Cyber Resilience Act
Recall
Legal definition Art. 3(49) CRA
“recall as defined in Article 3, point (22), of Regulation (EU) 2019/1020”
A recall brings back products that have already reached the end user, and it is the sharpest corrective measure the Cyber Resilience Act (CRA) provides for. The term is not defined in the CRA itself but in the market surveillance Regulation (EU) 2019/1020, to which it refers: any measure aimed at achieving the return of a product that has already been made available to the end user.
What matters in that wording is the aim, not the means. “Any measure” covers swapping a device out as much as asking users to take it out of service and send it back. And it presupposes that the product has already reached the end user. Before that there is nothing to recall.
Recall and withdrawal
The CRA almost always names the two measures in the same breath, yet they work in opposite directions:
- Recall concerns products already with end users and aims at getting them back.
- Withdrawal concerns products still in the supply chain and prevents them from being made available at all.
Only together do they cover the whole distribution chain. Withdraw alone and the shipped units stay in the field; recall alone and the warehouse keeps shipping.
When the manufacturer must recall on its own initiative
Article 13(21) binds manufacturers from the placing on the market and throughout the Support period: anyone who knows or has reason to believe that their product or their processes fail the essential cybersecurity requirements in Annex I must immediately take the necessary corrective measures and withdraw or recall the product as appropriate.
The words as appropriate imply a ranking. Bringing the product back into conformity comes first, typically through a security update. The recall sits at the far end of the scale. It needs no order from an authority: the duty arises with knowledge, not with a decision served on you.
Importers and distributors are bound too
Article 19(5) catches importers for products they have placed on the market; Article 20(4) catches distributors for products they have made available. The wording differs on one point: importers take the corrective measures, distributors make sure that they are taken, in practice through the manufacturer.
Both must inform the manufacturer without delay of any vulnerability that comes to their attention. And anyone who places a product on the market under their own name or trade mark, or makes a Substantial modification to it, counts as the manufacturer under Article 21 in any case. Every duty in Articles 13 and 14 comes with that status.
The recall ordered by an authority
Where a Market surveillance authority has sufficient reason to consider that a product presents a significant cybersecurity risk, it evaluates the product under Article 54, vulnerability handling included. If it finds non-compliance, it requires the economic operator to bring the product into conformity, withdraw it, or recall it within a period it prescribes and that is commensurate with the risk.
Two points are routinely missed. First, the measure does not stop at the border of the ordering Member State: under Article 54(4) the operator must extend it to all affected products it has made available anywhere in the Union. Second, the authority acts itself if the operator lets the deadline pass. Under Article 54(5) it must then take all appropriate provisional measures, up to and including a recall.
Two further layers sit above that. If a Member State objects within three months of receiving the notification of that provisional measure, or the Commission considers it incompatible with Union law, the Union safeguard procedure in Article 55 applies and the Commission decides within nine months of receiving that same notification. Under Articles 56 and 57 it can also adopt implementing acts requiring withdrawal or recall across the Union. That power is confined to exceptional circumstances that justify immediate intervention to preserve the internal market and in which market surveillance authorities have taken no effective measures.
Recall despite conformity, recall for formal defects
Two constellations show how far the instrument reaches. Article 57 covers products that do comply with the CRA but present, alongside a significant cybersecurity risk, a risk to the health or safety of persons, to compliance with obligations under Union or national law intended to protect fundamental rights, to services offered using an electronic information system by essential entities as referred to in Article 3(1) of the NIS2 Directive, or to other aspects of public interest protection. A recall is among the possible measures there as well. CE marking is no shield.
Article 58 covers the opposite case: purely formal defects. CE marking missing or affixed in breach of the rules, an EU declaration of conformity not drawn up or not drawn up correctly, Technical documentation missing or incomplete. Where the defect persists, the Member State takes all appropriate measures: it may restrict or prohibit the product from being made available on the market, or ensure that it is recalled or withdrawn. Here too, not a single vulnerability has to be demonstrated.
What the CRA leaves open
The definition comes from a regulation written mainly with physical goods in mind. “Return” is not a meaningful act for a downloaded program or for firmware that was never shipped as an object. The CRA does not say what takes its place. Deactivation, revoking licences, forced uninstallation are all conceivable, none of them regulated.
Nor does the CRA prescribe a procedure, a register or a form for recalls. What it does regulate is procedural rights: Article 54(1) declares Article 18 of Regulation (EU) 2019/1020 applicable to the corrective actions. And it prices inaction. Infringements of Article 13 carry fines of up to EUR 15 000 000 or, for undertakings, up to 2.5 % of total worldwide annual turnover for the preceding financial year, infringements of Articles 18 to 23 up to EUR 10 000 000 or 2 %, whichever is higher.
Practical questions
-
The CRA is silent on this. It allocates duties, not costs. Articles 13, 19 and 20 say who must act, not who foots the bill. What governs is the contract between manufacturer, Importer and Distributor, plus national warranty and liability law. If you distribute someone else’s products, settle cost allocation in advance: a deadline set by an authority keeps running whether or not the parties agree on the invoice.
-
For manufacturers the CRA provides no separate notification of the recall itself. The Article 14 reporting duties attach to actively exploited vulnerabilities and severe incidents, not to corrective measures. Importers and distributors, by contrast, must inform the market surveillance authorities of the Member States where they made the product available as soon as it presents a significant cybersecurity risk. That notification also has to set out the corrective measures taken.
-
Often, but not automatically. What counts is not whether a patch was published but whether the non-conformity is gone afterwards. On devices with no update channel or no network connection, part of the installed base stays as it was. Where the root cause sits in hardware or in the manufacturer’s processes, an update does not help at all. Track what share of shipped devices actually takes an update; that figure is your strongest argument in a conversation with an authority.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.