class, the deadlines that apply, and exactly what you’ll need to comply.

Start the free check