diff --git a/cra-kit/CRA-Cheat-Sheet.md b/cra-kit/CRA-Cheat-Sheet.md index 16dcd3552..4345aa01d 100644 --- a/cra-kit/CRA-Cheat-Sheet.md +++ b/cra-kit/CRA-Cheat-Sheet.md @@ -89,7 +89,7 @@ the EU market you also need: | Obligation | Article | Action | |------------|---------|--------| -| **EU Authorised Representative** | Art. 18 | Required if you're established outside the EU | +| **EU Authorised Representative** | Art. 18 | **Optional** under the CRA (Art. 18(1): *may*); check other EU acts covering your product | | **Product class** (Annex III/IV) | — | Determines self-cert vs **Notified Body** — long queues | | **Conformity assessment + CE mark** | Art. 32, 30 | Module A or external review | | **Technical documentation** | Annex VII | Risk assessment, support-period commitment | diff --git a/cra-kit/CRA-Compliance-Shortlist.md b/cra-kit/CRA-Compliance-Shortlist.md index 96d83a5e5..2e09da91b 100644 --- a/cra-kit/CRA-Compliance-Shortlist.md +++ b/cra-kit/CRA-Compliance-Shortlist.md @@ -73,7 +73,7 @@ SBOMs alone make you ready: | Obligation | Article | What it means | |------------|---------|---------------| -| **EU Authorised Representative** | Art. 18 | Manufacturers established **outside** the EU must appoint a written-mandated representative **inside** the EU before placing a product on the EU market. Either contract a third-party AR service or use an existing EU subsidiary. | +| **EU Authorised Representative** | Art. 18 | **Discretionary under the CRA.** Art. 18(1): a manufacturer *may* appoint one by written mandate. The Art. 18(3) tasks (hold the DoC and technical documentation, answer reasoned requests, cooperate on risk action) duplicate duties the manufacturer already carries under Art. 13(13). The practical reason to appoint one is control: Art. 14(7)(a) then fixes your coordinator CSIRT. Other EU acts covering finished products may require an EU representative outright. | | **Product classification** | Annex III / IV | Determines whether conformity assessment is self-declared (default class) or requires a **Notified Body** (important / critical class). Notified-body queues are already long — if you may need one, get in queue early. | | **Conformity assessment + CE mark** | Art. 32, 30 | Module A (self-assessment) or external review per classification; CE marking before placing the product on the EU market. | | **Technical documentation** | Annex VII | Risk assessment, secure-design rationale, vulnerability handling process, support-period commitment — more than the SBOM. | @@ -82,7 +82,7 @@ SBOMs alone make you ready: These are **legal and structural decisions**, not artefacts you can generate from source code. wolfSSL ships SBOMs, security-policy templates, and the -narrative in this kit; **you** appoint your EU AR, classify your product, run +narrative in this kit; **you** decide your own Art. 18 position, classify your product, run your conformity assessment, and produce your declaration of conformity. If you do not yet have a CRA consultant, engaging one for the classification + AR questions specifically is usually the highest-leverage @@ -95,7 +95,7 @@ classification statement, conformity assessment route, declaration of conformity template, EU Authorised Representative status, support-period policy, vulnerability-handling process, technical documentation outline, and CE marking statement. Where decisions are made, they're stated; where -they're in flight (EU AR appointment, public SLA), the gap is named. +they're in flight, the gap is named. Adapt as a template for your own product. --- diff --git a/cra-kit/CRA-Supply-Chain-Glossary.md b/cra-kit/CRA-Supply-Chain-Glossary.md index c310828bf..d681d1cf9 100644 --- a/cra-kit/CRA-Supply-Chain-Glossary.md +++ b/cra-kit/CRA-Supply-Chain-Glossary.md @@ -71,7 +71,7 @@ that no SBOM tool can satisfy. **Not legal advice** — engage CRA counsel. | Term | Article / location | Plain English | |------|--------------------|---------------| -| **EU Authorised Representative** (EU AR) | Art. 18 | Required if the manufacturer is established **outside** the EU. A written-mandated EU-resident legal entity that receives regulator correspondence on the manufacturer's behalf. Either contract a third-party AR service or use an existing EU subsidiary. **Long-lead** — start now. | +| **EU Authorised Representative** (EU AR) | Art. 18 | A written-mandated EU-established **natural or legal** person that receives regulator correspondence on the manufacturer's behalf. Appointment is **discretionary** under the CRA: Art. 18(1) says a manufacturer *may* appoint one, and Art. 18(2) bars the mandate from carrying the substantive obligations. Other EU legislation covering finished products may require an EU representative outright. | | **Notified Body** | — | Independent third-party conformity-assessment organisation. For "important" or "critical" products (Annex III/IV) the conformity assessment must involve a Notified Body. Queues are long — engage early if you may need one. | | **Annex III** | Annex III | List of **"important"** products with above-baseline cybersecurity risk (e.g. password managers, network management systems, browsers, certain identity-management components). Triggers stricter conformity assessment than the default class. | | **Annex IV** | Annex IV | List of **"critical"** products (highest-risk class), e.g. hardware security modules, secure-boot devices, smart-meter gateways of certain types. Always requires Notified Body involvement. | diff --git a/cra-kit/README.md b/cra-kit/README.md index 5d85d0a4c..a22110ae0 100644 --- a/cra-kit/README.md +++ b/cra-kit/README.md @@ -258,10 +258,13 @@ distributor obligations. See [`CRA-Compliance-Shortlist.md`](CRA-Compliance-Shor legal/structural decisions, not artefacts. **Are we outside the EU? (US / Asia / etc.)** -Then you almost certainly need an **EU Authorised Representative** (Art. 18) -appointed in writing **before** placing your product on the EU market. Either -contract a third-party AR service or use an existing EU subsidiary. This is a -long-lead item — start now, do not wait for September 2026. +Under the CRA an **EU Authorised Representative** (Art. 18) is **optional**. +Art. 18(1) says a manufacturer *may* appoint one, and the Art. 18(3) tasks +duplicate duties you already carry as manufacturer under Art. 13(13). The reason +to appoint one is control rather than compliance: Art. 14(7)(a) then fixes which +coordinator CSIRT you file to. Note that other EU legislation covering finished +consumer products may require an EU representative outright — check the full set +of acts that applies to your product with counsel. --- diff --git a/cra-kit/ROADMAP.md b/cra-kit/ROADMAP.md index e6bed2e5d..260faa091 100644 --- a/cra-kit/ROADMAP.md +++ b/cra-kit/ROADMAP.md @@ -36,7 +36,7 @@ they're actually inheriting when they reference us as a component supplier. | CNA status | **Available** | wolfSSL is a CVE Numbering Authority | | Public SLA (24h ack / 72h triage) | **Pending leadership approval** | Will be added to CVD policy once approved | | 24h ENISA reporting (Art. 14) runbook | **In progress** | Owner assignment pending; on-call rotation TBD | -| EU Authorised Representative (Art. 18) | **In progress** | wolfSSL Inc. is US-established; AR appointment underway | +| EU Authorised Representative (Art. 18) | **Settled** | Discretionary under Art. 18(1); wolfSSL Inc. performs the Art. 18(3) functions directly | | CSAF 2.0 advisory feed | **Roadmap** | See above | See [`wolfssl-inc-auditor-packet/`](wolfssl-inc-auditor-packet/) for the manufacturer-side diff --git a/cra-kit/SKILL.md b/cra-kit/SKILL.md index 06bdba6f0..e58e5fb02 100644 --- a/cra-kit/SKILL.md +++ b/cra-kit/SKILL.md @@ -59,7 +59,7 @@ Set `WOLFSSL_DIR` to your wolfSSL source tree when regenerating SBOMs. **Before starting**, confirm with the customer (do not assume): -- Where is the customer **established** (US / EU / other)? If outside the EU, flag the **EU Authorised Representative** requirement (Art. 18) — long-lead item, start now. +- Where is the customer **established** (US / EU / other)? Note that a CRA **EU Authorised Representative** (Art. 18) is **discretionary** — Art. 18(1) says a manufacturer *may* appoint one. Other EU instruments covering finished products may require an EU representative outright, so point the customer at counsel for the full set of acts, not at Art. 18. - What is the **product classification** under Annex III/IV? Self-declared (default class) or Notified Body required (important / critical)? Flag if unknown — Notified Body queues are long. - Is the customer's CRA work **on track for 11 Sep 2026** (Art. 14 reporting wave) and **11 Dec 2027** (full applicability)? If structural items are open, SBOM work alone won't make them ready. @@ -95,7 +95,7 @@ Then run the SBOM execution checklist: - **VEX** = customer + scanner; wolfSSL provides advisories, not VEX files. - **bomsh** = optional provenance; not required for most CRA transparency asks. - **Vulnerability handling (Art. 13/14)** = customer publishes their own CVD policy + `security.txt`, runs on-call, files 24h ENISA reports for their product; wolfSSL provides reference templates and handles ENISA reporting only for libraries placed on the EU market by wolfSSL Inc. -- **Structural CRA (out of scope for this kit)** = EU Authorised Representative (Art. 18 — required if customer is outside the EU), Annex III/IV classification (determines self-cert vs Notified Body), conformity assessment + CE mark (Art. 32, 30), technical documentation (Annex VII), support-period commitment (Art. 13(8), 5+ years default). When a customer asks "are we ready?", surface these — SBOMs alone are not enough. Recommend engaging CRA counsel or consultant. +- **Structural CRA (out of scope for this kit)** = EU Authorised Representative (Art. 18 — **discretionary** under the CRA; other EU acts may require one), Annex III/IV classification (determines self-cert vs Notified Body), conformity assessment + CE mark (Art. 32, 30), technical documentation (Annex VII), support-period commitment (Art. 13(8), 5+ years default). When a customer asks "are we ready?", surface these — SBOMs alone are not enough. Recommend engaging CRA counsel or consultant. --- diff --git a/cra-kit/auditor-packet/00-INDEX.md b/cra-kit/auditor-packet/00-INDEX.md index 96ef38605..79260e314 100644 --- a/cra-kit/auditor-packet/00-INDEX.md +++ b/cra-kit/auditor-packet/00-INDEX.md @@ -28,7 +28,7 @@ CRA conformity packet for a real product also includes: - Declaration of conformity (Art. 28) - Technical documentation per Annex VII (risk assessment, design info, support-period commitment, vulnerability handling process) - Proof of conformity assessment (self-declared per Art. 32 Module A, or Notified Body certificate per product class) -- Identity of the EU Authorised Representative (Art. 18) if the manufacturer is established outside the EU +- Identity of the EU Authorised Representative (Art. 18) where one has been mandated - CE marking declaration See [`../CRA-Compliance-Shortlist.md`](../CRA-Compliance-Shortlist.md) diff --git a/cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md b/cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md index 8baf3628d..699c1b10f 100644 --- a/cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md +++ b/cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md @@ -5,7 +5,7 @@ | [`classification-statement.md`](classification-statement.md) | Annex III / IV | ✅ Decided — default category (not Annex III/IV), self-certification | | [`conformity-assessment-route.md`](conformity-assessment-route.md) | Art. 32, Annex VIII | ✅ Module A self-assessment | | [`declaration-of-conformity.template.md`](declaration-of-conformity.template.md) | Art. 28 | 🟡 Template ready; signature pending product release alignment | -| [`eu-authorised-representative.md`](eu-authorised-representative.md) | Art. 18 | 🟠 In progress — appointment underway | +| [`eu-authorised-representative.md`](eu-authorised-representative.md) | Art. 18 | ✅ Settled — appointment is discretionary; Art. 18(3) functions performed directly | | [`support-period-policy.md`](support-period-policy.md) | Art. 13(2), 13(8) | ✅ Decided — 5-year minimum, longer for LTS lines | | [`vulnerability-handling-process.md`](vulnerability-handling-process.md) | Art. 13, 14 | 🟡 Process documented; public SLA pending leadership approval | | [`technical-documentation-outline.md`](technical-documentation-outline.md) | Annex VII | 🟠 In progress — outline complete; per-release packet on roadmap | diff --git a/cra-kit/wolfssl-inc-auditor-packet/README.md b/cra-kit/wolfssl-inc-auditor-packet/README.md index f038652cc..814e3d4c7 100644 --- a/cra-kit/wolfssl-inc-auditor-packet/README.md +++ b/cra-kit/wolfssl-inc-auditor-packet/README.md @@ -26,7 +26,7 @@ fiction. **Not legal advice.** These artefacts are templates and statements of position; they are not, and do not replace, the actual signed legal documents wolfSSL Inc. -files with EU regulators or its EU Authorised Representative. +files with EU regulators. --- diff --git a/cra-kit/wolfssl-inc-auditor-packet/declaration-of-conformity.template.md b/cra-kit/wolfssl-inc-auditor-packet/declaration-of-conformity.template.md index 5fdf88150..e8ef7ebe6 100644 --- a/cra-kit/wolfssl-inc-auditor-packet/declaration-of-conformity.template.md +++ b/cra-kit/wolfssl-inc-auditor-packet/declaration-of-conformity.template.md @@ -25,7 +25,7 @@ template for their own products. - Email: [TO BE FILLED — kept synchronised with `/.well-known/security.txt` once wolfSSL Inc.'s security alias is provisioned] - Website: https://www.wolfssl.com/ -**3. EU Authorised Representative** (Art. 18, required for non-EU manufacturers) +**3. EU Authorised Representative** (Art. 18, include only where one has been mandated) - Name: [TO BE FILLED — see `eu-authorised-representative.md`] - Postal address: [TO BE FILLED] diff --git a/cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representative.md b/cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representative.md index 9204b8226..2d691c34d 100644 --- a/cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representative.md +++ b/cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representative.md @@ -1,63 +1,70 @@ # EU Authorised Representative — wolfSSL Inc. -**Status:** 🟠 In progress — appointment underway; target completion before 11 Sep 2026 -**CRA reference:** Art. 18 +**Status:** ✅ Settled — Art. 18 appointment is discretionary; wolfSSL Inc. performs the Art. 18(3) functions directly as manufacturer +**CRA reference:** Art. 18 (authorised representatives), Art. 13(13), 13(16), 13(17) -## Why an EU AR is required +## What Art. 18 actually requires -wolfSSL Inc. is established in the **United States** (Edmonds, Washington). CRA -Art. 18 requires manufacturers established outside the EU to appoint, **in -writing**, an Authorised Representative inside the EU before placing a product -on the EU market. The AR: +Art. 18(1) is permissive, not mandatory: -- Receives correspondence from EU market surveillance authorities and ENISA on the manufacturer's behalf. -- Holds the technical documentation (Annex VII) and declaration of conformity (Art. 28) for **10 years** post-placement, available to authorities on request. -- Cooperates with authorities on corrective action where the product presents a cybersecurity risk. +> "A manufacturer **may**, by a written mandate, appoint an authorised representative." -The AR does **not** transfer manufacturer obligations — wolfSSL Inc. remains -the manufacturer and bears the substantive obligations. The AR is a single -point of contact in the EU. +There is no provision in the CRA obliging a manufacturer established outside the +Union to appoint one. An authorised representative is defined in Art. 3 as "a +natural or legal person established within the Union who has received a written +mandate from a manufacturer to act on its behalf in relation to specified tasks." -## Current state +Art. 18(2) further excludes the substantive obligations from any such mandate: +Art. 13(1) to (11), Art. 13(12) first subparagraph, and Art. 13(14) cannot form +part of it. Filing Art. 14 notifications is likewise not among the tasks listed +in Art. 18(3). The manufacturer retains all of it either way. -🟠 **wolfSSL Inc. is finalising the EU AR appointment.** Two paths were evaluated: +## How wolfSSL Inc. discharges these functions -1. **Use an existing wolfSSL EU presence.** wolfSSL has business operations in - the DACH region (Germany / Austria / Switzerland). Nominating an existing - EU-resident wolfSSL legal entity as the AR is the simplest path if such an - entity exists with the appropriate legal capacity to act as AR. -2. **Contract a third-party AR service.** Several vendors (e.g. Obelis, Authrep, - Casa Group) offer AR-as-a-service across CE-marking regulations. Cost is - typically EUR 1500–4000/year per regulation; lead time 4–6 weeks. +The Art. 18(3) minimum mandate lists three tasks. wolfSSL Inc. performs each +directly, under duties that bind it as manufacturer regardless of whether a +representative is mandated: -The internal decision is being finalised by wolfSSL leadership. The written -mandate will be in place before 11 Sep 2026 (Art. 14 vulnerability reporting -onset) and certainly before 11 Dec 2027 (full CRA applicability). +| Art. 18(3) task | How wolfSSL Inc. discharges it | +|---|---| +| (a) Keep the EU declaration of conformity and technical documentation at the disposal of market surveillance authorities for 10 years post-placement or the support period, whichever is longer | **Art. 13(13)** places the identical duty, with the identical retention clock, on the manufacturer. wolfSSL Inc. retains both directly. | +| (b) Provide market surveillance authorities, on reasoned request, with the information and documentation needed to demonstrate conformity | wolfSSL Inc. responds directly. Manufacturer identity and contact details are published per **Art. 13(16)**. | +| (c) Cooperate with market surveillance authorities on action to eliminate risks | wolfSSL Inc. cooperates directly, through the same channels. | -## Placeholder identity +In addition, **Art. 13(17)** requires a single point of contact enabling users to +communicate directly and rapidly with the manufacturer, including to report +vulnerabilities. wolfSSL Inc. publishes that contact today: -Once the appointment is signed: +- [`/.well-known/security.txt`](https://www.wolfssl.com/.well-known/security.txt) (RFC 9116) +- [`/.well-known/vulnerability-disclosure-policy.txt`](https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt) +- `secure@wolfssl.com` -- **Name:** [TO BE FILLED] -- **Address:** [TO BE FILLED] -- **Email:** [TO BE FILLED] -- **Mandate effective date:** [TO BE FILLED] -- **Mandate scope:** all wolfSSL libraries placed on the EU market by wolfSSL Inc. under CRA. +Art. 14 notifications for wolfSSL libraries placed on the EU market by wolfSSL +Inc. are filed by wolfSSL Inc. through the Single Reporting Platform. See +[`vulnerability-handling-process.md`](vulnerability-handling-process.md). + +The practical effect is a shorter chain: authorities and reporters reach the +manufacturer directly rather than through a forwarding intermediary. ## What this means for customers -If your company is established **outside the EU** (US / UK post-Brexit / Asia / -elsewhere), you face the same Art. 18 obligation. wolfSSL's choice of AR does -not satisfy your obligation — you appoint your own. +**Check your own instruments, not just the CRA.** Art. 18 is discretionary under +the CRA. Other EU legislation is not: several regulations covering finished +consumer products require an EU-established responsible person or representative +outright. If you place a finished product on the EU market from outside the +Union, the binding requirement is more likely to come from one of those than +from the CRA, and wolfSSL's position on Art. 18 says nothing about your position +under them. Engage CRA counsel on the full set that applies to your product. -The single-most-important advice we can give: **start now**. AR appointments -take weeks to months including legal review on both sides; the lead time -compounds with conformity assessment timelines and is the most common -last-minute blocker for non-EU manufacturers. +**Our arrangement does not carry over to you.** Whatever you conclude, you +conclude it as the manufacturer of your product. ## References -- CRA Art. 18 (Authorised Representative) -- CRA Art. 19 (Importer obligations) — what an EU importer carries if no AR is in place +- CRA Art. 18 — authorised representatives (discretionary appointment; mandate scope) +- CRA Art. 3 — definition of authorised representative +- CRA Art. 13(13), 13(16), 13(17) — manufacturer retention, contact details, single point of contact +- CRA Art. 19 — importer obligations +- [`vulnerability-handling-process.md`](vulnerability-handling-process.md) — Art. 14 filing - [`../CRA-Compliance-Shortlist.md`](../CRA-Compliance-Shortlist.md) — "Beyond this kit" - [`../CRA-Supply-Chain-Glossary.md`](../CRA-Supply-Chain-Glossary.md) — EU Authorised Representative diff --git a/cra-kit/wolfssl-inc-auditor-packet/technical-documentation-outline.md b/cra-kit/wolfssl-inc-auditor-packet/technical-documentation-outline.md index 98d0409f5..04861a94d 100644 --- a/cra-kit/wolfssl-inc-auditor-packet/technical-documentation-outline.md +++ b/cra-kit/wolfssl-inc-auditor-packet/technical-documentation-outline.md @@ -6,7 +6,7 @@ CRA Annex VII enumerates the contents of the technical documentation file that manufacturers must maintain (and retain for **10 years** after market placement) for each conformant product. This file is not made public; it is held by the -manufacturer (and the EU AR) and produced to authorities on request. +manufacturer under Art. 13(13) and produced to authorities on request. ## Outline of wolfSSL Inc.'s per-release technical documentation file @@ -71,7 +71,7 @@ following sections are populated: ## Retention - **10 years** from the date the product is placed on the EU market, or for the duration of the support period (whichever is longer). -- Held by wolfSSL Inc. **and** the EU Authorised Representative ([`eu-authorised-representative.md`](eu-authorised-representative.md)). +- Held by wolfSSL Inc. under **Art. 13(13)**, at the disposal of market surveillance authorities (see [`eu-authorised-representative.md`](eu-authorised-representative.md)). ## What this means for customers