Independent information resource Product security · EU CRA
CRA enforcement / 05

Corrective Actions for Non-Compliant Digital Products

What corrective action means under the Cyber Resilience Act when a product with digital elements is found non-compliant, including remediation, market restrictions, withdrawal, recall and procedural rights.

IN BRIEF

Corrective action is broader than issuing a software patch. The required response depends on the non-compliance and risk and can range from bringing affected products into conformity to stopping further market availability, withdrawal or recall. Article 54 requires action across all concerned products the economic operator has made available throughout the Union, while Regulation (EU) 2019/1020 supplies wider corrective-action and procedural rules.

01 / 11

Corrective Action Starts After a Finding of Non-Compliance

Under Article 54, the corrective-action stage begins when a market surveillance authority's evaluation finds that a product with digital elements does not comply with the CRA. The authority must without delay require the relevant economic operator to take all appropriate corrective actions. Corrective action is therefore a response to an identified compliance problem, not merely a general recommendation for better cybersecurity practice.

02 / 11

The Product Can Be Brought Into Compliance

One route is to correct the non-compliance so that the affected product meets the applicable CRA requirements. In software-intensive products this may involve security remediation, configuration changes, corrected update mechanisms, revised documentation or other technical and organisational changes. The required measure depends on the actual finding and must address the identified non-compliance rather than simply create a new document describing it.

03 / 11

Withdrawal and Recall Are Separate Outcomes

Article 54 also allows the authority to require withdrawal from the market or recall. Withdrawal generally concerns preventing a product already in the supply chain from continuing to be made available, while recall reaches products already made available to end users. These are distinct from correcting the product while allowing continued market availability.

04 / 11

The Period Must Reflect the Nature of the Cybersecurity Risk

The CRA provides for a reasonable period commensurate with the nature of the cybersecurity risk as prescribed by the market surveillance authority. There is no single universal corrective-action deadline in Article 54 for every case. A company therefore needs to manage the authority's specified period as a formal compliance deadline while prioritising remediation according to the risk and scope of affected products.

05 / 11

Corrective Action Must Cover All Concerned Products Across the Union

Article 54 requires the economic operator to ensure that all appropriate corrective action is taken for all products with digital elements concerned that it has made available on the market throughout the Union. A response limited to the Member State that opened the case can therefore be inadequate where the same affected product or release was made available elsewhere in the EU.

06 / 11

The Wider Market-Surveillance Rules Describe Additional Measures

Article 16 of Regulation (EU) 2019/1020 describes corrective measures that can include bringing the product into compliance, preventing further market availability, withdrawal or recall, rendering a product inoperable, warnings, prior conditions for market availability and alerts to end users in appropriate cases. Which measures are legally appropriate depends on the applicable CRA procedure and the facts of the case.

07 / 11

A Patch Is Evidence Only When It Solves the Compliance Problem

For a software defect, producing a patch is only one step. The economic operator should be able to show which affected versions were identified, how the fix addresses the non-compliance, what verification was performed, how the update was distributed and whether affected products actually received or can receive the correction. Authorities can maintain procedures for verifying that required corrective action has been taken.

08 / 11

Inadequate Corrective Action Can Trigger Provisional Measures

If the economic operator does not take adequate corrective action within the required period, Article 54 allows the market surveillance authority to take appropriate provisional measures. These can prohibit or restrict the product from being made available on the national market, withdraw it or recall it. The authority then notifies the Commission and other Member States.

09 / 11

Corrective Action Can Become a Cross-Border Enforcement Matter

Where non-compliance is not restricted to the initiating Member State, the Article 54 procedure requires information to be shared with the Commission and other Member States. If the provisional national measure is not objected to within the applicable three-month period, it is deemed justified and market surveillance authorities across the Union must take appropriate restrictive measures concerning the product.

10 / 11

Procedural Rights Still Apply

Article 54 states that Article 18 of Regulation (EU) 2019/1020 applies to corrective actions. Measures, decisions or orders must state their exact grounds and be communicated without delay with information about available remedies. The economic operator must generally have an opportunity to be heard within an appropriate period of not less than 10 working days, subject to the urgency exception set out in Article 18.

11 / 11

Maintain an Evidence Trail From Finding to Closure

A defensible corrective-action record should connect the authority finding to affected product versions, root-cause analysis, remediation decisions, technical verification, market and supply-chain scope, user communications where relevant and final closure evidence. This lets the company demonstrate not only that it acted, but that the action addressed the specific non-compliance across the products concerned.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.