FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
826of826items
Across 40 modules • Updated Mar 10, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Mar 10, 2026
CRA Market Surveillance and Enforcement

Can authorities ask for internal documentation and data, not just the public-facing compliance file?

Yes.

On a reasoned request, authorities must be granted access to the data needed to assess design, development, production, and vulnerability handling, including related internal documentation of the relevant economic operator. The documentation must be accessible in a language easily understood by the authority.

Citations
Cyber Resilience Act

Article 53 gives authorities access, on reasoned request, to data and internal documentation needed to assess conformity.

CRA Market Surveillance and Enforcement

Can data-protection authorities also access CRA documentation?

Yes, where they need that documentation for the fulfilment of their own tasks.

Article 52(7) gives authorities supervising Union data-protection law the power to request and access documentation created or maintained under the CRA, while also requiring them to inform the designated CRA market-surveillance authorities of the Member State concerned.

Citations
Cyber Resilience Act

Article 52(7) gives data-protection supervisory authorities access to CRA documentation when needed for their tasks.

CRA Market Surveillance and Enforcement

Do market-surveillance authorities have to test a product in the same way as the manufacturer?

Not necessarily.

The Commission FAQ says authorities may consider using the same methodology as the manufacturer, especially where that methodology is part of a harmonised standard supporting the CRA, but they may use a different methodology on a justified basis.

Citations
CRA Market Surveillance and Enforcement

What measures can a national authority require after it finds CRA non-compliance?

It can require the relevant economic operator to bring the product into compliance, withdraw it from the market, or recall it.

The deadline must be reasonable and proportionate to the nature of the cybersecurity risk.

Citations
Cyber Resilience Act

Article 54(1) lists corrective action, withdrawal, and recall after a finding of CRA non-compliance.

CRA Market Surveillance and Enforcement

If a CRA problem is found in one Member State, does the corrective action stop there?

No.

If the product has been made available across the Union, the economic operator must ensure that appropriate corrective action is taken for all affected products throughout the Union.

Citations
Cyber Resilience Act

Article 54(3)-(4) requires Union-wide corrective action for affected products when non-compliance is not confined nationally.

CRA Market Surveillance and Enforcement

What happens if the operator does not take adequate corrective action?

The national authority must take appropriate provisional measures itself.

Those measures can include prohibiting or restricting the product from being made available on the national market, withdrawing it, or recalling it. The authority must then notify the Commission and the other Member States without delay.

Citations
Cyber Resilience Act

Article 54(5)-(6) governs national provisional restrictions, withdrawal, recall, and notification to the Commission and Member States.

CRA Market Surveillance and Enforcement

When does a national provisional measure become "deemed justified" at Union level?

If no Member State and the Commission object within three months after the Article 54(5) notification, the measure is deemed justified.

That deeming rule does not prejudice the economic operator's procedural rights under Regulation (EU) 2019/1020.

Citations
Cyber Resilience Act

Article 54(8)-(9) sets the three-month no-objection rule and follow-up restrictive measures.

CRA Market Surveillance and Enforcement

What is the CRA Union safeguard procedure?

It is the Commission review process that applies when another Member State objects to a notified national measure or when the Commission considers that measure contrary to Union law.

The Commission must consult the relevant Member State and the economic operator, evaluate the national measure, and decide within nine months from the Article 54(5) notification whether the measure is justified.

Citations
Cyber Resilience Act

Article 55(1)-(2) sets Commission consultation, evaluation, decision timing, and follow-up for objected national measures.

CRA Market Surveillance and Enforcement

What if the underlying CRA enforcement problem comes from a harmonised standard, a certification scheme, or a common specification?

The safeguard procedure still applies, but the Commission may also need to act on the conformity tool itself.

If the justified national measure is linked to shortcomings in a harmonised standard, the Commission applies the standards safeguard procedure. If it is linked to shortcomings in a European cybersecurity certification scheme or in common specifications, the Commission must consider whether to amend or repeal the CRA act that gave that tool presumption-of-conformity effect.

Citations
Cyber Resilience Act

Articles 54(6)(b) and 55(3)-(5) address shortcomings in harmonised standards, certification schemes, and common specifications.

CRA Market Surveillance and Enforcement

Can a product still be restricted even if it complies with the CRA?

Yes.

Article 57 covers products that are compliant with the CRA but still present a significant cybersecurity risk together with a risk to health or safety, fundamental-rights compliance, the availability, authenticity, integrity or confidentiality of services offered by essential entities, or other aspects of public-interest protection.

Citations
Cyber Resilience Act

Article 57(1)-(5) covers compliant CRA products that still present listed significant cybersecurity and public-interest risks.

CRA Market Surveillance and Enforcement

Can the Commission intervene directly in exceptional cases?

Yes.

If immediate intervention is justified to preserve the proper functioning of the internal market, and effective national measures have not been taken, the Commission may carry out its own evaluation, may request ENISA analysis, and may adopt Union-level implementing acts requiring corrective or restrictive measures, including withdrawal or recall.

The CRA provides this type of Union-level intervention both for non-compliant products that present a significant cybersecurity risk and for compliant products that still present the risks covered by Article 57.

Citations
Cyber Resilience Act

Articles 56(3)-(7) and 57(6)-(10) allow Union-level intervention when immediate internal-market action is justified.

CRA Market Surveillance and Enforcement

What role do CSIRTs and ENISA play in CRA enforcement?

They support enforcement, but they are not the primary market-surveillance authorities.

Authorities may ask CSIRTs designated as coordinators or ENISA for technical advice and compliance-support analysis. ENISA can also propose joint activities and identify product categories for sweeps.

Citations
Cyber Resilience Act

Articles 52, 56, 57, 59 and 60 support CSIRT and ENISA technical advice, analysis, joint-activity proposals, and sweep proposals.

CRA Market Surveillance and Enforcement

Does a notified-body certificate or other third-party conformity evidence block CRA market-surveillance action?

No.

The CRA still allows market-surveillance authorities to investigate, require corrective action, adopt restrictive measures, and address formal non-compliance. Where an Article 54 investigation leads to corrective action, the authority must also inform the relevant notified body.

Citations
Cyber Resilience Act

Articles 54, 57 and 58 preserve market-surveillance action even where conformity-assessment evidence exists.

CRA Market Surveillance and Enforcement

What is "formal non-compliance" under the CRA?

It covers certain documentary or marking failures even before the authority proves a deeper substantive breach of Annex I.

Article 58 lists the relevant cases: CE marking missing or wrongly affixed, the EU declaration of conformity missing or incorrect, the notified-body identification number missing where required, or technical documentation unavailable or incomplete.

Citations
Cyber Resilience Act

Article 58(1) lists CRA formal non-compliance findings for CE marking, declarations, notified-body numbers, and technical documentation.

CRA Market Surveillance and Enforcement

What happens under the CRA if formal non-compliance is not fixed?

The Member State concerned must take appropriate measures to restrict or prohibit the product from being made available on the market or to ensure that it is recalled or withdrawn.

Citations
Cyber Resilience Act

Article 58(2) requires restrictions, prohibition, recall, or withdrawal when formal non-compliance persists.

CRA Market Surveillance and Enforcement

What are joint activities under the CRA?

They are coordinated actions that market-surveillance authorities may carry out with other relevant authorities for specific products or categories of products, especially where those products are often found to present cybersecurity risks.

The Commission or ENISA may propose joint activities based on indications of potential non-compliance across several Member States, and the agreement on joint activities must be made public.

Citations
Cyber Resilience Act

Article 59 defines CRA joint activities and their publication, competition, and later-use safeguards.

CRA Market Surveillance and Enforcement

What are CRA sweeps?

Sweeps are simultaneous coordinated control actions for particular products or product categories to check compliance or detect infringements.

They may include inspections of products acquired under a cover identity. Unless the participating authorities agree otherwise, sweeps are coordinated by the Commission, and ENISA may propose categories of products for which sweeps should be organised.

Citations
CRA Market Surveillance and Enforcement

Can CRA market surveillance focus on support-period decisions as well as immediate vulnerabilities?

Yes.

Authorities must monitor how manufacturers applied the Article 13(8) criteria when determining support periods. ADCO must publish relevant statistics, including average support periods, and may issue recommendations to focus surveillance on product categories where support periods appear inadequate.

Citations
Cyber Resilience Act

Article 52(16) requires monitoring of support-period criteria and allows ADCO recommendations for surveillance focus.

CRA Market Surveillance and Enforcement

Is CRA enforcement subject to confidentiality protections?

Yes.

The CRA protects intellectual property, confidential business information, trade secrets, source code, the effectiveness of inspections and investigations, public and national security interests, and the integrity of criminal or administrative proceedings. Information exchanged confidentially between authorities and the Commission is also protected against onward disclosure without the originating authority's agreement.

Citations
Cyber Resilience Act

Article 63 protects confidential information, source code, investigations, security interests, and proceedings.

CRA Market Surveillance and Enforcement

How do CRA penalties and administrative fines work?

Member States must lay down the national penalty rules, but Article 64 sets Union-level caps for certain infringements.

The highest cap applies to non-compliance with Annex I and with Articles 13 and 14: up to EUR 15 000 000 or, for an undertaking, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 64 also sets lower caps for other listed obligations and for supplying incorrect, incomplete, or misleading information.

Citations
Cyber Resilience Act

Article 64(1)-(4) sets Member State penalty rules and Union-level administrative-fine caps for listed infringements.

Page 16 of 42