Cyber Resilience Act

Administrative cooperation group (ADCO)

Practical term

An administrative cooperation group (ADCO) is the standing coordination body of the national market surveillance authorities of a given sector. Article 52(15) of the Cyber Resilience Act (CRA) establishes a dedicated ADCO, on the legal basis of Article 30(2) of the Market Surveillance Regulation (EU) 2019/1020. The purpose sits in the same sentence: the uniform application of the Regulation.

For manufacturers, ADCO is not an authority they deal with directly. It issues no orders, imposes no fines and sends no request for information to a company. What it does shape is the yardstick used by the authorities that do all three.

Who sits in it

ADCO is composed of representatives of the designated market surveillance authorities and, where appropriate, representatives of the single liaison offices. The Commission attends the meetings under Article 30(3) of Regulation (EU) 2019/1020 and, under recital 108 of the CRA, assists the group through an executive secretariat providing technical and logistic support.

Upward, ADCO connects to the Union Product Compliance Network, whose members include the chairs of every ADCO under Article 30(1) of Regulation (EU) 2019/1020. Sideways, recital 108 has it liaise with other ADCOs, such as the one established under the Radio Equipment Directive 2014/53/EU, and invite independent experts.

Support periods: the most visible mandate

Article 52(16) first tasks the market surveillance authorities with monitoring how manufacturers applied the Article 13(8) criteria when setting the support period. ADCO turns that data into three outputs:

  • it publishes statistics on categories of products with digital elements, including average support periods, in a publicly accessible and user-friendly form;
  • it provides guidance setting out indicative support periods per category;
  • where the data suggests inadequate periods, it may recommend that authorities focus their activities on those categories.

The third output bites fastest, because it steers where anyone looks in the first place. The first two work over a longer horizon: under Article 13(8), the Commission may, taking ADCO recommendations into account, adopt delegated acts specifying a minimum support period for particular product categories where the market surveillance data suggests inadequate support periods. Recital 62 names two triggers: manufacturers departing systematically from the criteria, or manufacturers in different Member States setting unjustifiably divergent periods. A statistic can therefore end up as binding law.

The statutory floor is untouched by all of this. The Support period is at least five years, unless the product is expected to be in use for less.

Dependency assessment and software bills of materials

Article 13(25) hands ADCO a second and far less familiar instrument. It may decide to carry out a Union-wide assessment of dependency on software components for specific product categories, in particular on components qualifying as free and open-source software. Market surveillance authorities may then require manufacturers in those categories to submit the Software Bill of Materials (SBOM) referred to in Part II, point 1, of Annex I.

Confidentiality is built into the mechanism. Article 13(25) provides that market surveillance authorities may give ADCO anonymised and aggregated information about software dependencies, not the bills of materials themselves; recital 22 gives the reason expressly, namely protecting the confidentiality of those bills of materials. ADCO reports the outcome to the Cooperation Group established under Article 14 of the NIS2 Directive. The practical consequence for manufacturers: your SBOM can be called for even when nobody suspects your product of non-compliance.

Open source, sandboxes, labelling

Three further competences are scattered across the Regulation:

  • Article 52(15) also has ADCO address specific matters related to market surveillance activities in relation to the obligations placed on open-source software stewards; those obligations are set out in Article 24.
  • Where a Member State sets up a cyber resilience regulatory sandbox, Article 33(2) has it inform the Commission and the other market surveillance authorities through ADCO.
  • Before adopting implementing acts on labels, pictograms or other marks, Article 30(6) requires the Commission to consult ADCO, provided it has already been established.

On top of that sits the general task list in Article 32(2) of Regulation (EU) 2019/1020: establishing and coordinating common projects such as cross-border joint market surveillance activities, developing common practices and methodologies, promoting best practices, facilitating sector-specific product evaluations. Recital 109 expressly anticipates that market surveillance authorities, through ADCO, will develop guidance documents, such as best practices and indicators for checking compliance.

Three bodies that get confused

  • The Union Product Compliance Network is the cross-sector umbrella hosted by the Commission. ADCO is the sector-specific layer beneath it.
  • The Cooperation Group under Article 14 of the NIS2 Directive is a body of cybersecurity authorities. ADCO faces it only as the reporter of the dependency assessment.
  • ENISA is an agency with its own CRA tasks and not a member of ADCO. Under Article 59(2) the Commission or ENISA proposes joint activities for market surveillance authorities to check compliance with the Regulation, based on indications or information of potential non-compliance across several Member States; where it identifies categories of products for which coordinated control actions may be organised, Article 60(3) has it submit a proposal to the coordinator.

When the work starts

The CRA sets no date for establishing ADCO, and Article 71 adds none. Article 30(6) in fact conditions the consultation duty on the group having already been established pursuant to Article 52(15), anticipating that the Commission may prepare implementing acts on marks before ADCO exists.

The general date of application is 11 December 2027 under Article 71(2). Statistics on average support periods presuppose that authorities have gathered data first, and that data can only come from products placed on the market under the CRA. Robust per-category guidance is therefore realistic no earlier than a few years into application. Anyone setting a support period today cannot yet lean on it.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.