CRA enforcement is not limited to products that fail a formal compliance requirement. A product can satisfy the Regulation and still create a level of cybersecurity risk that requires intervention. The enforcement path depends on whether the issue is non-compliance, a compliant-but-risky product, or an exceptional Union-level situation. Manufacturers should therefore separate conformity evidence from ongoing product-risk monitoring.
The CRA Uses the Term Significant Cybersecurity Risk
The Regulation uses significant cybersecurity risk as the legal term. This should not be confused with a severe incident having an impact on product security under Article 14. A significant cybersecurity risk is relevant to market-surveillance procedures in Chapter V and can trigger authority evaluation and corrective or restrictive action.
Article 54 Covers Products Suspected of Significant Risk and Non-Compliance
Where a market surveillance authority has sufficient reason to consider that a product with digital elements, including its vulnerability handling, presents a significant cybersecurity risk, Article 54 requires an evaluation without undue delay. The authority assesses compliance with the CRA and the relevant economic operators must cooperate. If non-compliance is found, the authority can require corrective action and escalate to market restrictions if the response is inadequate.
A Product Can Be CRA-Compliant and Still Be Too Risky
Article 57 addresses a different situation. After an Article 54 evaluation, an authority may find that the product and the manufacturer's processes comply with the CRA yet still present a significant cybersecurity risk together with another protected risk. Compliance therefore does not create an absolute shield against intervention where the real-world cybersecurity risk remains significant.
Article 57 Lists Four Protected Risk Areas
The additional risk can concern the health or safety of persons, compliance with Union or national law intended to protect fundamental rights, the availability, authenticity, integrity or confidentiality of services offered by NIS2 essential entities using electronic information systems, or other aspects of public interest protection. The authority must connect its intervention to the relevant risk context rather than rely on cybersecurity risk in the abstract.
Authorities Can Require the Risk to Be Removed
Article 57 allows the authority to require the economic operator to take all appropriate measures. The measures can include changes ensuring that the product and the manufacturer's processes no longer present the relevant risks when the product is made available on the market. The response should be commensurate with the nature of the risks.
Withdrawal and Recall Remain Available
Where proportionate, Article 57 measures can include withdrawal from the market or recall. The fact that the product formally complies with the CRA does not prevent those measures if the statutory risk conditions are met. Withdrawal and recall remain distinct actions and should be planned with accurate product-version, distribution and customer records.
National Measures Can Enter a Union Coordination Process
When a Member State acts against a compliant product presenting the Article 57 risks, the Commission and the other Member States are informed. The Commission can consult the Member States and the relevant economic operator and evaluate whether the national measure is justified. This helps prevent materially inconsistent treatment of the same product across the internal market.
Article 56 Provides a Separate Union-Level Route
Article 56 allows the Commission to act at Union level where it has sufficient reason to consider that a product presenting a significant cybersecurity risk does not comply with the CRA. In exceptional circumstances requiring immediate intervention to preserve the proper functioning of the internal market, the Commission can adopt implementing acts requiring corrective or restrictive measures where effective national action has not been taken.
Risk Monitoring Should Continue After Conformity Assessment
A passed conformity assessment does not end the manufacturer's need to watch product risk. New exploitation methods, deployment patterns, component vulnerabilities or operational dependencies can change the risk profile after market placement. Product security teams should therefore maintain a path from post-market intelligence to vulnerability handling, risk reassessment and corrective action.
Prepare Evidence for Both Conformity and Risk Decisions
An authority reviewing a significant-risk case may need to understand both whether the product complies and why the product nevertheless creates a material risk. Useful evidence can include the cybersecurity risk assessment, architecture, affected-version analysis, vulnerability records, mitigations, security updates, deployment assumptions and the manufacturer's decision record for corrective measures.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.