Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion cra-kit/CRA-Cheat-Sheet.md
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ the EU market you also need:

| Obligation | Article | Action |
|------------|---------|--------|
| **EU Authorised Representative** | Art. 18 | Required if you're established outside the EU |
| **EU Authorised Representative** | Art. 18 | **Optional** under the CRA (Art. 18(1): *may*); check other EU acts covering your product |
| **Product class** (Annex III/IV) | — | Determines self-cert vs **Notified Body** — long queues |
| **Conformity assessment + CE mark** | Art. 32, 30 | Module A or external review |
| **Technical documentation** | Annex VII | Risk assessment, support-period commitment |
Expand Down
6 changes: 3 additions & 3 deletions cra-kit/CRA-Compliance-Shortlist.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ SBOMs alone make you ready:

| Obligation | Article | What it means |
|------------|---------|---------------|
| **EU Authorised Representative** | Art. 18 | Manufacturers established **outside** the EU must appoint a written-mandated representative **inside** the EU before placing a product on the EU market. Either contract a third-party AR service or use an existing EU subsidiary. |
| **EU Authorised Representative** | Art. 18 | **Discretionary under the CRA.** Art. 18(1): a manufacturer *may* appoint one by written mandate. The Art. 18(3) tasks (hold the DoC and technical documentation, answer reasoned requests, cooperate on risk action) duplicate duties the manufacturer already carries under Art. 13(13). The practical reason to appoint one is control: Art. 14(7)(a) then fixes your coordinator CSIRT. Other EU acts covering finished products may require an EU representative outright. |
| **Product classification** | Annex III / IV | Determines whether conformity assessment is self-declared (default class) or requires a **Notified Body** (important / critical class). Notified-body queues are already long — if you may need one, get in queue early. |
| **Conformity assessment + CE mark** | Art. 32, 30 | Module A (self-assessment) or external review per classification; CE marking before placing the product on the EU market. |
| **Technical documentation** | Annex VII | Risk assessment, secure-design rationale, vulnerability handling process, support-period commitment — more than the SBOM. |
Expand All @@ -82,7 +82,7 @@ SBOMs alone make you ready:

These are **legal and structural decisions**, not artefacts you can generate
from source code. wolfSSL ships SBOMs, security-policy templates, and the
narrative in this kit; **you** appoint your EU AR, classify your product, run
narrative in this kit; **you** decide your own Art. 18 position, classify your product, run
your conformity assessment, and produce your declaration of conformity. If
you do not yet have a CRA consultant, engaging one for the
classification + AR questions specifically is usually the highest-leverage
Expand All @@ -95,7 +95,7 @@ classification statement, conformity assessment route, declaration of
conformity template, EU Authorised Representative status, support-period
policy, vulnerability-handling process, technical documentation outline,
and CE marking statement. Where decisions are made, they're stated; where
they're in flight (EU AR appointment, public SLA), the gap is named.
they're in flight, the gap is named.
Adapt as a template for your own product.

---
Expand Down
2 changes: 1 addition & 1 deletion cra-kit/CRA-Supply-Chain-Glossary.md
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ that no SBOM tool can satisfy. **Not legal advice** — engage CRA counsel.

| Term | Article / location | Plain English |
|------|--------------------|---------------|
| **EU Authorised Representative** (EU AR) | Art. 18 | Required if the manufacturer is established **outside** the EU. A written-mandated EU-resident legal entity that receives regulator correspondence on the manufacturer's behalf. Either contract a third-party AR service or use an existing EU subsidiary. **Long-lead** — start now. |
| **EU Authorised Representative** (EU AR) | Art. 18 | A written-mandated EU-established **natural or legal** person that receives regulator correspondence on the manufacturer's behalf. Appointment is **discretionary** under the CRA: Art. 18(1) says a manufacturer *may* appoint one, and Art. 18(2) bars the mandate from carrying the substantive obligations. Other EU legislation covering finished products may require an EU representative outright. |
| **Notified Body** | — | Independent third-party conformity-assessment organisation. For "important" or "critical" products (Annex III/IV) the conformity assessment must involve a Notified Body. Queues are long — engage early if you may need one. |
| **Annex III** | Annex III | List of **"important"** products with above-baseline cybersecurity risk (e.g. password managers, network management systems, browsers, certain identity-management components). Triggers stricter conformity assessment than the default class. |
| **Annex IV** | Annex IV | List of **"critical"** products (highest-risk class), e.g. hardware security modules, secure-boot devices, smart-meter gateways of certain types. Always requires Notified Body involvement. |
Expand Down
11 changes: 7 additions & 4 deletions cra-kit/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -258,10 +258,13 @@ distributor obligations. See [`CRA-Compliance-Shortlist.md`](CRA-Compliance-Shor
legal/structural decisions, not artefacts.

**Are we outside the EU? (US / Asia / etc.)**
Then you almost certainly need an **EU Authorised Representative** (Art. 18)
appointed in writing **before** placing your product on the EU market. Either
contract a third-party AR service or use an existing EU subsidiary. This is a
long-lead item — start now, do not wait for September 2026.
Under the CRA an **EU Authorised Representative** (Art. 18) is **optional**.
Art. 18(1) says a manufacturer *may* appoint one, and the Art. 18(3) tasks
duplicate duties you already carry as manufacturer under Art. 13(13). The reason
to appoint one is control rather than compliance: Art. 14(7)(a) then fixes which
Comment on lines +261 to +264
coordinator CSIRT you file to. Note that other EU legislation covering finished
consumer products may require an EU representative outright — check the full set
of acts that applies to your product with counsel.

---

Expand Down
2 changes: 1 addition & 1 deletion cra-kit/ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ they're actually inheriting when they reference us as a component supplier.
| CNA status | **Available** | wolfSSL is a CVE Numbering Authority |
| Public SLA (24h ack / 72h triage) | **Pending leadership approval** | Will be added to CVD policy once approved |
| 24h ENISA reporting (Art. 14) runbook | **In progress** | Owner assignment pending; on-call rotation TBD |
| EU Authorised Representative (Art. 18) | **In progress** | wolfSSL Inc. is US-established; AR appointment underway |
| EU Authorised Representative (Art. 18) | **Settled** | Discretionary under Art. 18(1); wolfSSL Inc. performs the Art. 18(3) functions directly |
| CSAF 2.0 advisory feed | **Roadmap** | See above |

See [`wolfssl-inc-auditor-packet/`](wolfssl-inc-auditor-packet/) for the manufacturer-side
Expand Down
4 changes: 2 additions & 2 deletions cra-kit/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ Set `WOLFSSL_DIR` to your wolfSSL source tree when regenerating SBOMs.

**Before starting**, confirm with the customer (do not assume):

- Where is the customer **established** (US / EU / other)? If outside the EU, flag the **EU Authorised Representative** requirement (Art. 18) — long-lead item, start now.
- Where is the customer **established** (US / EU / other)? Note that a CRA **EU Authorised Representative** (Art. 18) is **discretionary** — Art. 18(1) says a manufacturer *may* appoint one. Other EU instruments covering finished products may require an EU representative outright, so point the customer at counsel for the full set of acts, not at Art. 18.
- What is the **product classification** under Annex III/IV? Self-declared (default class) or Notified Body required (important / critical)? Flag if unknown — Notified Body queues are long.
- Is the customer's CRA work **on track for 11 Sep 2026** (Art. 14 reporting wave) and **11 Dec 2027** (full applicability)? If structural items are open, SBOM work alone won't make them ready.

Expand Down Expand Up @@ -95,7 +95,7 @@ Then run the SBOM execution checklist:
- **VEX** = customer + scanner; wolfSSL provides advisories, not VEX files.
- **bomsh** = optional provenance; not required for most CRA transparency asks.
- **Vulnerability handling (Art. 13/14)** = customer publishes their own CVD policy + `security.txt`, runs on-call, files 24h ENISA reports for their product; wolfSSL provides reference templates and handles ENISA reporting only for libraries placed on the EU market by wolfSSL Inc.
- **Structural CRA (out of scope for this kit)** = EU Authorised Representative (Art. 18 — required if customer is outside the EU), Annex III/IV classification (determines self-cert vs Notified Body), conformity assessment + CE mark (Art. 32, 30), technical documentation (Annex VII), support-period commitment (Art. 13(8), 5+ years default). When a customer asks "are we ready?", surface these — SBOMs alone are not enough. Recommend engaging CRA counsel or consultant.
- **Structural CRA (out of scope for this kit)** = EU Authorised Representative (Art. 18 — **discretionary** under the CRA; other EU acts may require one), Annex III/IV classification (determines self-cert vs Notified Body), conformity assessment + CE mark (Art. 32, 30), technical documentation (Annex VII), support-period commitment (Art. 13(8), 5+ years default). When a customer asks "are we ready?", surface these — SBOMs alone are not enough. Recommend engaging CRA counsel or consultant.

---

Expand Down
2 changes: 1 addition & 1 deletion cra-kit/auditor-packet/00-INDEX.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ CRA conformity packet for a real product also includes:
- Declaration of conformity (Art. 28)
- Technical documentation per Annex VII (risk assessment, design info, support-period commitment, vulnerability handling process)
- Proof of conformity assessment (self-declared per Art. 32 Module A, or Notified Body certificate per product class)
- Identity of the EU Authorised Representative (Art. 18) if the manufacturer is established outside the EU
- Identity of the EU Authorised Representative (Art. 18) where one has been mandated
- CE marking declaration

See [`../CRA-Compliance-Shortlist.md`](../CRA-Compliance-Shortlist.md)
Expand Down
2 changes: 1 addition & 1 deletion cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
| [`classification-statement.md`](classification-statement.md) | Annex III / IV | ✅ Decided — default category (not Annex III/IV), self-certification |
| [`conformity-assessment-route.md`](conformity-assessment-route.md) | Art. 32, Annex VIII | ✅ Module A self-assessment |
| [`declaration-of-conformity.template.md`](declaration-of-conformity.template.md) | Art. 28 | 🟡 Template ready; signature pending product release alignment |
| [`eu-authorised-representative.md`](eu-authorised-representative.md) | Art. 18 | 🟠 In progress — appointment underway |
| [`eu-authorised-representative.md`](eu-authorised-representative.md) | Art. 18 | ✅ Settled — appointment is discretionary; Art. 18(3) functions performed directly |
| [`support-period-policy.md`](support-period-policy.md) | Art. 13(2), 13(8) | ✅ Decided — 5-year minimum, longer for LTS lines |
| [`vulnerability-handling-process.md`](vulnerability-handling-process.md) | Art. 13, 14 | 🟡 Process documented; public SLA pending leadership approval |
| [`technical-documentation-outline.md`](technical-documentation-outline.md) | Annex VII | 🟠 In progress — outline complete; per-release packet on roadmap |
Expand Down
2 changes: 1 addition & 1 deletion cra-kit/wolfssl-inc-auditor-packet/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ fiction.

**Not legal advice.** These artefacts are templates and statements of position;
they are not, and do not replace, the actual signed legal documents wolfSSL Inc.
files with EU regulators or its EU Authorised Representative.
files with EU regulators.

---

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ template for their own products.
- Email: [TO BE FILLED — kept synchronised with `/.well-known/security.txt` once wolfSSL Inc.'s security alias is provisioned]
- Website: https://www.wolfssl.com/

**3. EU Authorised Representative** (Art. 18, required for non-EU manufacturers)
**3. EU Authorised Representative** (Art. 18, include only where one has been mandated)

- Name: [TO BE FILLED — see `eu-authorised-representative.md`]
- Postal address: [TO BE FILLED]
Expand Down
89 changes: 48 additions & 41 deletions cra-kit/wolfssl-inc-auditor-packet/eu-authorised-representative.md
Original file line number Diff line number Diff line change
@@ -1,63 +1,70 @@
# EU Authorised Representative — wolfSSL Inc.

**Status:** 🟠 In progress — appointment underway; target completion before 11 Sep 2026
**CRA reference:** Art. 18
**Status:** ✅ Settled — Art. 18 appointment is discretionary; wolfSSL Inc. performs the Art. 18(3) functions directly as manufacturer
**CRA reference:** Art. 18 (authorised representatives), Art. 13(13), 13(16), 13(17)

## Why an EU AR is required
## What Art. 18 actually requires

wolfSSL Inc. is established in the **United States** (Edmonds, Washington). CRA
Art. 18 requires manufacturers established outside the EU to appoint, **in
writing**, an Authorised Representative inside the EU before placing a product
on the EU market. The AR:
Art. 18(1) is permissive, not mandatory:

- Receives correspondence from EU market surveillance authorities and ENISA on the manufacturer's behalf.
- Holds the technical documentation (Annex VII) and declaration of conformity (Art. 28) for **10 years** post-placement, available to authorities on request.
- Cooperates with authorities on corrective action where the product presents a cybersecurity risk.
> "A manufacturer **may**, by a written mandate, appoint an authorised representative."

The AR does **not** transfer manufacturer obligations — wolfSSL Inc. remains
the manufacturer and bears the substantive obligations. The AR is a single
point of contact in the EU.
There is no provision in the CRA obliging a manufacturer established outside the
Union to appoint one. An authorised representative is defined in Art. 3 as "a
natural or legal person established within the Union who has received a written
mandate from a manufacturer to act on its behalf in relation to specified tasks."

## Current state
Art. 18(2) further excludes the substantive obligations from any such mandate:
Art. 13(1) to (11), Art. 13(12) first subparagraph, and Art. 13(14) cannot form
part of it. Filing Art. 14 notifications is likewise not among the tasks listed
in Art. 18(3). The manufacturer retains all of it either way.

🟠 **wolfSSL Inc. is finalising the EU AR appointment.** Two paths were evaluated:
## How wolfSSL Inc. discharges these functions

1. **Use an existing wolfSSL EU presence.** wolfSSL has business operations in
the DACH region (Germany / Austria / Switzerland). Nominating an existing
EU-resident wolfSSL legal entity as the AR is the simplest path if such an
entity exists with the appropriate legal capacity to act as AR.
2. **Contract a third-party AR service.** Several vendors (e.g. Obelis, Authrep,
Casa Group) offer AR-as-a-service across CE-marking regulations. Cost is
typically EUR 1500–4000/year per regulation; lead time 4–6 weeks.
The Art. 18(3) minimum mandate lists three tasks. wolfSSL Inc. performs each
directly, under duties that bind it as manufacturer regardless of whether a
representative is mandated:

The internal decision is being finalised by wolfSSL leadership. The written
mandate will be in place before 11 Sep 2026 (Art. 14 vulnerability reporting
onset) and certainly before 11 Dec 2027 (full CRA applicability).
| Art. 18(3) task | How wolfSSL Inc. discharges it |
|---|---|
| (a) Keep the EU declaration of conformity and technical documentation at the disposal of market surveillance authorities for 10 years post-placement or the support period, whichever is longer | **Art. 13(13)** places the identical duty, with the identical retention clock, on the manufacturer. wolfSSL Inc. retains both directly. |
| (b) Provide market surveillance authorities, on reasoned request, with the information and documentation needed to demonstrate conformity | wolfSSL Inc. responds directly. Manufacturer identity and contact details are published per **Art. 13(16)**. |
| (c) Cooperate with market surveillance authorities on action to eliminate risks | wolfSSL Inc. cooperates directly, through the same channels. |

## Placeholder identity
In addition, **Art. 13(17)** requires a single point of contact enabling users to
communicate directly and rapidly with the manufacturer, including to report
vulnerabilities. wolfSSL Inc. publishes that contact today:

Once the appointment is signed:
- [`/.well-known/security.txt`](https://www.wolfssl.com/.well-known/security.txt) (RFC 9116)
- [`/.well-known/vulnerability-disclosure-policy.txt`](https://www.wolfssl.com/.well-known/vulnerability-disclosure-policy.txt)
- `secure@wolfssl.com`

- **Name:** [TO BE FILLED]
- **Address:** [TO BE FILLED]
- **Email:** [TO BE FILLED]
- **Mandate effective date:** [TO BE FILLED]
- **Mandate scope:** all wolfSSL libraries placed on the EU market by wolfSSL Inc. under CRA.
Art. 14 notifications for wolfSSL libraries placed on the EU market by wolfSSL
Inc. are filed by wolfSSL Inc. through the Single Reporting Platform. See
[`vulnerability-handling-process.md`](vulnerability-handling-process.md).

The practical effect is a shorter chain: authorities and reporters reach the
manufacturer directly rather than through a forwarding intermediary.

## What this means for customers

If your company is established **outside the EU** (US / UK post-Brexit / Asia /
elsewhere), you face the same Art. 18 obligation. wolfSSL's choice of AR does
not satisfy your obligation — you appoint your own.
**Check your own instruments, not just the CRA.** Art. 18 is discretionary under
the CRA. Other EU legislation is not: several regulations covering finished
consumer products require an EU-established responsible person or representative
outright. If you place a finished product on the EU market from outside the
Union, the binding requirement is more likely to come from one of those than
from the CRA, and wolfSSL's position on Art. 18 says nothing about your position
under them. Engage CRA counsel on the full set that applies to your product.

The single-most-important advice we can give: **start now**. AR appointments
take weeks to months including legal review on both sides; the lead time
compounds with conformity assessment timelines and is the most common
last-minute blocker for non-EU manufacturers.
**Our arrangement does not carry over to you.** Whatever you conclude, you
conclude it as the manufacturer of your product.

## References

- CRA Art. 18 (Authorised Representative)
- CRA Art. 19 (Importer obligations) — what an EU importer carries if no AR is in place
- CRA Art. 18 — authorised representatives (discretionary appointment; mandate scope)
- CRA Art. 3 — definition of authorised representative
- CRA Art. 13(13), 13(16), 13(17) — manufacturer retention, contact details, single point of contact
- CRA Art. 19 — importer obligations
- [`vulnerability-handling-process.md`](vulnerability-handling-process.md) — Art. 14 filing
- [`../CRA-Compliance-Shortlist.md`](../CRA-Compliance-Shortlist.md) — "Beyond this kit"
- [`../CRA-Supply-Chain-Glossary.md`](../CRA-Supply-Chain-Glossary.md) — EU Authorised Representative
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
CRA Annex VII enumerates the contents of the technical documentation file that
manufacturers must maintain (and retain for **10 years** after market placement)
for each conformant product. This file is not made public; it is held by the
manufacturer (and the EU AR) and produced to authorities on request.
manufacturer under Art. 13(13) and produced to authorities on request.

## Outline of wolfSSL Inc.'s per-release technical documentation file

Expand Down Expand Up @@ -71,7 +71,7 @@ following sections are populated:
## Retention

- **10 years** from the date the product is placed on the EU market, or for the duration of the support period (whichever is longer).
- Held by wolfSSL Inc. **and** the EU Authorised Representative ([`eu-authorised-representative.md`](eu-authorised-representative.md)).
- Held by wolfSSL Inc. under **Art. 13(13)**, at the disposal of market surveillance authorities (see [`eu-authorised-representative.md`](eu-authorised-representative.md)).

## What this means for customers

Expand Down
Loading