The question that sits under every other Cyber Resilience Act question is not how to comply. It is who checks. Article 64 sets fines of up to EUR 15 million or 2.5% of turnover, and the number gets quoted everywhere, but the Regulation does not give the Commission a single enforcement arm. Article 52(2) requires each member state to designate one or more market surveillance authorities, and those authorities, under the general market surveillance rules in Regulation (EU) 2019/1020, are the ones who ask for your technical file, test your product, order a recall, or impose the fine.

So "who enforces the CRA" has 27 answers, and the honest state of those answers on the day the first obligation applied is the subject of this article.

Where the answers are published

Designations are registered with the Commission and published in the Single Market Compliance Space, the same database that lists market surveillance authorities for every other piece of product legislation, from toys to pressure equipment. It is filterable by regulation. The Commission's own CRA page for member states links to it and nowhere else, so it is the record.

There are two registers, because the Regulation creates two roles:

  • Market surveillance authority, Article 52: the enforcer. Checks products on the market, handles complaints, imposes penalties.
  • Notifying authority, Article 36: the body that assesses and monitors the conformity assessment bodies (the notified bodies) that important and critical products will need. Not an enforcer, but the state's first institutional commitment to the Regulation.

We read both on 11 September 2026, the day Article 14 applied. Here is what they held.

The register, state by state

Member state Market surveillance authority (Article 52) Notifying authority (Article 36)
Austria not registered not registered
Belgium Belgian Institute for Postal services and Telecommunications CCB – Centre for Cybersecurity Belgium
Bulgaria not registered not registered
Croatia not registered Information Systems Security Bureau
Cyprus Office of the Commissioner of Communications - Digital Security Authority (DSA) Digital Security Authority - National Cybersecurity Certification Authority
Czechia not registered not registered
Denmark not registered not registered
Estonia not registered Consumer Protection and Technical Regulatory Authority
Finland Finnish Transport and Communications Agency (Traficom) not registered
France Agence Nationale des Fréquences Agence nationale de la sécurité des systèmes d’information
Germany Bundesamt für Sicherheit in der Informationstechnik (BSI) Bundesamt für Sicherheit in der Informationstechnik - Referat S 14 – Befugniserteilung und Aufsicht über Konformitätsbewertungsstellen
Greece not registered not registered
Hungary not registered Supervisory Authority for Regulatory Affairs
Ireland not registered not registered
Italy not registered not registered
Latvia Consumer Rights Protection Centre (Patērētāju tiesību aizsardzības centrs) not registered
Lithuania not registered Ministry of National Defence of the Republic of Lithuania
Luxembourg not registered not registered
Malta not registered Malta Digital Innovation Authority
Netherlands not registered Ministry of Economic Affairs – Dutch Authority for Digital Infrastructure
Poland not registered Ministry of Digital Affairs - Cybersecurity Department
Portugal not registered not registered
Romania not registered not registered
Slovakia National Security Authority Slovak Office of Standards, Metrology and Testing
Slovenia not registered not registered
Spain not registered not registered
Sweden not registered SWEDAC - Swedish Board for Accreditation and Conformity Assessment

Names are verbatim from the register, in the language and form each state chose. "Not registered" means the database returned no authority for that state under the CRA filter on the date above; it does not mean the state has no plan, only that it has not told the Commission.

What the table says

Seven of 27 have registered an enforcer. Belgium, Cyprus, Finland, France, Germany, Latvia and Slovakia. Twenty have not.

Thirteen have registered a notifying authority. Fourteen have not. The two lists overlap but are not the same: Estonia, Croatia, Hungary, Lithuania, Malta, the Netherlands, Poland and Sweden have named who will supervise conformity assessment bodies but not who will enforce; Finland and Latvia have done the reverse.

Twelve states have registered neither. Austria, Bulgaria, Czechia, Denmark, Greece, Ireland, Italy, Luxembourg, Portugal, Romania, Slovenia and Spain. A manufacturer with its main establishment in any of those has, as of the reporting duty starting, no registered authority for the Regulation it is now subject to.

The states that have moved chose different kinds of body. Germany gave it to its federal information security office, which also runs the national CSIRT and the notifying role. France split it: the frequencies agency for market surveillance, the national information security agency for notification. Belgium and Finland used their telecoms regulators. Latvia used its consumer protection centre. Cyprus and Slovakia used their national security or digital security authorities. There is no single model, and a company with products in several markets will deal with agencies of quite different cultures.

What this means if you are small

The fear in every community FAQ about the CRA is the enforcement one: if I make a mistake, will I get in trouble, and from whom. The register lets us say something concrete rather than reassuring.

Enforcement is national and, for most states, not yet staffed. Full application is 11 December 2027, and market surveillance of Annex I requirements cannot begin before the requirements apply. The reporting duty in Article 14 is in force now, but a state with no registered authority has nobody positioned to act on a missed report today. That is a description of the present, not a prediction: the Commission expects designations to fill in before December 2027, and the twenty gaps will close.

The register is where a penalty in one state becomes visible in the others. Article 64(6) requires an authority that imposes a fine to inform the market surveillance authorities of every other member state through the information system in Article 34 of Regulation (EU) 2019/1020. Once the register is full, that is the channel.

Size is a factor in the amount, by law. Article 64(5)(c) requires an authority setting a fine to give due regard to the size of the operator, "in particular with regard to microenterprises and small and medium-sized enterprises, including start-ups". That is in the enacting text, and it binds every authority in the table above and every one still to be added. We have written the tiers and the small-manufacturer provisions out in full.

Your CSIRT is not your enforcer. The Article 14 notification goes to the CSIRT designated as coordinator and to ENISA; the CSIRT is there to coordinate a response, not to police you. Market surveillance authorities are a different set of bodies, and in most states so far a different agency. The CSIRT for each state is here.

What to do with it

Nothing changes about the obligations. What changes is what you can write in your own file: which authority you would deal with, if your state has named one, and the date you checked if it has not. A scope determination and an incident procedure that name the authority, or record that none is registered yet, are more defensible than ones that leave the question open.

We will re-read the register and update the table. The date at the top of this article is the date the table was read, and the register itself is public and filterable, so you can check it against the source rather than take our reading.

Sources

  • Regulation (EU) 2024/2847, Articles 36, 52, 64 and 71(2).
  • Regulation (EU) 2019/1020 on market surveillance and compliance of products, Article 34.
  • The Commission's Single Market Compliance Space, market surveillance authorities filtered to Regulation 2024/2847 (legislation id 9021) and notifying authorities filtered to the same (legislation id 167953), both read on 11 September 2026.
  • The Commission's "Cyber Resilience Act, Member States" page, updated 31 July 2026, which links the two registers.

This is not legal advice. The register is public and filterable; if your state appears here as not registered and you know otherwise, the register is where the correction belongs, and we will pick it up on the next read.