Independent information resource Product security · EU CRA
CRA enforcement / 01

How CRA Market Surveillance Works

How Cyber Resilience Act market surveillance works in practice, from monitoring and authority requests to product evaluations, corrective action, cross-border coordination, joint activities and sweeps.

IN BRIEF

Market surveillance is an ongoing post-market control function, not a one-time certification step. It can be triggered by complaints, authority monitoring, reporting information, coordinated activity or evidence of cybersecurity risk. A manufacturer should expect the authority to examine both the product and the processes supporting its lifecycle security.

01 / 13

Market Surveillance Continues After Market Placement

Conformity assessment supports the decision to place a product on the market, while market surveillance checks whether products actually made available in the Union continue to comply with the CRA. Article 52 applies Regulation (EU) 2019/1020 to CRA products, giving the cybersecurity regime a place inside the established EU product-surveillance system.

02 / 13

Authorities Can Use Several Sources of Compliance Intelligence

The CRA does not restrict surveillance to one trigger. Authorities can act on complaints, market-monitoring information, findings from other authorities, Article 14 reporting information shared through the relevant cooperation channels, joint activities, sweeps and information indicating product risk or non-compliance. Manufacturers should therefore assume that enforcement can begin from operational security evidence as well as from a document review.

03 / 13

Authorities Can Request Data Needed to Assess Annex I Compliance

Article 53 requires access, upon a reasoned request, to data needed to assess the design, development, production and vulnerability handling of products and manufacturer processes. The data must be provided in a language easily understood by the market surveillance authority. Related internal documentation can be included within the request.

04 / 13

A Market-Surveillance Review Can Reach Development Evidence

Because Article 53 expressly mentions design and development, a manufacturer should be prepared for scrutiny of cybersecurity risk assessment, architecture, secure-development controls, test results, vulnerability-management records and version-specific technical documentation. The authority is not limited to checking the CE mark or user-facing documentation.

05 / 13

Article 54 Creates the Significant-Risk Investigation Route

When a national market surveillance authority has sufficient reason to consider that a product, including its vulnerability handling, presents a significant cybersecurity risk, Article 54 requires an evaluation without undue delay. The review assesses compliance with the CRA requirements. The economic operator must cooperate as necessary.

06 / 13

Technical Support Can Come From CSIRTs or ENISA

Market surveillance authorities may request a CSIRT designated as coordinator or ENISA to provide technical advice on implementation and enforcement. During an Article 54 investigation, the authority can ask the CSIRT or ENISA for analysis supporting the product compliance evaluation. The market surveillance authority remains the enforcement authority even where specialist technical analysis comes from another body.

07 / 13

Non-Technical Risk Factors Can Matter

Article 54 requires authorities to consider non-technical risk factors when determining the significance of cybersecurity risk, particularly factors established through Union-level coordinated security risk assessments of critical supply chains under NIS2. Where such factors create significant cybersecurity risk, the market surveillance authority informs the relevant NIS2 competent authorities and cooperates as necessary.

08 / 13

Corrective Action Applies to All Affected Products Across the Union

Where an Article 54 evaluation finds non-compliance, the economic operator must ensure that appropriate corrective action is taken for all affected products it has made available on the market throughout the Union. A compliance problem should therefore be analysed by affected product version, geography and distribution scope rather than treated only as a local case involving the sample examined by one authority.

09 / 13

National Restrictions Can Become Coordinated Union Measures

If adequate corrective action is not taken, the authority can restrict or prohibit market availability, withdraw the product or recall it and notify the Commission and other Member States. Other authorities can provide information or object. If the provisional measure is not challenged within the Article 54 period, it is deemed justified and appropriate restrictive measures are taken across Member States.

10 / 13

The Union Safeguard Procedure Resolves Disputed National Measures

Article 55 applies where another Member State objects to a national measure or the Commission considers the measure contrary to Union law. The Commission consults the Member State and economic operator and decides whether the measure is justified. A justified measure can lead to withdrawal of the non-compliant product across Member States.

11 / 13

Joint Activities Can Target Products With Repeated Cybersecurity Risk

Article 59 allows market surveillance authorities to conduct joint activities with other relevant authorities, particularly for products often found to present cybersecurity risks. The Commission or ENISA can propose joint activities where information suggests potential non-compliance across several Member States. Information gathered can later be used in investigations.

12 / 13

Sweeps Are Coordinated Control Actions

Article 60 requires simultaneous coordinated control actions, known as sweeps, for selected products or product categories to check compliance or detect infringements. Sweeps can include products acquired under a cover identity. Unless the participating authorities agree otherwise, the Commission coordinates the sweep and may make aggregated results public.

13 / 13

Manufacturers Should Build a Market-Surveillance Response Process

A practical process should designate an authority-response owner, preserve version-specific evidence, establish legal and engineering escalation routes, identify who can provide technical documentation and internal records, and define how corrective actions are assessed across all affected EU products. Response speed matters because Article 54 enforcement can move quickly from evaluation to corrective or restrictive measures.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.