Cyber Resilience Act
Market surveillance authority
Legal definition Art. 3(33) CRA
“a market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020”
A market surveillance authority is the national body that checks and enforces compliance with the Cyber Resilience Act (CRA). The CRA does not define the term itself; it refers to the Market Surveillance Regulation (EU) 2019/1020, which has it as an authority designated by a Member State under Article 10 as responsible for carrying out market surveillance in the territory of that Member State.
Two things sit inside that sentence. Competence is territorial. It stops at the national border. And market surveillance is downstream: it examines products that are already on the market, and replaces no approval before placing on the market.
Who designates the authority
Under Article 52(2), each Member State designates one or more market surveillance authorities. It may assign the role to an existing body or create a new one; recital 107 names the competent authorities under NIS2, the national cybersecurity certification authorities and the market surveillance authorities for the Radio Equipment Directive as candidates. The Commission and the other Member States must be told of the designation and of each authority’s area of competence. That obligation comes from Article 10(2) of Regulation (EU) 2019/1020, which Article 52(1) makes applicable.
The CRA therefore names no authority. Which one is responsible for a given product follows from the national law of the Member State where that product is made available.
What the authority can demand
Its powers attach to documentation you have to hold anyway:
- Article 53 grants access, upon a reasoned request, to the data required to assess design, development, production and vulnerability handling, including the economic operator’s internal documentation.
- Article 13(22) requires manufacturers to provide, upon a reasoned request, all documentation demonstrating conformity with Annex I, and to cooperate on measures to eliminate the risks.
- Technical documentation and the EU declaration of conformity must be kept at the authority’s disposal for at least ten years after placing on the market, and longer where product support runs longer.
- Annex VII, point 8 adds the Software Bill of Materials (SBOM) upon a reasoned request, where the authority needs it to check compliance with Annex I.
- Article 23 obliges every economic operator to name its suppliers and, where available, its customers on request; it must be able to present that information for ten years after it was supplied with the product and for ten years after it supplied the product.
Under Article 52(3), market surveillance also covers the obligations placed on open-source software stewards by Article 24.
The significant cybersecurity risk procedure
Article 54 is the core of enforcement. Where an authority has sufficient reason to consider that a product (including its vulnerability handling) presents a significant cybersecurity risk, it carries out its own evaluation without undue delay, where appropriate with the relevant CSIRT. Non-technical risk factors count too, for instance those from the Union-level coordinated supply chain risk assessments under Article 22 of the NIS2 Directive.
If it finds non-compliance, it requires the economic operator to take corrective action within a period it prescribes and commensurate with the risk, or to take the product off the market (Withdrawal) or call it back (Recall). Where adequate action does not follow, the authority takes provisional measures for its national market and notifies the Commission and the Member States. If no objection is raised within three months, the measure is deemed justified; otherwise the Commission decides under the Union safeguard procedure of Article 55 within nine months of the notification.
Article 57 extends this to products that do comply with the CRA and still present a significant cybersecurity risk. That risk may be to the health or safety of persons, to obligations protecting fundamental rights, or to services of essential entities, among others. Compliance is no safe harbour.
Formal non-compliance
Article 58 lists six findings that need no risk assessment at all: the CE marking is missing or was affixed in violation of Articles 29 and 30, the EU declaration of conformity was not drawn up or not drawn up correctly, the identification number of the notified body involved is missing, or the technical documentation is unavailable or incomplete. Where the defect persists, the Member State must restrict or prohibit the product from being made available, or ensure it is recalled or withdrawn.
This is the lowest-threshold route. It catches manufacturers whose product is technically sound but whose paperwork is not.
Fines
Article 64 leaves the detail to the Member States but sets the ceilings. There are three tiers, and the higher of the two figures applies in each; the percentage is of total worldwide annual turnover for the preceding financial year and applies only where the offender is an undertaking:
- EUR 15 million or 2.5 % for non-compliance with the essential cybersecurity requirements in Annex I and with Articles 13 and 14.
- EUR 10 million or 2 % for breaches of, among others, Articles 18 to 23, Article 28, Article 31(1) to (4) and Article 53.
- EUR 5 million or 1 % for supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities in reply to a request.
The amount turns on the nature, gravity and duration of the infringement and of its consequences, on whether the same or other market surveillance authorities have already fined the same operator for a similar infringement, and on that operator’s size and market share. Fines imposed are communicated to the authorities of the other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.
Article 64(10) carves out two cases: manufacturers that qualify as microenterprises or small enterprises for missing the 24-hour early warning deadline in Article 14(2), point (a), and Article 14(4), point (a), and open-source software stewards for any infringement. The drafting here is imprecise: the carve-out is framed as a derogation from paragraphs 3 to 9, while the fines for breaches of Article 14 sit in paragraph 2.
More than policing
Part of the mandate is cooperative. Article 52(10) allows authorities to give economic operators guidance and advice on implementation. Paragraph 11 obliges them to tell consumers where to file complaints and where to report vulnerabilities, incidents and cyber threats. Paragraph 16 tasks them with monitoring how manufacturers applied the Article 13(8) criteria when setting the Support period.
Coordination runs through the administrative cooperation group (ADCO) established under Article 30(2) of Regulation (EU) 2019/1020, which publishes statistics on average support periods and guidance with indicative figures per product category. On top of that come joint activities under Article 59 and coordinated control actions (sweeps) under Article 60, which may expressly include buying and inspecting products under a cover identity.
When market surveillance starts to bite
Chapter V applies from 11 December 2027, like the rest of the CRA; only two parts come earlier, Article 14 with the reporting obligations from 11 September 2026 and Chapter IV on the notification of conformity assessment bodies from 11 June 2026.
Products placed on the market before 11 December 2027 fall under the Regulation’s requirements only if they undergo a substantial modification after that date. The reporting obligations in Article 14, by contrast, apply to them without qualification.
Practical questions
-
Yes, if you made the product available in that territory. Competence follows the market, not your place of establishment. Selling across several Member States therefore means several authorities, each acting independently of the others. The documentation has to be supplied in a language the requesting authority readily understands, so translation time belongs in your planning for the deadline it sets. The other side of that: the request must be reasoned, so it is not an open-ended licence to inspect everything you hold.
-
In practice, yes. Article 54(4) obliges the economic operator to extend corrective action to every affected product it has made available anywhere in the Union, not only those in the country of the authority that acted. Where that authority considers the non-compliance is not restricted to its own territory, Article 54(3) has it inform the Commission and the other Member States. If a provisional measure it then takes goes unopposed for three months, it is deemed justified, and the market surveillance authorities of all Member States must ensure that appropriate restrictive measures are taken (Article 54(8) and (9)). Answering a national procedure with a purely local response therefore tends to fall short.
-
Article 53 grants access, upon a reasoned request, to the data needed to assess design, development, production and vulnerability handling, including internal documentation. None of that amounts to a blanket entitlement to source code. Article 63 requires everyone involved to protect intellectual property rights, confidential business information and trade secrets, and names source code among them. The test remains what the specific conformity evaluation actually requires. It pays to settle in advance which artefacts you can hand over and at what depth, and where an on-site inspection is the lighter alternative.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.