Independent information resource Product security · EU CRA
CRA enforcement / 06

Product Withdrawal Under the CRA

Understand product withdrawal under the Cyber Resilience Act, including what withdrawal means, when market surveillance authorities can require it, how it differs from recall and what evidence manufacturers should preserve.

IN BRIEF

A CRA withdrawal should be treated as a controlled supply-chain action. The company needs to identify affected models and versions, stop further market availability, notify relevant distributors and other economic operators, control inventory and preserve evidence showing which products were prevented from reaching additional users.

01 / 11

Withdrawal Stops Products Still in the Supply Chain

Regulation (EU) 2019/1020 defines withdrawal as any measure aimed at preventing a product in the supply chain from being made available on the market. That definition is important for CRA enforcement because it separates withdrawal from recall. Withdrawal focuses on products that have not yet reached the end user.

02 / 11

Article 54 Can Require Withdrawal After a Non-Compliance Finding

Where an Article 54 evaluation finds that a product does not comply with the CRA, the market surveillance authority must require appropriate corrective action. The authority can require the product to be brought into compliance, withdrawn from the market or recalled within a reasonable period that reflects the nature of the cybersecurity risk.

03 / 11

Withdrawal Can Also Follow Inadequate Corrective Action

If the relevant economic operator does not take adequate corrective action within the period required by the authority, Article 54 allows provisional restrictive measures. Withdrawal can therefore move from one possible corrective route into an authority-imposed restriction where earlier remediation has not been sufficient.

04 / 11

A Compliant Product Can Still Face Withdrawal in a Significant-Risk Case

Article 57 addresses the unusual situation where the product and manufacturer processes comply with the CRA but the product still presents a significant cybersecurity risk together with specified risks to health, safety, fundamental rights, essential services or other public interests. In that situation, proportionate measures can still include withdrawal or recall.

05 / 11

Formal Non-Compliance Can Escalate to Withdrawal

Article 58 covers formal problems such as missing or incorrectly affixed CE marking, missing or incorrectly drawn up EU declarations of conformity, missing notified-body identification where applicable, or unavailable or incomplete technical documentation. If the manufacturer does not end the formal non-compliance, the Member State can require withdrawal or recall.

06 / 11

Identify the Affected Product Population Before Acting

A withdrawal plan should identify the affected product models, versions, hardware revisions, software builds, batches and markets. The company also needs to know where those products are located in the supply chain so it can distinguish warehouse stock, importer inventory, distributor inventory and products already delivered to end users.

07 / 11

Stop Further Market Availability

The operational purpose of withdrawal is to prevent further making available on the market. This can require shipment holds, sales blocks, marketplace listing changes, distributor stop-sale notices and inventory controls. The exact mechanism depends on the product and distribution model, but the outcome should be that affected supply-chain stock does not continue moving toward end users.

08 / 11

Coordinate With Importers and Distributors

A manufacturer may not directly control every unit in the Union supply chain. Importers and distributors therefore need clear identification of affected products, the action required, the effective date and any conditions under which corrected stock can resume distribution. Communication should use product identifiers that supply-chain partners can apply reliably.

09 / 11

Corrected Products Need Clear Release Criteria

Where withdrawal is connected to a correctable cybersecurity issue, the company should define when a remediated product can re-enter normal distribution. That can include a corrected firmware or software version, updated documentation, completed testing, revised conformity evidence and confirmation that the authority's required corrective action has been satisfied.

10 / 11

Withdrawal Can Become Union-Wide

Where non-compliance is not confined to one Member State, the CRA's safeguard procedures can extend justified restrictive measures across the Union. A manufacturer selling the same affected product in several Member States should therefore map the geographic distribution early rather than treating withdrawal as a purely national inventory issue.

11 / 11

Preserve Withdrawal Evidence

The enforcement record should preserve the authority decision, affected-product population, supply-chain notices, shipment holds, inventory status, corrected-version criteria and completion evidence. Those records help demonstrate that the company actually prevented additional affected units from being made available on the market.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.