A U.S. headquarters does not answer the CRA question. Product, manufacturer role and EU-market availability are the facts that drive the analysis.
Headquarters location is not the decisive question
The CRA is an EU market-access regime. A U.S. company should not dismiss it merely because it has no European headquarters. The practical question is whether it acts as a manufacturer of a product with digital elements that is made available on the Union market, directly or through an importer, distributor, subsidiary, marketplace or other commercial channel.
That does not mean every U.S. software company is automatically covered. The product, commercial activity, role in the supply chain, open-source status, exclusions and market facts all matter. Applicability needs a product-specific analysis.
What counts as a product with digital elements
The CRA definition reaches software or hardware products and their remote data-processing solutions where the digital components are integral to the product. That can include connected devices, downloadable software, applications, firmware, network equipment, embedded components and other commercial digital products. Pure services and certain regulated-sector products may require separate analysis.
Who may be the manufacturer
A company can be the manufacturer when it develops or manufactures a product with digital elements, or has the product designed, developed or manufactured, and markets it under its name or trademark. Contract manufacturing or outsourced software development therefore does not necessarily move the legal role away from the brand owner.
For U.S. companies, this often means the analysis begins with product ownership and branding, not with where the engineers or factory are located.
Existing EU-market products matter for reporting
The reporting obligations apply to in-scope products with digital elements made available on the Union market, including products placed before the broader December 11, 2027 application date and products whose support period has ended. That makes September 2026 readiness relevant beyond future launches or currently supported products.
The rules do not retroactively require a report merely because active exploitation was already known before September 11. If a vulnerability was known but the manufacturer learns of active exploitation on or after September 11, the reporting duty can be triggered. A product register should identify each EU-market product, version, support period, product owner, security owner, market evidence, component dependencies and corrective-release process.
Non-EU routing and representative roles
For a manufacturer established outside the EU, CRA Article 14(7) uses a routing order: the Member State where the authorised representative is established; if none, where the importer is established; if none, where the distributor is established; and if none, the Member State with the highest number of affected users. Product-specific facts and qualified review remain important.
ENISA’s “Assigned Representative” is an SRP user role and is distinct from a CRA Article 18 authorised representative. The manufacturer retains legal responsibility. A U.S. manufacturer should prepare its EU legal-entity, authorised-representative, importer, distributor and market-user facts before a report is due.
Five screening questions for a U.S. company
- Is there a software or hardware product with digital elements? Identify the product, remote components and branding.
- Is it made available on the EU market? Review direct sales, channel partners, marketplaces, subscriptions, downloads and importer/distributor arrangements.
- What economic-operator role does the company hold? Manufacturer, importer, distributor, authorised representative or open-source software steward obligations differ.
- Is the product excluded or governed by a more specific regime? Sector-specific rules and statutory exclusions need review.
- Who can submit and which routing order applies? Document the Article 14(7) facts, SRP Assigned Representatives, active personal EU Login and two-factor authentication, and qualified review. ENISA says SRP registration occurs when a report is needed.
What to do before the legal analysis is finished
A company can build neutral operational readiness without prematurely concluding that every product is covered. Inventory EU-market products, establish a product-security intake path, preserve prompt initial assessments and awareness decisions, assign a reporting owner and backup, prepare personal EU Login access, map the ENISA stages and run a tabletop without making a fictitious submission. Those controls are useful even when the final scope determination is “not covered,” because they preserve how the decision was reached.
Avoid two opposite mistakes
The first mistake is ignoring the CRA because the company is American. The second is declaring every remotely accessible product covered without product and market analysis. The better approach is a controlled screen: document the product, role, EU availability, exclusions, reporting owner, routing facts and legal review status.
For companies with products already in the EU, September 11 is a reporting-process deadline. December 2027 may be the larger product-conformity milestone, but it is not the first time the CRA can create operational obligations.
EU CRA 24/72-Hour Reporting Readiness & Evidence System
Manage awareness, deadlines, ENISA fields, stage packets, approvals, corrective measures, evidence and submission confirmations in one Excel-based operating system.
Frequently asked questions
Can the CRA apply to a U.S. software company?
It may. The key issues include the company’s role, the product with digital elements and whether the product is made available on the EU market.
Does a U.S. company need an EU subsidiary for CRA reporting to matter?
Not necessarily. Sales and distribution through importers, distributors, marketplaces or other EU channels may be relevant.
Are products already sold in Europe part of the September reporting regime?
In-scope products made available on the EU market can be included even if placed before December 11, 2027 or after support ends, subject to the non-retroactivity and awareness nuances described above.
Does the workbook decide whether a U.S. company is covered?
No. It organizes the facts, review status, reporting workflow and evidence; legal applicability remains fact-specific.
Primary sources
- Regulation (EU) 2024/2847
- European Commission — CRA reporting obligations
- ENISA — Single Reporting Platform FAQ
- European Commission — final CRA implementation guidance
Syntera Systems is not affiliated with or endorsed by the European Commission, ENISA or any member-state CSIRT. This article provides operational information, not legal advice. Applicability and reportability are fact-specific.