Independent information resource Product security · EU CRA
CRA fundamentals / 13

Who Enforces the Cyber Resilience Act?

Understand who enforces the Cyber Resilience Act, including national market surveillance authorities, the European Commission, ENISA, CRA ADCO, corrective measures and the CRA penalty framework.

IN BRIEF

CRA enforcement is decentralised across national market surveillance authorities rather than assigned to one single EU regulator. Member States designate the authorities that supervise products and economic operators, while the Commission, ENISA, CSIRTs and CRA cooperation structures perform distinct supporting and coordination roles.

01 / 08

Member State Market Surveillance Authorities Are the Main Enforcers

Article 52 requires each Member State to designate one or more market surveillance authorities responsible for ensuring effective implementation of the Cyber Resilience Act. The CRA also brings covered products within the market-surveillance framework of Regulation (EU) 2019/1020. Enforcement is therefore not centred on one EU-wide inspector that approves every product before it enters the market. Manufacturers generally perform the required conformity work before market placement, while national authorities supervise products on the market, investigate compliance and intervene when the legal conditions for corrective or restrictive action are met.

02 / 08

Authorities Can Evaluate Products and Request Evidence

CRA enforcement depends heavily on the evidence maintained by economic operators. Market surveillance authorities can investigate whether a product with digital elements complies with the Regulation and can request information and documentation relevant to that assessment. For manufacturers, this makes the technical documentation, cybersecurity risk assessment, EU declaration of conformity, product identification, support information and other conformity evidence operationally important after market placement as well as before it. A compliance file that exists only during product release but cannot later be retrieved, explained or connected to the marketed version creates enforcement risk.

03 / 08

Corrective and Restrictive Measures Can Affect the Product

Where an authority identifies non-compliance or a significant cybersecurity risk, the CRA provides procedures for bringing the product into compliance and addressing the risk. Depending on the circumstances, economic operators can be required to take corrective action. More restrictive outcomes can include limiting availability, withdrawal from the market or recall. The enforcement framework therefore reaches the commercial status of the product itself, not only the possibility of a financial penalty. Product-security and compliance teams should have a process for responding quickly to authority requests, assessing affected versions and coordinating remediation, customer communications and supply-chain action.

04 / 08

The European Commission Has a Union-Level Role

National authorities remain central, but the European Commission also has functions within the enforcement system. Article 56 establishes a Union-level procedure for products presenting a significant cybersecurity risk. Where the statutory conditions are met, the Commission can coordinate with relevant market surveillance authorities, request analysis from ENISA and, in specified circumstances, adopt Union-level corrective or restrictive measures. This can include requiring affected products to be withdrawn or recalled. The Commission also supports coordination and consistent implementation across Member States. It should therefore not be described as either the sole CRA enforcement authority or as having no enforcement role.

05 / 08

ENISA and CSIRTs Have Different Roles From Market Surveillance Authorities

ENISA plays an important role in the CRA, particularly through the Single Reporting Platform, cybersecurity expertise, information flows and support for Union-level cooperation. CSIRTs designated as coordinators receive Article 14 notifications through the reporting framework and can provide relevant information to national market surveillance authorities. Those functions should not be confused with the core market-surveillance role. A manufacturer reporting an actively exploited vulnerability through the Single Reporting Platform is interacting with the CRA reporting system. A market surveillance authority assessing product conformity is performing an enforcement function. The same cybersecurity event can therefore involve several authorities for different legal purposes.

06 / 08

CRA ADCO Supports Consistent Enforcement

The CRA establishes cooperation between national market surveillance authorities through an Administrative Cooperation Group, commonly referred to as CRA ADCO. This forum supports coordination, information exchange and a more consistent approach to market surveillance across the Union. National authorities can also carry out joint activities and coordinated control actions. For manufacturers operating across many Member States, that cooperation matters because a compliance issue identified in one jurisdiction may not remain isolated from wider EU market-surveillance activity.

07 / 08

The CRA Includes Significant Administrative Fine Ceilings

Article 64 establishes the CRA penalty framework and requires Member States to lay down effective, proportionate and dissuasive rules. Non-compliance with Annex I essential cybersecurity requirements and obligations in Articles 13 and 14 can be subject to administrative fines of up to EUR 15 million or, for an undertaking, up to 2.5 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Other listed infringements can carry lower maximum levels, and providing incorrect, incomplete or misleading information in response to specified authority or notified-body requests has its own penalty tier. The precise enforcement outcome depends on the legal framework and circumstances of the case.

08 / 08

Enforcement Readiness Is an Evidence and Response Problem

Companies preparing for CRA enforcement should make sure that product evidence can be retrieved quickly and that responsibility for authority requests is clear. Each covered product should have an identifiable owner, current conformity records, a version history, cybersecurity risk evidence, vulnerability records and the required manufacturer and supply-chain information. Legal and product-security teams should know who communicates with a market surveillance authority and who can coordinate remediation if a product is challenged. Enforcement readiness is therefore not a separate document created after compliance work. It is the ability to demonstrate and operate the product-security system that supports the product throughout its market and support lifecycle.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.