Importers must check before placing a product on the Union market that the manufacturer has carried out the appropriate conformity assessment, drawn up technical documentation, applied the CE marking, provided the EU declaration of conformity, and supplied required user information. Distributors must act with due care and verify CE marking, manufacturer and importer identification, support-period information, user instructions, and necessary documents before making products available.
Market surveillance authorities can request data and documentation needed to assess design, development, production, and vulnerability handling. Where a product or its vulnerability handling presents a significant cybersecurity risk, authorities can evaluate the product, require corrective action, withdrawal, or recall, and coordinate with CSIRTs, ENISA, other market surveillance authorities, and data-protection authorities where relevant.