This page explains what happens during an inspection. If you are already addressing identified non-compliance, continue to Correct product non-compliance.
Surveillance may be based on risk analysis, an inspection plan or information about possible non-compliance. Inclusion or absence from an annual plan does not preclude an off-plan inspection. See published plans, results and warnings.
If NBÚ contacts you
- Verify the name, unit, contact details, case reference and legal basis through the details in the official communication.
- Appoint a contact person and preserve relevant documentation and technical evidence.
- Confirm the scope of requested documents, products and versions and the response deadline.
- Respond within the stated period. If the request is unclear or objectively impossible, tell the contact in the official communication without delay; do not assume this extends the deadline.
This website does not currently provide a separate public contact for inspector verification. Use the identification and contact details in the specific official communication, and do not send sensitive technical material to general-purpose addresses.
What an inspection may cover
Depending on the legal basis and circumstances, the market-surveillance authority may request or examine:
- technical documentation, the EU declaration of conformity, the SBOM and other relevant records;
- identification of the product, manufacturer, importer and affected versions;
- product samples and expert testing;
- authorised access to the product, software, firmware, premises or marketplace needed to assess conformity;
- an explanation of findings, cooperation and compliance with a stated deadline.
The specific scope, powers, procedural safeguards and obligations are governed by applicable law and the official communication in the case concerned.
Your procedural rights
- During an on-site inspection, the inspector identifies themselves using an official or employee identity card.
- The authority may interfere with protected rights and interests only to the extent necessary for the purpose of surveillance and must choose proportionate means.
- The economic operator may comment throughout the market-surveillance procedure.
- Before a measure is imposed, the economic operator may comment on it unless urgent action is required because the public interest, health or safety is at risk.
- If the nature of the product allows it, the economic operator may take control samples itself in the inspector’s presence and retain part of each sample.
Inspection protocol and response period
The Office prepares and delivers an inspection protocol as a public instrument. It identifies the economic operator, inspector and subject of the inspection. If non-compliance or a breach is found, it also states the legal provision concerned, lists the supporting evidence, and sets out the proposed measure and its deadline.
The protocol gives the economic operator a reasonable period of at least ten working days to comment on the protocol and the proposed measure. Check the delivered protocol and the current text of the applicable law for the steps and deadline in the specific case.
Objection to a measure
An economic operator that disagrees with a measure may submit a reasoned written objection within five working days after the measure is delivered. The objection does not have suspensive effect, so the measure must be implemented within its stated scope and deadline unless the competent authority decides otherwise. The person who imposed the measure may amend or revoke it within ten working days after receiving the objection. If the objection is not granted, that person refers it to the Director of the Office within the same period; the Director decides within ten working days after referral. The Director’s decision is final.
When submitting an objection, check the instructions in the delivered measure and the current text of the applicable law, particularly the submission method, deadline and required particulars.
Further remedy information is available on Appeals and complaints.
What to prepare
- unambiguous product, model, version and batch identification;
- technical documentation, the cybersecurity risk assessment and testing evidence;
- the EU declaration of conformity, conformity-assessment evidence and information for users;
- records of vulnerabilities, updates, support, concerns and decisions;
- a map of the supply chain and markets where the product was made available.
If an inspection identifies non-compliance, follow the correction workflow. To understand a formal authority measure or penalty, see Measures, decisions and penalties.