Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Correct product non-compliance

Last updated:

This page explains the economic operator’s actions to correct non-compliance. If an inspection is only beginning or you are preparing records for NBÚ, see If NBÚ contacts or inspects you.

If you know or have reason to believe that a product with digital elements, or the manufacturer’s processes, does not conform to the CRA, act without delay. The aim is to correct the non-compliance and manage the cybersecurity risk proportionately across all affected versions and countries.

Choose a proportionate measure

The measure should match the nature and seriousness of the non-compliance or risk. If NBÚ has specified a scope, deadline or evidence needed to demonstrate correction, follow that official communication.

Correction workflow

  1. Stop making the affected version available if continuing would increase the risk.
  2. Identify affected products, versions, batches, markets and partners.
  3. Record the finding, root cause and risk assessment.
  4. Choose the measure, assign owners and deadlines, and test that the correction is effective.
  5. Coordinate the manufacturer, authorised representative, importers and distributors. Tell users clearly, in appropriate languages, if they need to act.
  6. Retain evidence of update delivery, stop-sale, withdrawal or recall and of the final outcome.

Voluntary correction does not replace a duty to inform a market-surveillance authority or a separate duty to report an actively exploited vulnerability or severe incident where the CRA conditions are met.

Responsibilities in the supply chain

The manufacturer is responsible for bringing the product and its processes into conformity. An importer or distributor that has reason to believe a product does not conform should not make it available until conformity has been restored and must cooperate on the necessary action. Where the product presents a significant cybersecurity risk, the relevant economic operators must immediately inform the market-surveillance authorities in Member States where they made it available, giving details of the non-compliance and measures taken.

A formal authority measure or decision is explained under Measures, decisions and penalties.

Legal basis: Regulation (EU) 2024/2847 and Regulation (EU) 2019/1020.