The Cyber Resilience Act is a regulation, applying directly across all 27 member states without national transposition. CRA enforcement is not centralised. Member states designate their own authorities, and a manufacturer placing products across the EU may deal with several of them.
Four distinct roles in CRA enforcement exist and they are frequently confused. Market surveillance authorities enforce compliance and impose penalties. Notifying authorities assess and designate conformity assessment bodies. CSIRTs receive incident reports as coordinators. ENISA operates the Single Reporting Platform and holds no enforcement power.
Member states were required to designate notifying authorities by 11 June 2026. Market surveillance authority designations followed the same track. The European Commission maintains the consolidated list on its CRA Member States page, which is the authoritative source and should be checked rather than relied upon second-hand.
Germany’s designation of the Federal Office for Information Security is the clearest example of the CRA enforcement model most member states have followed: a single national cybersecurity agency holding both notifying and market surveillance functions.
CRA Enforcement: Key Definitions
| Term | Definition |
|---|---|
| CRA | Cyber Resilience Act, Regulation (EU) 2024/2847 |
| Market surveillance authority | The national body that enforces CRA compliance, conducts inspections, and imposes penalties under Articles 52 to 60 |
| Notifying authority | The national body that assesses, designates, notifies, and monitors conformity assessment bodies under Chapter IV |
| Notified body | A conformity assessment body designated by a notifying authority and notified to the Commission |
| CSIRT | Computer Security Incident Response Team. The national body designated as coordinator for CRA incident reporting |
| ENISA | European Union Agency for Cybersecurity. Operates the Single Reporting Platform |
| SRP | Single Reporting Platform. The exclusive channel for CRA reporting from 11 September 2026 |
| ADCO | Administrative Cooperation Group. The forum coordinating market surveillance authorities across member states |
| Safeguard procedure | The mechanism under which a restriction imposed by one member state extends across the EU |
CRA Enforcement Four Roles
| Role | Function | Appointed by | Deals with manufacturers |
|---|---|---|---|
| Market surveillance authority | Enforcement, inspection, penalties, market restriction | Member state | Yes, on compliance |
| Notifying authority | Designation and monitoring of conformity assessment bodies | Member state | Indirectly, through notified bodies |
| Notified body | Third-party conformity assessment for Important Class II and Critical products | Notifying authority | Yes, on assessment |
| CSIRT | Receives incident notifications as coordinator | Member state | Yes, on reporting |
| ENISA | Operates the SRP, supports coordination | EU level | Through the platform only |
The distinction that matters most in practice is between the market surveillance authority and the CSIRT. The first enforces. The second receives reports.
In several member states CRA enforcement happens within the same organisation, in others they are not. Reporting an incident to your CSIRT does not discharge any obligation owed to your market surveillance authority, and a market surveillance investigation is not triggered automatically by an incident report. Here’s ECS CRA Vulnerability Report Template pack you will definitely find handy.
CRA Enforcement and Market Surveillance Authorities
Articles 52 to 60 govern market surveillance and enforcement. Each member state must designate one or more market surveillance authorities to ensure effective implementation.
What They Can Do
Market surveillance authorities operate under the general framework of Regulation (EU) 2019/1020 as adapted by the CRA. Their powers include:
| Power | Effect |
|---|---|
| Request documentation | Require technical documentation, SBOM, declaration of conformity, and supporting evidence |
| Inspect products | Examine products placed on the market for compliance with essential requirements |
| Require corrective action | Order the manufacturer to bring a non-compliant product into conformity within a set period |
| Restrict availability | Limit how and where a product may be made available on the market |
| Withdraw | Require removal of a product from the market |
| Recall | Require return of products already supplied to end users |
| Impose penalties | Administrative fines up to the CRA ceilings |
For a software product, withdrawal is a more serious commercial event than the fine.
CRA Enforcement Penalties
| Infringement | Maximum penalty |
|---|---|
| Non-compliance with Annex I essential requirements or Articles 13 and 14 manufacturer obligations | €15 million or 2.5% of total worldwide annual turnover, whichever is higher |
| Non-compliance with other CRA obligations | €10 million or 2% of total worldwide annual turnover |
| Supplying incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities | €5 million or 1% of total worldwide annual turnover |
Member states set the specific penalty rules within these ceilings. Variation between member states in how penalties are calculated and applied is expected.
Which CRA Enforcement Authority Has Jurisdiction?
Jurisdiction follows the market, not the manufacturer. A market surveillance authority has jurisdiction over products made available in its member state, regardless of where the manufacturer is established.
A UK or US manufacturer selling into Germany, France, and Spain is potentially subject to three market surveillance authorities. In practice, enforcement is coordinated through the ADCO mechanism and the safeguard procedure, so a restriction imposed by one member state can extend EU-wide rather than each authority acting independently.
CRA Enforcement: Notifying Authorities
Chapter IV of the CRA applied from 11 June 2026. It governs the designation of conformity assessment bodies.
Member states were required to designate, by 11 June 2026, notifying authorities responsible for setting up and carrying out the procedures for assessment, designation, and notification of conformity assessment bodies. Member states may use accreditation to assess the competence of those bodies.
Once a notifying authority notifies a conformity assessment body under Article 43, that body is a notified body and may conduct CRA conformity assessments.
The CRA requires notifying authorities to ensure conformity assessments are carried out proportionately, taking account of the size of undertakings, particularly microenterprises and SMEs, including in relation to fees. This is a live issue: notified body capacity is finite and demand will concentrate ahead of December 2027.
Why This Matters Before December 2027
Manufacturers of Important Class II and Critical products require notified body assessment. Those assessments cannot begin until notified bodies exist, and notified bodies could not be designated until notifying authorities were in place from June 2026.
The sequencing creates a queue. Manufacturers in these classes who wait until 2027 to engage a notified body will be competing for capacity with everyone else in the same position.
| Product class | Conformity assessment route | Notified body required |
|---|---|---|
| Default (approximately 90% of products) | Manufacturer self-assessment | No |
| Important Class I | Harmonised standards, or third-party assessment | Only if standards not applied |
| Important Class II | Third-party assessment | Yes |
| Critical | European cybersecurity certification | Yes |
CSIRTs and the Reporting Channel
Incident reporting under Article 14 has applied since 11 September 2026. Reports go simultaneously to the CSIRT designated as coordinator and to ENISA, through the Single Reporting Platform.
Determining Your Coordinating CSIRT
The coordinating CSIRT is that of the member state where the manufacturer has its main establishment. Where the manufacturer is established outside the EU, it is the member state of the authorised representative.
| Manufacturer situation | Coordinating CSIRT |
|---|---|
| Single EU establishment | CSIRT of that member state |
| Multiple EU establishments | CSIRT of the member state of main establishment |
| No EU establishment, authorised representative appointed | CSIRT of the representative’s member state |
| No EU establishment, no authorised representative | Determination unclear; appoint a representative |
The last row is a genuine problem for non-EU manufacturers selling directly into the EU without an authorised representative. Resolve it before an incident occurs rather than during one.
CRA Enforcement Reporting Clocks
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours from awareness | That the vulnerability or incident exists, and affected member states if known |
| Notification | 72 hours from awareness | Product affected, nature of the issue, corrective or mitigating measures available |
| Final report | 14 days after a corrective measure is available (vulnerability) or one month after the 72-hour notification (severe incident) | Full description, severity, impact, corrective measure deployed |
Clocks run in elapsed hours. A Friday evening disclosure does not wait for Monday.
ENISA’s Role
ENISA operates the Single Reporting Platform and supports coordination between national authorities. It does not enforce the CRA, does not impose penalties, and does not conduct market surveillance.
This is a meaningful distinction. A manufacturer that reports to ENISA has met a reporting obligation. It has not engaged with an enforcement body, and the report does not by itself trigger a market surveillance investigation.
CRA Authorities by Member State
The table below lists the national body designated or reported as holding CRA enforcement functions in each member state. Where a country has split the roles, the same organisation may not hold all three.
Verify against the European Commission’s CRA Member States page before relying on any entry. Designations continue to be updated and several member states have not published complete allocations.
Confirmed and widely reported designations for CRA enforcement in EU
| Country | Authority | Full name | Role |
|---|---|---|---|
| Germany | BSI | Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security) | Notifying authority and market surveillance authority. Notifies conformity assessment bodies from June 2026. Powers to inspect and sanction |
| Netherlands | NCSC-NL | Nationaal Cyber Security Centrum | Coordinating CSIRT. CRA manufacturer reporting runs through its national portal from 11 September 2026 |
| France | ANSSI | Agence nationale de la sécurité des systèmes d’information | National cybersecurity agency, reported CRA authority |
| Spain | INCIBE | Instituto Nacional de Ciberseguridad | National cybersecurity institute, reported CRA authority |
| Italy | ACN | Agenzia per la Cybersicurezza Nazionale | National cybersecurity agency, reported CRA authority |
| Poland | NASK | Naukowa i Akademicka Sieć Komputerowa | National research and academic computer network, reported CRA authority |
| Sweden | MSB | Myndigheten för samhällsskydd och beredskap (Civil Contingencies Agency) | Reported CRA authority |
| Ireland | NCSC Ireland | National Cyber Security Centre | Reported CRA authority |
| Belgium | CCB | Centre for Cybersecurity Belgium / Centre pour la Cybersécurité Belgique | Reported CRA authority |
| Austria | NCS | Nationales Cyber Sicherheitszentrum | Reported CRA authority |
Remaining member states
For the following member states, the national cybersecurity agency is the most likely designee based on the pattern established elsewhere, but designations should be confirmed directly.
Several of these countries have historically split product market surveillance from cybersecurity functions, which makes assumption unsafe.
| Country | National cybersecurity agency | Confirm designation |
|---|---|---|
| Bulgaria | Cybersecurity Directorate, Ministry of e-Government | Required |
| Croatia | SOA / CERT.hr | Required |
| Cyprus | Digital Security Authority (DSA) | Required |
| Czechia | NÚKIB (National Cyber and Information Security Agency) | Required |
| Denmark | Center for Cybersikkerhed (CFCS) | Required |
| Estonia | RIA (Information System Authority) | Required |
| Finland | Traficom / NCSC-FI | Required |
| Greece | National Cybersecurity Authority | Required |
| Hungary | SZTFH / NKI | Required |
| Latvia | CERT.LV | Required |
| Lithuania | NKSC (National Cyber Security Centre) | Required |
| Luxembourg | ILR / CIRCL | Required |
| Malta | Malta Information Technology Agency / CSIRTMalta | Required |
| Portugal | CNCS (Centro Nacional de Cibersegurança) | Required |
| Romania | DNSC (Directoratul Național de Securitate Cibernetică) | Required |
| Slovakia | NBÚ (National Security Authority) | Required |
| Slovenia | URSIV / SI-CERT | Required |
Why Assumption Is Unsafe When It Comes to CRA Enforcement
Three things vary between member states and none of them can be inferred from the national cybersecurity agency’s identity.
Role separation. A member state may designate its cybersecurity agency as notifying authority, its consumer product safety regulator as market surveillance authority, and its CERT as coordinating CSIRT. Germany’s consolidation of notifying and market surveillance functions in the BSI is a pattern, not a rule.
Sectoral allocation. Where a member state designates multiple market surveillance authorities, product category determines which one has jurisdiction over your product. A connected medical adjacent device and a password manager may answer to different authorities in the same country.
Reporting channel. The Netherlands routes CRA manufacturer reporting through NCSC-NL’s national portal alongside the Single Reporting Platform. Other member states may operate differently. The SRP is the mandatory channel; national portals sit alongside it rather than replacing it.
National CRA Guides
Several member states have published national CRA guides explaining how the regulation is implemented locally: who does what, where manufacturers report vulnerabilities and incidents, how conformity assessment is organised, and which authorities hold oversight.
These guides are the most reliable source for country-level detail. Where a guide exists for a market you sell into, read it. Where one does not, contact the national cybersecurity agency directly rather than assuming the German or Dutch model applies.
- Germany’s BSI has published its own CRA guidance and technical material for manufacturers alongside the EU-level framework.
- The Dutch NCSC has published operational detail on its reporting portal.
Both illustrate that while the CRA text is uniform across the EU, the operational experience of compliance differs by member state.
Member State Designations
The European Commission maintains the consolidated list of designated notifying authorities and market surveillance authorities on its CRA Member States page. That page is the authoritative source.
The dominant model has been to assign both functions to the existing national cybersecurity agency.
Germany appointed the Federal Office for Information Security, the BSI. From June 2026 the BSI notifies third parties authorised to act as conformity assessment bodies. It also holds the power to inspect products for cybersecurity compliance and impose sanctions.
This concentration of notifying and market surveillance functions in a single technically capable agency is the pattern most member states have followed, though the specific bodies differ and some member states have designated separate authorities for each function.
Three practical points follow for manufacturers.
First, verify designations against the Commission’s list rather than assuming the national cybersecurity agency holds the role. Some member states have split the functions.
Second, where a member state has designated multiple market surveillance authorities, sectoral allocation may apply. Confirm which authority covers your product category.
Third, designations continue to be updated. A list checked in early 2026 may be incomplete.
Coordination Between Authorities
Two mechanisms prevent 27 authorities from reaching 27 different conclusions about the same product.
The CRA ADCO. The Administrative Cooperation Group for market surveillance authorities under the CRA. It is a restricted forum where national authorities coordinate enforcement approach, share findings, and work toward consistent interpretation.
The Working Group of Notifying Authorities. A parallel restricted forum responsible for coordinating the assessment, designation, notification, and monitoring of conformity assessment bodies.
The CRA Expert Group. A broader forum contributing to guidance development and awareness-raising at EU level.
For manufacturers, the operational implication is that engagement with one market surveillance authority is not contained to that member state. Findings are shared. A restriction imposed in one member state can extend EU-wide through the safeguard procedure under Regulation (EU) 2019/1020.
Which CRA enforcement Authority Do You Deal With, and When?
| Situation | Authority |
|---|---|
| Actively exploited vulnerability discovered | Coordinating CSIRT and ENISA, via the SRP |
| Severe incident affecting product security | Coordinating CSIRT and ENISA, via the SRP |
| Request for technical documentation | Market surveillance authority of the member state making the request |
| Product inspection | Market surveillance authority of the member state where the product is available |
| Conformity assessment for Class II or Critical product | Notified body, designated by a notifying authority |
| Dispute over conformity assessment | Notifying authority that designated the notified body |
| Penalty imposed | Market surveillance authority, challengeable through national procedures |
| Market restriction or withdrawal order | Market surveillance authority, extendable EU-wide via safeguard procedure |
What Non-EU Manufacturers Should Do
CRA applies to any manufacturer placing a product with digital elements on the EU market, regardless of establishment. UK, US, Swiss, and other non-EU manufacturers are in scope.
Appoint an authorised representative. Article 17 permits appointment by written mandate. For manufacturers without an EU establishment, this is the cleanest route to a determinable coordinating CSIRT and a functioning relationship with EU authorities. Without one, the coordinating CSIRT determination is unresolved and the importer carries verification obligations under Article 19 that it may be unable to discharge.
Identify your main establishment for reporting purposes. If you have an EU subsidiary, determine which one constitutes your main establishment. If you have none, your authorised representative’s location governs.
Verify market surveillance authorities in each market. Where you sell into several member states, identify the authority in each and understand which has jurisdiction over your product category.
Register on the Single Reporting Platform. Access runs through EU Login. Create the accounts before you need them.
Engage notified bodies early if you produce Class II or Critical products. Capacity will be constrained ahead of December 2027 and non-EU manufacturers will not receive priority.
FAQ
Who enforces the Cyber Resilience Act?
National market surveillance authorities designated by each member state. There is no central EU enforcement body for the CRA. ENISA operates the reporting platform but holds no enforcement power.
What is the difference between a market surveillance authority and a notifying authority?
A market surveillance authority enforces CRA compliance: it inspects products, requests documentation, orders corrective action, and imposes penalties. A notifying authority assesses, designates, notifies, and monitors conformity assessment bodies. Some member states have designated the same organisation for both roles and others have separated them.
Which market surveillance authority has jurisdiction over our products?
Jurisdiction follows the market. Any market surveillance authority in a member state where your products are made available may act. Where you sell across the EU, several authorities have jurisdiction, coordinated through the ADCO and the safeguard procedure.
Who do we report incidents to under the CRA?
To the CSIRT designated as coordinator, being that of the member state of your main establishment or, for non-EU manufacturers, that of your authorised representative. Reports are submitted through ENISA’s Single Reporting Platform, which routes to the CSIRT and makes the notification available to ENISA simultaneously.
Does ENISA enforce the CRA?
No. ENISA operates the Single Reporting Platform and supports coordination between national authorities. CRA enforcement sits with national market surveillance authorities.
When were CRA authorities designated?
Member states were required to designate notifying authorities by 11 June 2026, when Chapter IV began to apply. Market surveillance authority designations followed the same track. The Commission maintains the consolidated list on its CRA Member States page.
Which CRA enforcement authority did Germany designate?
The Federal Office for Information Security, the BSI. From June 2026 the BSI notifies conformity assessment bodies and holds powers to inspect products for cybersecurity compliance and impose sanctions.
What are the maximum CRA penalties?
€15 million or 2.5% of worldwide annual turnover for breach of the Annex I essential requirements or Articles 13 and 14 manufacturer obligations. €10 million or 2% for other obligations. €5 million or 1% for supplying incorrect or misleading information to authorities. Member states set the specific penalty rules within these ceilings.
Can one member state’s decision affect us across the EU?
Yes. Where a market surveillance authority restricts or withdraws a product, the safeguard procedure under Regulation (EU) 2019/1020 allows that decision to extend across the EU. CRA enforcemenent action in one member state is not contained to that market.
Do non-EU manufacturers need an EU authorised representative?
The CRA permits rather than universally mandates appointment. In practice, a manufacturer with no EU establishment should appoint one: without it, the coordinating CSIRT determination for reporting is unresolved, and the importer’s verification obligations under Article 19 may be impossible to satisfy.
How do we find our coordinating CSIRT?
By your main establishment, or your authorised representative’s establishment if you are outside the EU. The CSIRT is selected during SRP registration. Verify the designation against national sources before an incident rather than during one.
Are CRA authorities the same as NIS2 authorities?
Not necessarily. NIS2 competent authorities supervise organisations in critical sectors. CRA market surveillance authorities supervise products. Some member states have designated the same body for both, but CRA enforcement roles are distinct and an organisation in scope of both frameworks may deal with the same authority in two different capacities.
Disclaimer
This guide reflects Regulation (EU) 2024/2847 and the status of member state designations as at September 2026. Designations continue to be updated and the European Commission’s CRA Member States page is the authoritative source for current notifying and market surveillance authorities. This guide is published by European Compliance Suite for general informational purposes and does not constitute legal advice.
