Independent information resource Product security · EU CRA
CRA enforcement / 07

Product Recall Under the CRA

Understand product recall under the Cyber Resilience Act, including when authorities can require the return of products already supplied to end users, how recall differs from withdrawal and how manufacturers should manage recall evidence.

IN BRIEF

A CRA recall can be operationally more demanding than withdrawal because affected products are already with users. The manufacturer may need to identify affected users, issue clear notices, provide return, replacement or remediation instructions, coordinate with distributors and preserve evidence showing how the affected end-user population was addressed.

01 / 11

Recall Concerns Products Already With End Users

Regulation (EU) 2019/1020 defines recall as any measure aimed at achieving the return of a product that has already been made available to the end user. This distinguishes recall from withdrawal, which addresses products still in the supply chain before they reach the end user.

02 / 11

Article 54 Can Require Recall After a Non-Compliance Finding

Where an Article 54 evaluation finds CRA non-compliance, the market surveillance authority can require the relevant economic operator to bring the product into compliance, withdraw it or recall it within a reasonable period commensurate with the nature of the cybersecurity risk. Recall is therefore one of the express corrective outcomes available under the CRA.

03 / 11

Recall Can Follow Inadequate Corrective Action

If adequate corrective action is not taken within the period required by the authority, recall can also become a provisional restrictive measure. This makes timely technical remediation and communication important because failure to resolve the issue can lead to a more disruptive end-user return process.

04 / 11

Article 57 Can Reach a Product That Formally Complies

Under Article 57, a product and manufacturer processes can comply with CRA requirements yet still present a significant cybersecurity risk together with specified risks to protected interests. Authorities can still require proportionate measures, including recall, where necessary to address that risk.

05 / 11

Persistent Formal Non-Compliance Can Lead to Recall

Article 58 first requires the manufacturer to end specified formal non-compliance. If the problem persists, the Member State can take measures to restrict or prohibit market availability or ensure that the product is recalled or withdrawn. Administrative and documentation failures can therefore escalate into market action if they are not corrected.

06 / 11

Identify Which End Users Are Affected

A recall plan should define the affected product models, versions, serial ranges, software builds and deployment conditions. The company should then identify the channels available to reach affected users, including direct account records, registration databases, enterprise customer contacts, distributors, marketplaces and public security communications.

07 / 11

A Security Update May Avoid Physical Return in Some Cases

Not every serious product-security issue requires a physical return if an effective security update or other remediation can bring the product into acceptable compliance. The appropriate corrective measure depends on the authority decision, the nature of the cybersecurity risk, update capability and whether affected users can reliably receive and apply the remediation.

08 / 11

Recall Communication Must Be Actionable

Users need enough information to determine whether their product is affected and what action to take. A recall notice should identify the affected product population, explain the required return or remediation process, provide safe interim instructions where relevant and identify support channels. Ambiguous product identification can leave vulnerable units in use.

09 / 11

Coordinate the Return, Replacement or Remediation Process

The company should define how returned products are handled, whether users receive replacement or corrected products, how digital licences or accounts are transferred and how collected devices or components are securely processed. Where software rather than hardware is recalled, the equivalent process may involve disabling distribution, withdrawing access or moving users to a corrected supported version.

10 / 11

Track Recall Effectiveness

A recall record should distinguish notifications sent from products actually returned, replaced or remediated. Where the company cannot reach every end user, it should preserve the communication channels used and any follow-up measures. Effectiveness evidence is important when demonstrating that the authority's corrective requirement was implemented rather than merely announced.

11 / 11

Preserve Recall Evidence

The enforcement file should preserve the recall decision, affected-user population, notices, distributor communications, return records, replacement or remediation evidence, completion rates and final authority correspondence. This creates a traceable record of how products already in end-user hands were addressed.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.