The question that sits under every other Cyber Resilience Act question is not how to comply. It is who checks. Article 64 sets fines of up to EUR 15 million or 2.5% of turnover, and the number gets quoted everywhere, but the Regulation does not give the Commission a single enforcement arm. Article 52(2) requires each member state to designate one or more market surveillance authorities, and those authorities, under the general market surveillance rules in Regulation (EU) 2019/1020, are the ones who ask for your technical file, test your product, order a recall, or impose the fine.
So "who enforces the CRA" has 27 answers, and the honest state of those answers on the day the first obligation applied is the subject of this article.
Where the answers are published
Designations are registered with the Commission and published in the Single Market Compliance Space, the same database that lists market surveillance authorities for every other piece of product legislation, from toys to pressure equipment. It is filterable by regulation. The Commission's own CRA page for member states links to it and nowhere else, so it is the record.
There are two registers, because the Regulation creates two roles:
- Market surveillance authority, Article 52: the enforcer. Checks products on the market, handles complaints, imposes penalties.
- Notifying authority, Article 36: the body that assesses and monitors the conformity assessment bodies (the notified bodies) that important and critical products will need. Not an enforcer, but the state's first institutional commitment to the Regulation.
We read both on 11 September 2026, the day Article 14 applied. Here is what they held.
The register, state by state
| Member state | Market surveillance authority (Article 52) | Notifying authority (Article 36) |
|---|---|---|
| Austria | not registered | not registered |
| Belgium | Belgian Institute for Postal services and Telecommunications | CCB – Centre for Cybersecurity Belgium |
| Bulgaria | not registered | not registered |
| Croatia | not registered | Information Systems Security Bureau |
| Cyprus | Office of the Commissioner of Communications - Digital Security Authority (DSA) | Digital Security Authority - National Cybersecurity Certification Authority |
| Czechia | not registered | not registered |
| Denmark | not registered | not registered |
| Estonia | not registered | Consumer Protection and Technical Regulatory Authority |
| Finland | Finnish Transport and Communications Agency (Traficom) | not registered |
| France | Agence Nationale des Fréquences | Agence nationale de la sécurité des systèmes d’information |
| Germany | Bundesamt für Sicherheit in der Informationstechnik (BSI) | Bundesamt für Sicherheit in der Informationstechnik - Referat S 14 – Befugniserteilung und Aufsicht über Konformitätsbewertungsstellen |
| Greece | not registered | not registered |
| Hungary | not registered | Supervisory Authority for Regulatory Affairs |
| Ireland | not registered | not registered |
| Italy | not registered | not registered |
| Latvia | Consumer Rights Protection Centre (Patērētāju tiesību aizsardzības centrs) | not registered |
| Lithuania | not registered | Ministry of National Defence of the Republic of Lithuania |
| Luxembourg | not registered | not registered |
| Malta | not registered | Malta Digital Innovation Authority |
| Netherlands | not registered | Ministry of Economic Affairs – Dutch Authority for Digital Infrastructure |
| Poland | not registered | Ministry of Digital Affairs - Cybersecurity Department |
| Portugal | not registered | not registered |
| Romania | not registered | not registered |
| Slovakia | National Security Authority | Slovak Office of Standards, Metrology and Testing |
| Slovenia | not registered | not registered |
| Spain | not registered | not registered |
| Sweden | not registered | SWEDAC - Swedish Board for Accreditation and Conformity Assessment |
Names are verbatim from the register, in the language and form each state chose. "Not registered" means the database returned no authority for that state under the CRA filter on the date above; it does not mean the state has no plan, only that it has not told the Commission.
What the table says
Seven of 27 have registered an enforcer. Belgium, Cyprus, Finland, France, Germany, Latvia and Slovakia. Twenty have not.
Thirteen have registered a notifying authority. Fourteen have not. The two lists overlap but are not the same: Estonia, Croatia, Hungary, Lithuania, Malta, the Netherlands, Poland and Sweden have named who will supervise conformity assessment bodies but not who will enforce; Finland and Latvia have done the reverse.
Twelve states have registered neither. Austria, Bulgaria, Czechia, Denmark, Greece, Ireland, Italy, Luxembourg, Portugal, Romania, Slovenia and Spain. A manufacturer with its main establishment in any of those has, as of the reporting duty starting, no registered authority for the Regulation it is now subject to.
The states that have moved chose different kinds of body. Germany gave it to its federal information security office, which also runs the national CSIRT and the notifying role. France split it: the frequencies agency for market surveillance, the national information security agency for notification. Belgium and Finland used their telecoms regulators. Latvia used its consumer protection centre. Cyprus and Slovakia used their national security or digital security authorities. There is no single model, and a company with products in several markets will deal with agencies of quite different cultures.
What this means if you are small
The fear in every community FAQ about the CRA is the enforcement one: if I make a mistake, will I get in trouble, and from whom. The register lets us say something concrete rather than reassuring.
Enforcement is national and, for most states, not yet staffed. Full application is 11 December 2027, and market surveillance of Annex I requirements cannot begin before the requirements apply. The reporting duty in Article 14 is in force now, but a state with no registered authority has nobody positioned to act on a missed report today. That is a description of the present, not a prediction: the Commission expects designations to fill in before December 2027, and the twenty gaps will close.
The register is where a penalty in one state becomes visible in the others. Article 64(6) requires an authority that imposes a fine to inform the market surveillance authorities of every other member state through the information system in Article 34 of Regulation (EU) 2019/1020. Once the register is full, that is the channel.
Size is a factor in the amount, by law. Article 64(5)(c) requires an authority setting a fine to give due regard to the size of the operator, "in particular with regard to microenterprises and small and medium-sized enterprises, including start-ups". That is in the enacting text, and it binds every authority in the table above and every one still to be added. We have written the tiers and the small-manufacturer provisions out in full.
Your CSIRT is not your enforcer. The Article 14 notification goes to the CSIRT designated as coordinator and to ENISA; the CSIRT is there to coordinate a response, not to police you. Market surveillance authorities are a different set of bodies, and in most states so far a different agency. The CSIRT for each state is here.
What to do with it
Nothing changes about the obligations. What changes is what you can write in your own file: which authority you would deal with, if your state has named one, and the date you checked if it has not. A scope determination and an incident procedure that name the authority, or record that none is registered yet, are more defensible than ones that leave the question open.
We will re-read the register and update the table. The date at the top of this article is the date the table was read, and the register itself is public and filterable, so you can check it against the source rather than take our reading.
Sources
- Regulation (EU) 2024/2847, Articles 36, 52, 64 and 71(2).
- Regulation (EU) 2019/1020 on market surveillance and compliance of products, Article 34.
- The Commission's Single Market Compliance Space, market surveillance authorities filtered to Regulation 2024/2847 (legislation id 9021) and notifying authorities filtered to the same (legislation id 167953), both read on 11 September 2026.
- The Commission's "Cyber Resilience Act, Member States" page, updated 31 July 2026, which links the two registers.
This is not legal advice. The register is public and filterable; if your state appears here as not registered and you know otherwise, the register is where the correction belongs, and we will pick it up on the next read.