A natural person, company, research institution, public authority, security researcher or another third party may flag possible non-compliance of a product with digital elements.
First choose the correct submission type
- The product may breach CRA requirements: continue with this page.
- You found a technical vulnerability: use coordinated vulnerability disclosure; do not send a sensitive exploit by ordinary email.
- A cyber incident is under way: use the SK-CERT incident route (Slovak).
- You are a manufacturer with an Article 14 duty: use the CRA reporting procedure, not a market-surveillance concern.
- You want a repair, refund or damages: this is a consumer or contractual remedy; a market-surveillance concern does not itself secure a private claim.
What to prepare
- product name, manufacturer, model, version and available identifiers;
- where and when it was bought, downloaded or made available;
- a description of the possible non-compliance and its impact;
- photographs of the CE marking, packaging, label and manufacturer or importer details;
- instructions, EU declaration of conformity, support information or seller communications;
- evidence and a clear account of how you found the problem.
Do not send passwords, tokens, unredacted personal data or a detailed exploit over an unencrypted channel.
How to deliver the concern
This website does not currently list a verified electronic form or dedicated CRA mailbox for these concerns. Confirm the appropriate delivery method on the contact page. Do not send sensitive attachments to general contacts.
What may happen next
The authority may register and initially assess the information before deciding whether there are grounds for further examination. A reporter cannot require a particular outcome. Any acknowledgement and follow-up depend on the supplied contact details, confidentiality and the ongoing assessment.