Independent information resource Product security · EU CRA
CRA enforcement / 02

Which Authorities Enforce the Cyber Resilience Act?

Which national and EU authorities enforce or support enforcement of the Cyber Resilience Act, including market surveillance authorities, the Commission, ENISA, CSIRTs, ADCO, AI Act authorities and data protection authorities.

IN BRIEF

There is no single EU agency that replaces national CRA enforcement. The structure is distributed: Member State market surveillance authorities lead ordinary supervision, while Union bodies and other national authorities support technical analysis, cross-border coordination or specific overlapping legal regimes. Manufacturers should identify the relevant national authority for the market where an enforcement issue arises.

01 / 13

National Market Surveillance Authorities Are the Primary CRA Enforcers

Article 52 requires every Member State to designate one or more market surveillance authorities to ensure effective implementation of the CRA. A Member State may designate an existing authority or establish a new one. These authorities carry out the core supervision, investigation and corrective-measure functions under Chapter V.

02 / 13

The Exact National Authority Can Differ by Member State

The CRA does not force every Member State to use the same institutional model. A country can assign the role to an existing cybersecurity, product-safety, telecommunications or other competent authority, or create a new authority. Companies operating across the Union should therefore maintain a current authority map rather than assuming the regulator in one Member State has the same name or organisational home in another.

03 / 13

Regulation 2019/1020 Supplies the Wider Market-Surveillance Framework

Article 52 makes Regulation (EU) 2019/1020 applicable to CRA products. That framework includes national market-surveillance structures and coordination mechanisms such as the single liaison office. The CRA then adds cybersecurity-specific authority duties, cooperation rules and product-risk procedures.

04 / 13

ENISA Supports Enforcement but Is Not the Ordinary National Regulator

Article 52 allows market surveillance authorities to request technical advice from ENISA, and Article 54 investigations can be supported by ENISA analysis. ENISA also receives and processes CRA reporting information under the reporting framework and can propose coordinated sweeps where its information indicates relevant product categories. These roles support enforcement, but ordinary market-surveillance decisions remain with the competent authority unless the CRA provides a specific Union-level role.

05 / 13

CSIRTs Designated as Coordinators Have a Technical Cooperation Role

Market surveillance authorities cooperate with CSIRTs designated as coordinators in relation to supervision of Article 14 reporting obligations. Authorities can also ask the relevant CSIRT for technical advice and analysis during an Article 54 investigation. The CSIRT is therefore an important technical counterpart, but it is not simply another name for the market surveillance authority.

06 / 13

The European Commission Coordinates and Can Intervene at Union Level

The Commission facilitates cooperation between national authorities, participates in safeguard procedures and can act under Article 56 in exceptional Union-level significant-risk situations where immediate intervention is needed and effective national measures have not been taken. It can adopt implementing acts requiring corrective or restrictive measures, including withdrawal or recall.

07 / 13

ADCO Supports Uniform Application

Article 52 establishes a dedicated administrative cooperation group, ADCO, composed of representatives of designated market surveillance authorities and, where appropriate, single liaison offices. ADCO supports uniform application, addresses market-surveillance issues including open-source software steward obligations and publishes or develops material related to support-period monitoring.

08 / 13

National Cybersecurity Certification Authorities Can Be Relevant

Where relevant, CRA market surveillance authorities cooperate and exchange information with national cybersecurity certification authorities designated under the Cybersecurity Act. This matters where conformity arguments rely on European cybersecurity certification schemes or where findings intersect certification responsibilities.

09 / 13

Data Protection Authorities Can Cooperate on Overlapping Findings

Article 52 requires cooperation, where appropriate, with authorities supervising Union data protection law. Data protection authorities can request and access CRA documentation where necessary for their own tasks, and market surveillance authorities can inform them of findings relevant to their competence. Cybersecurity enforcement can therefore intersect with privacy supervision where product security affects personal-data processing.

10 / 13

High-Risk AI Products Have a Special Market-Surveillance Rule

For CRA products that are also classified as high-risk AI systems under Article 6 of the AI Act, Article 52 assigns CRA market-surveillance activities to the market surveillance authorities designated for the AI Act. Those authorities cooperate with CRA-designated authorities and with CSIRT coordinators and ENISA where the reporting obligations are concerned.

11 / 13

Notified Bodies Are Not Market Surveillance Authorities

A notified body performs conformity-assessment functions under the CRA where the selected procedure requires it. A market surveillance authority performs public enforcement and post-market supervision. Authorities can inform notified bodies about findings, and notified bodies have information duties toward authorities, but the two roles should not be treated as interchangeable.

12 / 13

Importers and Distributors Can Face the Same Authority Network

Market-surveillance powers are not relevant only to manufacturers. Importers, distributors, authorised representatives and other economic operators have CRA obligations and can be involved in authority requests or corrective measures. The responsible company should know which entity placed or made the product available on the Union market and which records that entity must provide.

13 / 13

Build an Authority Map Before an Investigation Starts

For each important EU market, record the designated CRA market surveillance authority, internal legal owner, product-security contact, document custodian and escalation path. Also identify whether the product overlaps high-risk AI, cybersecurity certification, data protection or NIS2-critical-supply-chain concerns. This reduces confusion when several competent bodies become involved in the same technical issue.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.