Skip to main content
  • Infographic

Connections and relationships between CRA stakeholders

The Cyber Resilience Act impacts various stakeholders within the cybersecurity ecosystem. Learn more about how these stakeholders interact.

Person working on a computer with the screen reflecting in their glasses

The Cyber Resilience Act (CRA) establishes a risk-based framework that significantly impacts various stakeholders within the cybersecurity ecosystem for digital products and software on the EU market. This includes manufacturers, importers, authorized representatives, distributors, market surveillance authorities and cybersecurity organizations like the European Union Agency for Cybersecurity (ENISA) and Cyber Security Incident Response Teams (CSIRTs). Each stakeholder has a unique yet interconnected role in confirming compliance and enhancing resilience.​

​These relationships are both regulatory and collaborative, creating a complex web of responsibilities and information sharing. In the following infographic, we will examine how these stakeholders interact, support one another and work together to uphold the CRA’s objectives of improving cybersecurity across the European Union.

First stakeholder​Second stakeholder​Relationship between first stakeholder and second stakeholder​
Non EU-based manufactureAuthorized representative​Formally appoints​
Authorized representative​Market Surveillance AuthorityProvides technical documentation and responds to product issue
Non EU/EU-based manufacturerNotified Body​Provides technical security documentation for assessment​
Non EU/EU-based manufacturerMarket Surveillance AuthorityProvides assessment documents for inspection and compliance enforcement​
Authorized representative​CSIRTsReports actively exploited vulnerabilities and cybersecurity incidents
EU-based manufacturerCSIRTsReports actively exploited vulnerabilities and cybersecurity incidents
Authorized representativeENISAShares notification of actively exploited vulnerabilities and cybersecurity incidents
EU-based manufacturer​ENISAShares notification of actively exploited vulnerabilities and cybersecurity incidents
CSIRTsENISAShares data on threats, vulnerabilities and incidents
Market Surveillance AuthorityENISACollaborates with ENISA in case of significant cybersecurity incidents and threat intelligence
Importer​ENISAReports suspected cybersecurity risk
DistributorENISAReports suspected cybersecurity risk
DistributorImporter​Reports suspected cybersecurity risk
Importer​DistributorSupplies product
Non EU-based manufacturerImporter​Shares CE marking and documentation for product placement

Want to know more about how we can help you reach CRA compliance?

Prepare for the CRA and contact us today.

X

Want to know more about how we can help you reach CRA compliance?

Prepare for the CRA and contact us today.

Please wait…