FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Market Surveillance and Enforcement

Does a notified-body certificate or other third-party conformity evidence block CRA market-surveillance action?

No.

The CRA still allows market-surveillance authorities to investigate, require corrective action, adopt restrictive measures, and address formal non-compliance. Where an Article 54 investigation leads to corrective action, the authority must also inform the relevant notified body.

Citations
Cyber Resilience Act

Articles 54, 57 and 58 preserve market-surveillance action even where conformity-assessment evidence exists.

CRA Market Surveillance and Enforcement

What is "formal non-compliance" under the CRA?

It covers certain documentary or marking failures even before the authority proves a deeper substantive breach of Annex I.

Article 58 lists the relevant cases: CE marking missing or wrongly affixed, the EU declaration of conformity missing or incorrect, the notified-body identification number missing where required, or technical documentation unavailable or incomplete.

Citations
Cyber Resilience Act

Article 58(1) lists CRA formal non-compliance findings for CE marking, declarations, notified-body numbers, and technical documentation.

CRA Market Surveillance and Enforcement

What happens under the CRA if formal non-compliance is not fixed?

The Member State concerned must take appropriate measures to restrict or prohibit the product from being made available on the market or to ensure that it is recalled or withdrawn.

Citations
Cyber Resilience Act

Article 58(2) requires restrictions, prohibition, recall, or withdrawal when formal non-compliance persists.

CRA Market Surveillance and Enforcement

What are joint activities under the CRA?

They are coordinated actions that market-surveillance authorities may carry out with other relevant authorities for specific products or categories of products, especially where those products are often found to present cybersecurity risks.

The Commission or ENISA may propose joint activities based on indications of potential non-compliance across several Member States, and the agreement on joint activities must be made public.

Citations
Cyber Resilience Act

Article 59 defines CRA joint activities and their publication, competition, and later-use safeguards.

CRA Market Surveillance and Enforcement

What are CRA sweeps?

Sweeps are simultaneous coordinated control actions for particular products or product categories to check compliance or detect infringements.

They may include inspections of products acquired under a cover identity. Unless the participating authorities agree otherwise, sweeps are coordinated by the Commission, and ENISA may propose categories of products for which sweeps should be organised.

Citations
CRA Market Surveillance and Enforcement

Can CRA market surveillance focus on support-period decisions as well as immediate vulnerabilities?

Yes.

Authorities must monitor how manufacturers applied the Article 13(8) criteria when determining support periods. ADCO must publish relevant statistics, including average support periods, and may issue recommendations to focus surveillance on product categories where support periods appear inadequate.

Citations
Cyber Resilience Act

Article 52(16) requires monitoring of support-period criteria and allows ADCO recommendations for surveillance focus.

CRA Market Surveillance and Enforcement

Is CRA enforcement subject to confidentiality protections?

Yes.

The CRA protects intellectual property, confidential business information, trade secrets, source code, the effectiveness of inspections and investigations, public and national security interests, and the integrity of criminal or administrative proceedings. Information exchanged confidentially between authorities and the Commission is also protected against onward disclosure without the originating authority's agreement.

Citations
Cyber Resilience Act

Article 63 protects confidential information, source code, investigations, security interests, and proceedings.

CRA Market Surveillance and Enforcement

How do CRA penalties and administrative fines work?

Member States must lay down the national penalty rules, but Article 64 sets Union-level caps for certain infringements.

The highest cap applies to non-compliance with Annex I and with Articles 13 and 14: up to EUR 15 000 000 or, for an undertaking, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 64 also sets lower caps for other listed obligations and for supplying incorrect, incomplete, or misleading information.

Citations
Cyber Resilience Act

Article 64(1)-(4) sets Member State penalty rules and Union-level administrative-fine caps for listed infringements.

CRA Market Surveillance and Enforcement

Can administrative fines be added on top of other CRA measures?

Yes.

The CRA expressly allows administrative fines, depending on the circumstances, to be imposed in addition to other corrective or restrictive measures applied for the same infringement.

Citations
Cyber Resilience Act

Article 64(9) allows administrative fines in addition to corrective or restrictive measures.

CRA Market Surveillance and Enforcement

Is supplying misleading information to market-surveillance authorities a separate sanctionable issue?

Yes.

Supplying incorrect, incomplete, or misleading information to notified bodies or market-surveillance authorities in reply to a request has its own fine category, with a cap of up to EUR 5 000 000 or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Citations
Cyber Resilience Act

Article 64(4) sets a separate fine category for incorrect, incomplete, or misleading replies to authorities or notified bodies.

CRA Market Surveillance and Enforcement

Do market-surveillance authorities report enforcement outcomes beyond the immediate case?

Yes.

They must report the outcomes of relevant market-surveillance activities to the Commission on an annual basis. They must also report without delay any information identified during market-surveillance activities that may be of potential interest for the application of Union competition law.

Citations
Cyber Resilience Act

Article 52(13) requires annual market-surveillance reporting and competition-law information reporting.

CRA Market Surveillance and Enforcement

Does every CRA enforcement case follow the same legal track?

No.

The CRA uses different enforcement routes depending on the problem. Article 54, together with Article 55, covers products that present a significant cybersecurity risk and are found non-compliant. Article 57 covers products that comply with the CRA but still present the additional risks listed there. Article 58 covers formal non-compliance such as missing or incorrect CE-marking, declaration, or technical-documentation elements.

Citations
Cyber Resilience Act

Articles 54, 55, 57 and 58 distinguish non-compliant-risk, compliant-risk, safeguard, and formal non-compliance tracks.

CRA Market Surveillance and Enforcement

Does the economic operator get a chance to present its position and keep procedural rights during safeguard action?

Yes.

Article 54(6) requires the notifying authority to include the arguments put forward by the relevant economic operator. Article 54(8) also preserves the operator's procedural rights under Regulation (EU) 2019/1020, and Article 55(1) requires the Commission to consult the relevant economic operator during the Union safeguard procedure. The Blue Guide likewise explains that safeguard decisions are binding legal measures and can be subject to appeal under the applicable framework.

Citations
Cyber Resilience Act

Articles 54(6), 54(8), and 55(1) require operator arguments, preserve procedural rights, and require Commission consultation.

Blue Guide 2022

Section 7.6.2 explains procedural safeguards and the reasons that must support national measures.

CRA Market Surveillance and Enforcement

Can information gathered in a CRA joint activity be used later in a national investigation?

Yes.

Article 59(4) expressly allows a market-surveillance authority to use information obtained through joint activities as part of any investigation it undertakes. So joint activities are not limited to one-off coordination exercises with no later evidentiary value.

Citations
Cyber Resilience Act

Article 59(4) permits market-surveillance authorities to use joint-activity information in later investigations.

CRA Market Surveillance and Enforcement

During a CRA sweep, can authorities use their ordinary investigation powers and involve Commission officials?

Yes.

Article 60 says sweeps may include inspections of products acquired under a cover identity. It also says that, when conducting sweeps, market-surveillance authorities may use the investigation powers in Articles 52 to 58 and any additional powers conferred by national law. They may also invite Commission officials and other persons authorised by the Commission to participate.

Citations
Cyber Resilience Act

Article 60(1), (4), and (5) supports cover-identity inspections, investigation powers, and Commission participation in sweeps.

Page 23 of 58