Cyber Resilience Act
user1234
user1234 at 12.de
Thu Sep 17 06:52:02 UTC 2026
On Wednesday, 16 September 2026 at 09:15:42 UTC, Gregor Mückl
wrote:
> Hi!
>
> I want to quickly bring up a topic that is certain to annoy
> everybody. I'm sure of it.
> [...]
Thanks, I wanted to know how is this enforced. I'll save other
people a few searches:
(Gemini verbatim begins)
---
Enforcement of the EU **Cyber Resilience Act (CRA)** is **not
centralised** under a single European Union body. Instead,
enforcement is managed decentrally by individual EU member states.
### 🏛️ Enforcement Structure
* **Market Surveillance Authorities (MSAs):** Each member state
designates national market surveillance authorities to enforce
compliance, inspect products with digital elements, and impose
penalties or product recalls for non-compliance.
* **Notifying Authorities:** Member states designate specific
bodies to assess and accredit conformity assessment
organizations. For example, in France, the ANSSI acts as the
notifying authority.
* **CSIRTs & ENISA:** Computer Security Incident Response Teams
coordinate locally regarding incident reports, while the
**European Union Agency for Cybersecurity (ENISA)** operates the
centralized Single Reporting Platform (SRP) for vulnerability
notifications, though ENISA itself holds no direct enforcement or
penalty powers.
---
(Gemini verbatim ends)
So basically the RCA is made as a tool to taxes the tech-giants.
It is a bit obscure how and if the sword will hit you. that
depends on how each particular EU member decides to deal wi the
RCA.
The risks are
> Non-compliance with the essential requirements or manufacturer
> obligations can attract fines of up to €15 million or 2.5% of
> total worldwide annual turnover, whichever is higher. Lower
> ceilings apply to other infringements and to supplying
> incorrect information.
So in a nutshell. Unless you are a tech giant you can ignore the
RCA.
More information about the Digitalmars-d
mailing list