Cyber Resilience Act
Withdrawal
Legal definition Art. 3(50) CRA
“withdrawal as defined in Article 3, point (23), of Regulation (EU) 2019/1020”
Withdrawal stops the supply line. It catches the units of a product still sitting in the supply chain and keeps them from reaching anyone at all. The Cyber Resilience Act (CRA) does not define the term itself; it refers to market surveillance Regulation (EU) 2019/1020: any measure aimed at preventing a product in the supply chain from being made available on the market.
The definition describes an aim, not a procedure. The wording is indifferent to the means, whether you halt shipments, block stock, deactivate an article number or remove a package from a registry. All that counts is that no further supply takes place.
Two words set the reach
The definition rests on “supply chain” and “made available”. Only one of them is a defined term, namely making available on the market, in Article 3, point (22). Neither the CRA nor Regulation (EU) 2019/1020 defines the supply chain; its outer edge follows instead from the counterpart measure, the recall.
The supply chain covers everything that has not yet reached the end user: your own finished-goods warehouse, stock held by the importer, the shelf at the Distributor, whom Article 3, point (17) expressly defines as a person in the supply chain. What is already with the end user is beyond the reach of a withdrawal; that is where the Recall begins.
Making available on the market means, under Article 3, point (22), supply for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. Free does not mean exempt. An open download, firmware on a support page and an image in a registry all count as making available, and a withdrawal catches every one of them.
For software it is the sharper instrument
A recall runs into the void with software: there is no return where no object was ever shipped. Withdrawal, by contrast, has a clear point of attack in the distribution route. Pull the artefact from the package registry, retract the version in the app store, take down the download page, stop shipping to OEM partners. That can be executed cleanly and evidenced afterwards.
The difficulty is completeness. Closing your own download area leaves the mirrors, the entries in third-party registries, the copies compiled into other vendors’ products and the onward supply through system integrators untouched. A reliable inventory of every distribution route is therefore not a documentation nicety but the precondition for being able to carry out a withdrawal at all.
Who triggers it
- The manufacturer. Article 13(21) requires immediate corrective measures, including withdrawal or recall as appropriate, from the placing on the market and throughout the support period where the manufacturer knows or has reason to believe that the product or its processes fail the Annex I requirements. No decision from an authority is needed.
- Importers and distributors. Under Article 19(5) the importer takes the necessary corrective measures itself, for products it has placed on the market. Under Article 20(4) the distributor makes sure they are taken, for products it has made available. In both cases the corrective measures include withdrawal or recall as appropriate.
- The market surveillance authority. Article 54 starts from a product presenting a significant cybersecurity risk: where the evaluation finds non-compliance, under paragraph 1 the authority requires the economic operator to restore conformity, withdraw or recall within a period it prescribes, commensurate with the nature of the cybersecurity risk. If the period passes, it takes provisional measures itself under paragraph 5.
- The Commission. Article 56(5) (non-compliant products) and Article 57(9) (compliant products that nonetheless carry a significant risk) allow implementing acts on corrective or restrictive measures at Union level, including a requirement to withdraw or recall within a period commensurate with the risk. That route opens only where the market surveillance authorities have not taken effective measures, and only for as long as the exceptional circumstances last (Article 56(3) and (7), Article 57(7) and (11)).
One feature belongs to withdrawal alone: in the cross-border enforcement of Articles 54 and 55 it is the only measure the CRA names explicitly. Under Article 54(9) the market surveillance authorities of all Member States must ensure restrictive measures without delay, such as withdrawing the product from their market. And where the Commission finds a national measure justified in the Union safeguard procedure, Article 55(2) requires every Member State to ensure the non-compliant product is withdrawn from its market. Even without that chain your own duty already crosses the border: Article 54(4) requires the corrective action for all affected products the operator has made available anywhere in the Union.
What a withdrawal does not end
Withdrawal touches distribution, not the installed base. For everything already placed on the market the duties keep running:
- Vulnerability handling under Annex I, Part II applies across the Support period, which runs at least five years unless the expected product lifetime is shorter (Article 13(8)).
- Every security update made available during the support period must remain available, once issued, for at least ten years or for the remainder of the support period, whichever is longer (Article 13(9)).
- Technical documentation and the EU declaration of conformity must be kept at the disposal of the market surveillance authorities for at least ten years after the placing on the market, or for the support period, whichever is longer (Article 13(13)).
- The Article 14 reporting duties attach to actively exploited vulnerabilities and severe incidents, not to whether the product is still being sold.
A withdrawal is therefore not an exit from the Regulation. It closes the inflow, nothing more.
What the CRA leaves open
For the withdrawal itself the CRA prescribes no procedure, no register and no notification to an authority. Nor does it say when a withdrawal counts as complete. With distributed routes to market that is precisely the hard question, and the economic operator has to answer it.
What is regulated are the counterweights. Article 4(1) obliges Member States not to impede, for the matters covered by the Regulation, the making available of compliant products; every withdrawal is an exception to that and needs a basis. Article 54(1) declares Article 18 of Regulation (EU) 2019/1020 applicable to the corrective actions, and Article 54(8) makes clear that those procedural rights survive even where a provisional national measure is deemed justified after three months for want of objections.
Practical questions
-
The CRA does not require it for the withdrawal itself. The measure is aimed at the supply chain, not at the people who already have the product. Where the non-conformity also affects units already delivered, a recall is the fitting measure anyway, and a recall lives on reaching users. The CRA does impose express duties to inform users elsewhere: Article 14(8) requires the manufacturer to inform the users concerned about an actively exploited vulnerability or a severe incident and about the measures they can take, and Article 13(23) requires notice to the users, to the extent possible, where a manufacturer ceases operations and can therefore no longer comply. So where the reason for your withdrawal also triggers a report under Article 14, there is no way around informing users.
-
The CRA provides for no formal re-authorisation. If you withdrew on your own initiative under Article 13(21), you may make the product available again once the non-conformity is gone. The burden of showing that is yours, and the technical documentation has to be continuously updated where appropriate under Article 31(2) anyway, at least during the support period. If the withdrawal followed a market surveillance measure under Article 54, there is no way around the authority: its measure is tied to the non-conformity and does not lapse because you shipped a patch. A pure security update that only lowers the cybersecurity risk and leaves the intended purpose untouched is not a Substantial modification under recital 39, so no fresh conformity assessment is triggered.
-
The CRA gives you no power of direction over someone else’s stock. It does place a duty on the distributor: under Article 20(4) it must make sure the necessary corrective measures are taken once it knows of the non-conformity, and it is your notice that creates that knowledge. Breaches carry fines of up to EUR 10 000 000 or, for undertakings, up to 2 % of total worldwide annual turnover for the preceding financial year under Article 64(3), whichever is higher. So record whom you informed, when and with what content, and involve the Market surveillance authority if the situation does not move.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.