Independent information resource Product security · EU CRA
CRA enforcement / Pillar

CRA Enforcement, Market Surveillance and Penalties

A practical guide to Cyber Resilience Act market surveillance, authority powers, product investigations, corrective measures, withdrawal, recall, formal non-compliance and administrative fines.

IN BRIEF

CRA enforcement is not limited to fines after a breach. Market surveillance begins with monitoring, complaints, authority intelligence, reporting information or evidence of product risk. An authority can examine whether the product and the manufacturer's processes comply, require remediation and escalate to restrictions, withdrawal or recall where necessary. Cross-border procedures help extend justified national measures across the Union, while Article 64 sets maximum administrative fine levels for specified infringements.

01 / 14

CRA Enforcement Sits Inside the EU Market-Surveillance System

Article 52 states that Regulation (EU) 2019/1020 applies to products with digital elements within the CRA. The CRA therefore adds cybersecurity-specific rules to the wider EU market-surveillance framework rather than creating a completely separate enforcement system. Manufacturers should read Chapter V together with the market-surveillance powers and procedures that already apply under Regulation (EU) 2019/1020.

02 / 14

Member States Designate the Market Surveillance Authorities

Each Member State must designate one or more market surveillance authorities to ensure effective implementation of the CRA. A Member State can appoint an existing authority or create a new one. This means enforcement is national in day-to-day operation, but the authorities work within a harmonised Union framework and exchange information when risks or non-compliance extend beyond one national market.

03 / 14

Market Surveillance Covers More Than the Finished Product

CRA market surveillance can examine both a product with digital elements and the processes put in place by its manufacturer. Article 53 expressly allows access, on a reasoned request, to data needed to assess design, development, production and vulnerability handling, including related internal documentation. A market-surveillance review can therefore reach architecture, risk assessment, testing, release controls and vulnerability-handling evidence rather than stopping at a visual product inspection.

04 / 14

A Significant Cybersecurity Risk Can Trigger a National Evaluation

Under Article 54, where a market surveillance authority has sufficient reason to consider that a product, including its vulnerability handling, presents a significant cybersecurity risk, it must carry out an evaluation without undue delay. The relevant economic operators must cooperate. The evaluation concerns compliance with the requirements of the CRA, and the authority can seek technical support from the relevant CSIRT or ENISA.

05 / 14

Authorities Can Require Corrective Action, Withdrawal or Recall

If an Article 54 evaluation finds non-compliance, the authority must require the relevant economic operator to take appropriate corrective actions. Depending on the case, that can mean bringing the product into compliance, withdrawing it from the market or recalling it within a reasonable period that reflects the nature of the cybersecurity risk. The authority also informs the relevant notified body where applicable.

06 / 14

Failure to Correct Can Lead to Restrictive Measures

If the economic operator does not take adequate corrective action within the required period, Article 54 allows the market surveillance authority to take provisional measures to prohibit or restrict the product from being made available on its national market, withdraw it or recall it. The Commission and other Member States are then notified, allowing the measure to move into the Union coordination process.

07 / 14

CRA Enforcement Can Expand Across the Union

Where non-compliance is not restricted to one national territory, the initiating authority informs the Commission and the other Member States. If no objection is raised within the Article 54 period, the provisional measure is deemed justified and market surveillance authorities across the Union must take appropriate restrictive measures. Article 55 provides a safeguard process where another Member State objects or the Commission questions the national measure.

08 / 14

The Commission Can Intervene at Union Level

Article 56 provides a Union-level procedure for products presenting a significant cybersecurity risk. In exceptional circumstances where immediate intervention is necessary to preserve the proper functioning of the internal market and effective national measures have not been taken, the Commission can evaluate compliance and adopt implementing acts requiring corrective or restrictive measures, including withdrawal or recall.

09 / 14

A Product Can Be Compliant Yet Still Present a Significant Risk

Article 57 covers the unusual case where the product and manufacturer processes comply with the CRA but the product still presents a significant cybersecurity risk together with specified risks to health or safety, fundamental rights, essential-entity services or other public interests. Authorities can still require proportionate measures, including risk reduction, withdrawal or recall. Formal conformity therefore does not eliminate every market-surveillance risk scenario.

10 / 14

Formal Non-Compliance Has Its Own Enforcement Route

Article 58 identifies formal problems such as missing or incorrectly affixed CE marking, a missing or incorrectly drawn up EU declaration of conformity, a missing notified-body identification number where applicable, or unavailable or incomplete technical documentation. The manufacturer must put an end to the non-compliance. If it persists, the Member State can restrict or prohibit market availability or require withdrawal or recall.

11 / 14

Authorities Can Coordinate Joint Activities and Sweeps

Articles 59 and 60 support coordinated enforcement. Market surveillance authorities can conduct joint activities with other relevant authorities and can carry out simultaneous coordinated control actions known as sweeps for selected products or product categories. Sweeps can include products acquired under a cover identity, and information obtained can feed later investigations.

12 / 14

Enforcement Is Supported by ADCO, ENISA and CSIRTs

The CRA creates a dedicated administrative cooperation group, ADCO, for uniform application of the Regulation. Market surveillance authorities can also request technical advice from a CSIRT designated as coordinator or from ENISA. Those bodies support enforcement and coordination, but they are not interchangeable with the national market surveillance authority that exercises the core market-surveillance role.

13 / 14

Article 64 Adds Administrative Fine Exposure

Article 64 requires Member States to establish effective, proportionate and dissuasive penalties. The highest CRA administrative fine tier reaches up to EUR 15 million or, for an undertaking, up to 2.5 percent of total worldwide annual turnover for the preceding financial year, whichever is higher, for specified Annex I and manufacturer or reporting obligations. Other infringement categories have separate maximum tiers.

14 / 14

Enforcement Readiness Is an Evidence-Management Problem

A manufacturer should be able to connect a released product to its cybersecurity risk assessment, technical documentation, architecture, SBOM, test evidence, conformity assessment, declaration, support period, vulnerability records and security updates. When an authority request arrives, the practical challenge is often not whether evidence once existed, but whether the company can retrieve the correct version quickly and explain how it supports the product actually placed on the market.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.