What can trigger a formal CRA product evaluation by a national authority?
A national authority can open the Article 54 procedure where it has sufficient reason to consider that a product with digital elements, including its vulnerability handling, presents a significant cybersecurity risk.
The evaluation concerns compliance with all CRA requirements, not just one suspected defect.
Article 54(1) sets the significant-cybersecurity-risk trigger for a national evaluation.