← Back to CRA Insights
Enforcement

CRA Market Surveillance: Who Enforces the Cyber Resilience Act and How

Editorial cover for an article on national market surveillance authorities enforcing the EU Cyber Resilience Act. A connected device under official examination on a neutral surface beside a stamped dossier. Institutional and calm, not threatening, no police or courtroom imagery, no text baked into the image. Brand navy #1C3D6E dominant, small #E0A100 accent on the inspection mark.

The European Commission wrote the Cyber Resilience Act. It does not enforce it against your product. That job belongs to national market surveillance authorities (MSAs) - one or more per Member State, designated under Article 52 of Regulation (EU) 2024/2847. Article 52 also makes Regulation (EU) 2019/1020 - the general EU market surveillance regulation - apply to products with digital elements. That means CRA enforcement uses the same toolkit already used for CE-marked physical products: information requests, document review, product testing, corrective action orders, restriction of sale, withdrawal, and recall. Fines are the last step, not the first.

If your mental model of CRA enforcement is "Brussels sends a fine," update it. The authority that will knock on your door - or send the formal letter - is a national body, operating under national administrative law, using powers that have existed in the EU product-safety world for years.

Key points

  • Article 52 of Regulation (EU) 2024/2847 requires each Member State to designate one or more market surveillance authorities and applies Regulation (EU) 2019/1020 to products with digital elements.
  • The Commission does not enforce the CRA against individual products. National MSAs do.
  • Germany has designated the BSI (Federal Office for Information Security) as its market surveillance authority. Most other Member State designations are still being published - check the authority for your largest EU market.
  • Enforcement can start three ways: authority-initiated sweeps, third-party complaints, or information passed on from ENISA or the Commission (including your own Article 14 vulnerability reports).
  • The most commercially damaging power is not the fine - it is the stop-sale order. A product restriction can halt revenue immediately.
  • The Article 14 reporting obligation bites first, from 11 September 2026. Full product obligations (CE marking, technical file, essential requirements) apply from 11 December 2027.
  • The most common failure mode is not "we had no security" - it is "we could not produce the documentation on request within the deadline."

Who the authority is

Article 52 of Regulation (EU) 2024/2847 requires each Member State to designate one or more market surveillance authorities responsible for ensuring effective enforcement of the CRA. A Member State may designate an existing authority or create a new one. There is no requirement to use a cybersecurity-specific body - some countries may designate a general product-safety authority, others a dedicated digital or cybersecurity regulator.

The clearest example so far is Germany. The German Federal Office for Information Security (BSI) has been designated as Germany's CRA market surveillance authority, and from 11 June 2026 also acts as the notifying authority responsible for conformity assessment body notifications. That institutional choice matters if you sell into Germany: one body, one point of contact, one set of inspection procedures. Other Member States may split market surveillance and notification duties between separate agencies, so do not assume the German model applies everywhere.

The European Commission's CRA Member States page maintains a list of designated notifying authorities and market surveillance authorities. As of the date of this post, designations are still being published across the EU - the process is live but not complete. Before you finalise your compliance plan, check which authority covers your largest EU market. Do not assume the answer.

The same MSAs are also responsible for market surveillance of open-source software steward obligations under Article 24. If your organisation falls into the steward category, the same enforcement machinery applies - though with a lighter obligation set. See our CRA open-source steward guide for the full picture.

Isometric illustration of a network of national government buildings across a stylised map of Europe, each connected by lines to a central EU emblem, representing distributed national enforcement authorities coordinating across borders

How enforcement actually starts

MSAs do not wait for something to go wrong. Under Regulation (EU) 2019/1020, enforcement can begin in three distinct ways.

1. Authority's own initiative - planned sweeps and sampling. The CRA expressly inserts itself into Regulation (EU) 2019/1020's Annex I, so national authorities can coordinate cross-border "sweeps" - coordinated checks of product categories across multiple Member States simultaneously. An authority can select a product category, acquire samples from the open market (including under a cover identity - more on that below), and begin assessment without any prior complaint or notification. Sector-wide sweeps are a standard tool in CE-marking enforcement and will be used for digital products too.

2. Consumer or third-party complaints. Any person - a competitor, a security researcher, a customer, a journalist - can bring a non-compliant product to an authority's attention. There is no formal threshold for a complaint to trigger an investigation. A credible report of a missing CVD policy, an absent EU Declaration of Conformity, or a product with known unpatched vulnerabilities is enough to open a file.

3. Information passed on from ENISA or the Commission. This is the route that catches many teams off guard. When you submit an Article 14 vulnerability report to ENISA via the single reporting platform, that information enters a system that national authorities can access. If a report reveals a pattern - a vulnerability class, a product line, a manufacturer - that information can be passed to the relevant MSA. Your own reporting can, in principle, trigger scrutiny of your broader compliance posture.

There is a fourth, indirect trigger worth noting. Importers and distributors have their own obligations under the CRA: if they become aware of a non-compliant product, they must act and inform the manufacturer. A customer in your supply chain can therefore trigger scrutiny - either by contacting you or by contacting the authority directly. See our importer and distributor obligations guide for how that chain works.


What powers they have

Under Regulation (EU) 2019/1020 - which Article 52 of the CRA applies directly - market surveillance authorities have a substantial toolkit, and they can use it in sequence or in combination.

Information and documentation requests. Authorities can require any economic operator to provide relevant documents and information to assess conformity. This is typically the first step: a formal letter requesting your technical file, Declaration of Conformity, and supporting evidence within a set deadline.

Access to technical documentation. Authorities can obtain access to your Annex VII technical file. Under Article 13 of the CRA, manufacturers must keep the technical documentation and EU Declaration of Conformity available to market surveillance authorities for at least 10 years after the product has been placed on the market, or for the support period, whichever is longer.

Product sampling and testing - including undercover. Under Regulation (EU) 2019/1020, market surveillance authorities have the power to acquire product samples, including under a cover identity, to inspect those samples and to reverse-engineer them in order to identify non-compliance and obtain evidence. An authority can buy your product from a retailer or online marketplace without identifying itself, test it in a lab, and use the results as evidence. This is not a theoretical power - it is used routinely in CE-marking enforcement today.

Corrective action orders. If an authority finds non-compliance, it can require the economic operator to bring the product into compliance within a set period. This is the standard first response to a finding - not a fine.

Restriction, withdrawal, and recall. Where non-compliance or risk persists, market surveillance authorities can prohibit or restrict the making available of a product on the market, order its withdrawal from the market, or order a recall of products already in the hands of end users.

The practical point here is important: a stop-sale order is usually far more commercially damaging than a fine. A fine is a one-time cost. A product restriction halts revenue from that product line immediately, in every Member State that adopts the measure, for as long as the non-compliance persists. If you sell through distributors or platform marketplaces, a restriction order can cascade through your entire channel within days. This is the practical reason to care about CRA enforcement - not the headline fine numbers.

For the fine tiers themselves - the three-tier structure under Article 64, the turnover percentages, and who cannot be fined - see our CRA penalties post.

star Important

A stop-sale order can halt revenue from a product line immediately and across multiple Member States simultaneously. Fines are the last step in the enforcement sequence — product restrictions come first and can be far more damaging commercially.


What they will ask you for

When an authority opens a file on your product, it will typically request documents in a predictable order. The failure mode is almost never "we had no security" - it is "we could not produce the documentation on request within the deadline." Here is the evidence pack, in the order it is usually requested:

  1. EU Declaration of Conformity (Annex V). The signed declaration that your product meets the essential requirements. This is the first document an authority will ask for - it is the formal claim you are making about your product.

  2. Technical documentation (Annex VII). The full technical file, retained for 10 years. This is the evidence behind the Declaration. See our Annex VII technical documentation guide for what it must contain.

  3. Article 13 cybersecurity risk assessment. The document that connects your product's real-world risks to the specific security measures you have implemented. See our Article 13 risk assessment guide.

  4. SBOM (Software Bill of Materials). The machine-readable inventory of your product's components, required under Annex I, Part II. Authorities can specifically request SBOMs from manufacturers of product categories under review. See our SBOM guide.

  5. Vulnerability-handling evidence (Annex I, Part II). Records showing how you identify, triage, and remediate vulnerabilities, including your coordinated vulnerability disclosure policy and contact point. See our Annex I, Part II guide.

  6. User documentation (Annex II). The information you ship with the product - installation guidance, security configuration, support period end date, contact point for reporting vulnerabilities. See our Annex II user documentation guide.

  7. Declared support period and its justification. The period you have committed to providing security updates, and the documented reasoning behind it. See our support period guide.

  8. CVD policy and contact point. A publicly accessible way for security researchers and users to reach you. This is both an Annex I, Part II requirement and one of the first things an authority will check - it is visible without any formal request.


The timing reality

The CRA switches on in stages, and it matters for enforcement.

The Article 14 vulnerability reporting obligation - the 24-hour early warning, 72-hour notification, and 14-day final report - applies from 11 September 2026, for all in-scope products already on the market, not just new ones placed after that date. As of the date of this post that date has not yet arrived, so the duty is not yet enforceable. But there is no grace period once it does: from 11 September the clock runs on the first qualifying vulnerability you become aware of. If your product is in scope and you have no reporting workflow, that is the gap to close first.

Full product obligations - the essential cybersecurity requirements in Annex I, CE marking, the EU Declaration of Conformity, and the technical documentation - apply from 11 December 2027. Document-driven enforcement on the technical file starts from that date. An authority cannot demand your Annex VII file for a product placed on the market before December 2027 and cite non-compliance with the full CRA - unless the product has been substantially modified after that date.

The practical implication: you have time to build the technical file, but far less time to build the reporting infrastructure.

CRA Enforcement Timeline — What's Live and What's Coming

What to do now

You do not need a legal team to take these steps. You need an owner and a system.

  • Nominate a single owner for regulatory correspondence. Make sure the contact address on your product, your Annex II documentation, and your EU Declaration of Conformity reaches a monitored inbox - not a shared alias that nobody checks.

  • Keep the technical file assembled, not scattered. The failure mode is a folder full of half-finished documents across three different drives. Treat the Annex VII file as a living document with a named owner, not a pre-deadline sprint.

  • Rehearse producing the pack against a 10-working-day request. Authorities will set a deadline when they request documentation. Run a dry run: can your team produce all eight items above within 10 working days? If not, find out where the bottleneck is now.

  • Check which authority covers your largest EU market. Start with the Commission's CRA Member States page. If your main market is Germany, your counterpart is the BSI. For other markets, designations are still being published - check and monitor.

  • Make sure your EU importer knows who to contact at your company. Importers have their own CRA obligations and can trigger scrutiny. They need a named contact, not a generic support email.

  • Stand up your Article 14 reporting flow before 11 September 2026. If you have not already done this, it is the most urgent action on this list. See our September 2026 reporting deadline guide.


Go deeper

lightbulb Tip

Stay current as national designations are published. The enforcement landscape is still forming — new MSA designations, ADCO guidance, and Commission implementing acts will all affect how enforcement works in practice. Subscribe to The CRA Brief → for a concise update whenever something material changes.


This article is general guidance on the Cyber Resilience Act, not legal advice. The correct compliance approach for your specific product depends on its category, intended use, and the national procedures of the relevant market surveillance authority. Confirm specifics against Regulation (EU) 2024/2847 and consult a qualified expert for formal compliance decisions.