CRAnotify Documentation

Legal entities and economic operators

A group that sells in the Union almost always has several companies, and the Cyber Resilience Act attributes obligations to each of them separately. Here you register the companies through which you place products on the market, and say which company holds which role on which managed product. The role lives on the relationship between entity and product, not on the product: it is the only way to represent a group that is the manufacturer of one thing and the importer of another.

Where it lives

From Products, the Legal entities button in the toolbar (/prodotti?vista=entita). Two panels: the list of entities, and the Entity ↔ managed product table with the CRA roles.

The primary entity

Every organisation has one, and it is the one derived from the details you entered under Account area › Company: it carries the primary label and is not created by hand. It is the entity to which anything not assigned elsewhere is attributed — in particular the "Manufacturer" fields of the technical documentation file come from it.

The companies you add from this screen are additional entities. The primary one remains the company record's: to change its details, edit it here, and the change is a new version, not a silent overwrite.

The fields of an entity

FieldWhat to enter
Legal name (required)The name the company is registered under. It is what ends up on a declaration of conformity.
Trading nameOnly if it differs from the legal name.
Country (required)ISO 3166-1 alpha-2 code, from a closed list: the 27 Member States, the EEA countries, and the third countries people sell into the Union from. The list is closed because "Germany", "DE" and "germany" would otherwise be three different countries to the code.
Time zoneAn IANA identifier. When absent, Europe/Rome.
Registered office, VAT number, company register no., websiteThe company's identifiers.
Regulatory contactWho answers for compliance matters on behalf of this company. It appears in the technical file.
Billing emailThe entity's administrative address.

Some country metadata — for Italy the PEC address and the SDI code — was written by the company record and does not pass through this form: it appears read-only on the entity's card.

The country is geographic data, not a legal conclusion. The label saying whether the office is in the Union tells you where the company is, not which obligations it carries. Which obligations you carry depends on the role you confirm on each product.

Every change is confirmed

Both registering a new entity and editing an existing one ask for an explicit tick, and the check is on the server: a confirmation that lives only in the browser is not a confirmation. Every save creates a version with its author and its date — the previous one stays — and leaves a row in the activity registry.

An entity identifier is accepted only if it already belongs to this organisation: you cannot "edit" another company's entity, and no namesake with the same identifier is created.

The link between entity and managed product

The Entity ↔ managed product table is where having several companies really matters: the same group can be the manufacturer of the router it designs, the importer of the module it buys outside the Union and the distributor of a third product, through different companies and with different obligations, at the same time.

Attributing a rolePick the entity, the managed product and the CRA role, and confirm with the tick. The confirmation stays on record with your name.
Managed products onlyA CRA role is attributed with respect to a managed product, not a variant: the form refuses a variant and says so.
Closing a roleOn a confirmed relationship the available gesture is closing it. Obligations already incurred do not disappear: see Your CRA role for each product.

A suggested role — arrived from an import, from a heuristic, or from the roles declared in the company record — appears separately and has no effect at all until a person confirms it. It is the same rule as on the product page, with the same session identity.

What changes when you confirm

A confirmed role is the only one the workflows read. It decides which CRA controls appear for that product and which role the technical file declares. It changes no date and no deadline: deadlines come from a case, not from the register.

No gesture on this screen writes a verdict, a date or a recipient. It is a register: it records who you are and with respect to what. The rest is decided by the compliance flow.

Who can do this

The pages can be read with any application role; the gestures — registering an entity, editing it, confirming or closing a role — require a role that may write, so not a read-only profile. See Users, roles and escalation.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu