Cyber Resilience Act

user1234 user1234 at 12.de
Thu Sep 17 06:52:02 UTC 2026


On Wednesday, 16 September 2026 at 09:15:42 UTC, Gregor Mückl 
wrote:
> Hi!
>
> I want to quickly bring up a topic that is certain to annoy 
> everybody. I'm sure of it.
> [...]

Thanks, I wanted to know how is this enforced. I'll save other 
people a few searches:

(Gemini verbatim begins)

---

Enforcement of the EU **Cyber Resilience Act (CRA)** is **not 
centralised** under a single European Union body. Instead, 
enforcement is managed decentrally by individual EU member states.

### 🏛️ Enforcement Structure
* **Market Surveillance Authorities (MSAs):** Each member state 
designates national market surveillance authorities to enforce 
compliance, inspect products with digital elements, and impose 
penalties or product recalls for non-compliance.
* **Notifying Authorities:** Member states designate specific 
bodies to assess and accredit conformity assessment 
organizations. For example, in France, the ANSSI acts as the 
notifying authority.
* **CSIRTs & ENISA:** Computer Security Incident Response Teams 
coordinate locally regarding incident reports, while the 
**European Union Agency for Cybersecurity (ENISA)** operates the 
centralized Single Reporting Platform (SRP) for vulnerability 
notifications, though ENISA itself holds no direct enforcement or 
penalty powers.

---

(Gemini verbatim ends)

So basically the RCA is made as a tool to taxes the tech-giants. 
It is a bit obscure how and if the sword will hit you. that 
depends on how each particular EU member decides to deal wi the 
RCA.

The risks are

> Non-compliance with the essential requirements or manufacturer 
> obligations can attract fines of up to €15 million or 2.5% of 
> total worldwide annual turnover, whichever is higher. Lower 
> ceilings apply to other infringements and to supplying 
> incorrect information.

So in a nutshell. Unless you are a tech giant you can ignore the 
RCA.


More information about the Digitalmars-d mailing list