Independent information resource Product security · EU CRA
CRA enforcement / 04

CRA Product Investigations Explained

How Cyber Resilience Act product investigations work, including authority triggers, Article 54 significant-risk evaluations, inspections, product sampling, reverse engineering, evidence review and cross-border escalation.

IN BRIEF

CRA investigations can combine documentation review with technical examination of the product. Authorities can request compliance evidence, inspect products, obtain samples and, under the wider market-surveillance framework, reverse-engineer samples to identify non-compliance. Article 54 adds a specific evaluation process for products presenting a significant cybersecurity risk. If the evaluation finds non-compliance, the case moves from investigation into corrective action and potentially market restrictions.

01 / 11

Not Every CRA Investigation Starts With Article 54

The EU market-surveillance framework gives authorities general powers to monitor products and start investigations to identify non-compliance. Article 54 is more specific: it applies when a market surveillance authority has sufficient reason to consider that a product with digital elements, including its vulnerability handling, presents a significant cybersecurity risk. Keeping these routes separate avoids treating every routine compliance check as a significant-risk case.

02 / 11

A Significant-Risk Evaluation Must Begin Without Undue Delay

When the Article 54 threshold is met, the authority must carry out an evaluation of the product without undue delay. The evaluation considers compliance with all requirements laid down in the CRA, not only the single defect or vulnerability that first drew attention to the product. Relevant economic operators must cooperate with the authority as necessary.

03 / 11

The Product and Its Vulnerability Handling Are Both Reviewable

Article 54 expressly includes the product's vulnerability handling. An investigation can therefore examine technical product properties together with the manufacturer's processes for identifying, documenting, remediating and communicating vulnerabilities. A strong response package should connect the product version being investigated to the corresponding vulnerability-handling records.

04 / 11

Authorities Can Combine Documents With Product Testing

A market-surveillance investigation is not limited to reviewing declarations or technical documentation. Regulation (EU) 2019/1020 gives authorities powers for physical checks, unannounced on-site inspections and acquisition of product samples. This allows the authority to compare what the documentation says with the behaviour and technical characteristics of the product itself.

05 / 11

Samples Can Be Acquired Under a Cover Identity

Article 14 of Regulation (EU) 2019/1020 includes the power to acquire product samples, including under a cover identity, to inspect them and obtain evidence. This reduces the possibility that a market-facing product is presented differently merely because the economic operator knows an authority is acquiring it for inspection.

06 / 11

Reverse Engineering Can Be an Investigation Tool

The same Article 14 power allows market surveillance authorities to reverse-engineer acquired samples in order to identify non-compliance and obtain evidence. For software-intensive products, manufacturers should therefore assume that technical claims can be tested against implementation rather than relying only on written compliance statements.

07 / 11

Authorities Can Investigate on Their Own Initiative

Regulation (EU) 2019/1020 requires investigation powers that include starting investigations on the authority's own initiative. Complaints, reports, vulnerability information, market intelligence, coordinated sweeps or other evidence may inform surveillance activity, but an authority does not need to wait for a manufacturer to self-report every possible non-compliance before it can investigate.

08 / 11

CSIRTs and ENISA Can Support the Technical Evaluation

When conducting an Article 54 investigation, CRA Article 52 allows a market surveillance authority to request a CSIRT designated as coordinator or ENISA to provide an analysis supporting the evaluation of product compliance. Those bodies can provide technical support, while the market surveillance authority remains responsible for the enforcement procedure.

09 / 11

Non-Technical Risk Factors Can Matter

Article 54 requires market surveillance authorities, when determining the significance of a cybersecurity risk, also to consider non-technical risk factors, particularly those established through Union-level coordinated security risk assessments of critical supply chains under NIS2. Significant cybersecurity risk is therefore not defined only by a vulnerability severity score or exploit metric.

10 / 11

A Finding of Non-Compliance Changes the Case

If the Article 54 evaluation finds that the product does not comply with the CRA, the authority must without delay require the relevant economic operator to take appropriate corrective actions. Depending on the case, that can mean bringing the product into compliance, withdrawing it or recalling it within a reasonable period commensurate with the cybersecurity risk.

11 / 11

Cross-Border Cases Can Move Beyond One Member State

Where the authority considers that the non-compliance is not restricted to its national territory, Article 54 requires it to inform the Commission and the other Member States of the evaluation results and the actions required from the economic operator. The procedure can then lead to coordinated Union-wide restrictive measures or, if objections arise, the Article 55 Union safeguard procedure.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.