Market surveillance
Authorities’ powers
Market surveillance authorities exercise the powers set out in Regulation (EU) 2019/1020, as amended by the CRA. In particular they may:
- require the technical documentation and the EU declaration of conformity;
- request any information necessary to establish conformity;
- purchase products on the market, including under a concealed identity, and subject them to testing;
- carry out inspections;
- in justified cases, request access to elements of the source code in order to assess conformity with the essential requirements, subject to confidentiality;
- order corrective measures, restrict or prohibit making available, order withdrawal or recall.
The “significant risk” procedure
Where an authority has sufficient reason to consider that a product presents a significant cybersecurity risk, it carries out an evaluation. If non-compliance is established, it orders the operator to take appropriate corrective measures within a reasonable period.
If the operator does not act, the authority restricts or prohibits making the product available, orders its withdrawal or recall, and informs the Commission and the other Member States. A phase then opens in which other States may object; failing that, the measure is deemed justified and extended.
A Union safeguard procedure allows the Commission to intervene where Member States disagree or where the risk is Union-wide.
Formal non-compliance
Distinct from risk: it concerns documentary failings. It covers in particular:
- a missing CE marking, or one affixed in breach of the rules;
- the absence of the notified body identification number where required;
- an EU declaration of conformity that is missing or does not comply with Annex V;
- technical documentation unavailable, incomplete or not retained;
- the absence of the manufacturer’s details or of the contact point for reporting;
- the absence of the Annex II information to the user.
It leads to an order to regularise and, if it persists, to the same measures as substantive non-compliance.
Coordinated activities
The Commission and the administrative cooperation group (ADCO) may organise coordinated sweeps on a product category or a particular requirement, simultaneously in several Member States.
These campaigns are announced and their results published. They are the most likely form of inspection for widely distributed products.
Response card: you receive a request from an authority
To print and keep with the crisis procedures.
- Acknowledge receipt immediately, confirming the single point of contact on your side — named in advance, with a deputy.
- Qualify the request: which authority, which Member State, which product, which version, which legal basis, what deadline.
- Freeze the evidence: lock the versions of the technical documentation, SBOM and logs corresponding to the version at issue. Change nothing retroactively.
- Assemble the response: the technical documentation as it stood when the product was placed on the market, the declaration, and the items requested — without adding backdated documents, which would amount to supplying misleading information.
- Have Legal approve before anything is sent.
- Respond within the deadline, formally requesting an extension if the deadline is untenable — a reasoned request beats silence.
- Log every exchange in the register, with timestamps.
- Inform the committee and, if the matter could be material, executive management.
What a request really tests
A request from an authority tests your archiving, not your security. The question is not “is your product secure?” but “can you produce, within days, the exact file for a version shipped four years ago?”. The answer is prepared years in advance: see Evidence retention.