EU AUTHORIZED REPRESENTATIVE
Selling products with digital elements in the EU but based outside Europe? You may need a locally established Authorized Representative. Meroi Security acts as your regulatory point of contact from the Netherlands, handling correspondence with authorities, maintaining your compliance documentation, and supporting market surveillance obligations.
What is an EU Authorized Representative?
An EU Authorized Representative (AR) is a natural or legal person established within the European Union, formally appointed by a non-EU manufacturer through a written mandate to act on their behalf for specific regulatory tasks. The AR serves as the essential link between the manufacturer and EU regulatory authorities.
Under the Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), the EU AI Act, and the EU’s Market Surveillance Regulation (EU) 2019/1020, products placed on the European market must have a responsible economic operator established in the EU. For manufacturers without their own EU entity, appointing an Authorized Representative is the most direct way to meet this requirement.

Why do non-EU manufacturers need an Authorized Representative?
EU regulations require that products placed on the European market have a responsible economic operator within the EU that authorities can reach. The Market Surveillance Regulation (EU) 2019/1020 sets this as a baseline obligation: before a product can be made available on the EU market, there must be an EU-established entity responsible for it. If you manufacture hardware or software outside the EU and sell into the single market, this means you need either an importer, a distributor, or an Authorized Representative established within the EU.
Without an EU-based economic operator, your products can be blocked at customs, removed from online marketplaces, or subject to enforcement actions with no local point of contact to coordinate a response. As EU cybersecurity and product safety legislation continues to expand, having a reliable EU presence is not just a formality: it is a condition for market access.
The role of the Authorized Representative under the CRA
Article 18 of the Cyber Resilience Act (Regulation (EU) 2024/2847) allows manufacturers to appoint an Authorized Representative by written mandate. The mandate must allow the AR to perform at least the following:
- Document retention: Keep the EU declaration of conformity and technical documentation available for market surveillance authorities for at least 10 years after the product has been placed on the market, or for the duration of the support period, whichever is longer.
- Information provision: Upon a reasoned request from a market surveillance authority, supply all information and documentation necessary to demonstrate the conformity of the product.
- Cooperation with authorities: Work with market surveillance authorities on any action taken to address risks posed by a product covered by the mandate.
The AR does not take on the manufacturer’s core product development and security obligations (those in Article 13(1) to (11), Article 13(12) first subparagraph, and Article 13(14) are explicitly excluded from the mandate). The manufacturer remains responsible for design, development, vulnerability handling, and security updates.
Regulations where an EU Authorized Representative plays a role
Several EU regulations either require or enable the appointment of an Authorized Representative for non-EU manufacturers:
- Cyber Resilience Act (CRA) – Regulation (EU) 2024/2847. Article 18 allows manufacturers to appoint an AR by written mandate for products with digital elements. While the CRA itself uses “may,” the Market Surveillance Regulation (EU) 2019/1020 (which the CRA amends) requires an EU-established economic operator for products on the EU market.
- Radio Equipment Directive (RED) – Directive 2014/53/EU. Article 11 similarly allows manufacturers to appoint an AR by written mandate. For non-EU manufacturers of radio and wireless equipment, the AR holds the declaration of conformity and technical documentation, and cooperates with national market surveillance authorities.
- EU AI Act – Regulation (EU) 2024/1689. Unlike the CRA and RED, the AI Act is explicit: Article 22 requires non-EU providers of high-risk AI systems to appoint an AR before making their systems available on the EU market. Article 54 extends the same obligation to providers of general-purpose AI models.
- General Product Safety Regulation (GPSR) – Regulation (EU) 2023/988. Article 16 requires that every consumer product on the EU market has a “responsible person” established in the EU. An Authorized Representative is one of the ways to fulfill this role, alongside an EU-based importer or distributor. In effect since December 13, 2024.
Key CRA compliance dates to keep in mind
- 11 June 2026: Conformity assessment body notification requirements take effect. Importers, distributors, and authorized representatives must verify that draft EU Declarations of Conformity and technical files exist.
- 11 September 2026: Vulnerability and incident reporting obligations become mandatory. Manufacturers must notify actively exploited vulnerabilities to the designated CSIRT via ENISA‘s Single Reporting Platform.
- 11 December 2027: Full application of all CRA requirements. Products with digital elements must meet all essential cybersecurity requirements and carry CE marking to be placed on the EU market.
What Meroi Security provides as your EU Authorized Representative
We are established in the Netherlands and registered with the Dutch Chamber of Commerce (KVK). As your designated AR, we provide a defined set of services based on a formal written mandate:
- Regulatory point of contact: We serve as your EU-based contact for market surveillance authorities in the Netherlands and across the EU.
- Documentation management: We store and maintain your EU declaration of conformity, technical documentation, and CE marking records, keeping them available to authorities as required.
- Authority correspondence: We receive and respond to requests from market surveillance authorities on your behalf, coordinating with your team to provide accurate and timely information.
- Cooperation on corrective actions: If authorities identify a risk with your product, we coordinate the response process between your organization and the relevant EU bodies.
- Compliance monitoring: We track regulatory changes that may affect your products and inform you of updates to applicable standards or enforcement practices.
Our role is focused on the specific obligations of an Authorized Representative as defined by the applicable regulations. We do not perform product development, testing, or security engineering on your behalf, though we can connect you with our CRA compliance consulting services for broader support.
Our location and EU presence
Meroi Security is registered in the Netherlands with the Dutch Chamber of Commerce, providing a stable EU legal base for your Authorized Representative needs. Our Dutch registration gives us direct access to the local market surveillance infrastructure and positions us within the EU’s regulatory framework.
We also maintain an operational presence in Taiwan, which means we understand the practical reality of manufacturing and product development in Asia. This helps us bridge the communication gap that sometimes exists between non-EU manufacturers and European regulatory authorities.
Registered address:
Meroi Security
Pastor van Arslaan 6A
5622CK Eindhoven
Netherlands
KVK-nummer: 77783077
BTW-id: NL003236261B11
Scope and limitations
To be upfront about what this service covers: acting as an Authorized Representative means we take on specific, well-defined regulatory obligations on your behalf. It does not transfer your manufacturer responsibilities to us. You remain accountable for product security, vulnerability management, update delivery, and all other obligations that the CRA and related legislation place on manufacturers.
We are also not a notified body or conformity assessment body. If your product requires third-party conformity assessment (for example, CRA Class II Important products or Critical products), that assessment must be conducted by an accredited notified body. We can help coordinate that process, but we do not perform the assessments ourselves.
Contact us to discuss your EU representation needs
If you are a manufacturer based outside the EU and need to appoint an Authorized Representative, get in touch. We will review your product portfolio, discuss which regulations apply, and explain what a mandate arrangement would look like in practice.
Contact us at [email protected]
