Information status: Most CRA obligations and the related market-surveillance framework apply from 11 December 2027. This page helps organisations prepare. Final national responsibilities, procedural rules and specific submission channels will be updated after official confirmation.
Market surveillance is intended to ensure that products with digital elements made available on the European Union market meet CRA requirements. It covers hardware and software within the CRA’s scope and builds on the general market-surveillance framework in Regulation (EU) 2019/1020.
What do you need to do?
- I want to flag a product that may not comply. Report possible product non-compliance and prepare useful evidence.
- NBÚ has contacted our organisation or an inspection is under way. See what to do during an inspection and which records to prepare.
- We need to correct non-compliance. Choose a proportionate correction, restriction, withdrawal or recall.
- I need to understand a measure or possible penalty. Read the overview of measures, decisions and penalties.
- We disagree with an NBÚ decision or procedure. Distinguish an appeal, judicial review and a complaint.
- I want published plans, results or warnings. Check the register of plans, results and warnings.
- I want to check a cross-border case or public EU database. See EU cooperation, ICSMS and Safety Gate.
- I found a vulnerability or am dealing with a cyber incident. First choose the correct CRA reporting route. A market-surveillance concern may not be the right route.
What may be supervised
Surveillance may cover products with digital elements placed or made available on the Slovak market regardless of their country of origin. For a product from a manufacturer outside the EU, an EU-established importer has an important role.
Checks may cover substantive conformity with the essential cybersecurity requirements and formal obligations such as the CE marking, EU declaration of conformity, technical documentation, information for users, and details needed to identify the product and economic operator.
Why surveillance matters
Surveillance supports trust in the conformity system. The CE marking is the manufacturer’s declaration of compliance with applicable requirements; it is not a guarantee that a product will never contain a vulnerability. Manufacturers must address cybersecurity throughout the relevant part of a product’s lifecycle, and economic operators must cooperate on corrective action where non-compliance occurs.