← CRA Glossary
CRA Regulatory

Market Surveillance Authority (MSA)

A Market Surveillance Authority is a national regulatory body responsible for enforcing product safety and compliance legislation within an EU member state. Under the Cyber Resilience Act, MSAs investigate non-compliant products with digital elements, order corrective actions, and can impose fines or market bans.

A Market Surveillance Authority is a national regulatory body responsible for enforcing product safety and compliance legislation within an EU member state. Under the Cyber Resilience Act, MSAs investigate non-compliant products with digital elements, order corrective actions, and can impose fines or market bans.

CRA Regulatory

What Is a Market Surveillance Authority?

A Market Surveillance Authority (MSA) is a government agency designated by an EU member state to monitor whether products placed on the national market comply with applicable EU legislation. Under the Cyber Resilience Act, each member state must designate one or more MSAs with responsibility for CRA enforcement. MSAs have the power to request technical documentation, conduct product assessments, order corrective measures, and withdraw or recall non-compliant products. They act as the primary enforcement arm that gives the CRA its legal teeth. Manufacturers, importers, and distributors operating in the EU must cooperate fully with MSA investigations, providing access to records, source code documentation, and vulnerability handling processes on request.

CRA reference:Article 41

MSA Powers Under the CRA

The CRA grants MSAs significant investigative and enforcement powers. They can require economic operators to provide all technical documentation and conformity assessment records. They may order manufacturers to bring non-compliant products into conformity within a defined timeframe, restrict or prohibit the product's availability on the market, and arrange for its withdrawal or recall. MSAs can also impose administrative fines - up to €15 million or 2.5% of global annual turnover for the most serious violations. When a product poses a significant cybersecurity risk, MSAs can act immediately without prior notice. MSAs coordinate through the EU's ADCO (Administrative Cooperation) group and notify the European Commission via the RAPEX/ICSMS notification systems when significant risks are identified.

CRA reference:Article 41, Article 54, Article 64

What Triggers an MSA Investigation?

MSA investigations are typically triggered by several routes: complaints from security researchers or affected users, notifications via ENISA's European Vulnerability Database, alerts raised by other member state MSAs through RAPEX, proactive market surveillance sweeps, or incidents reported under the CRA's mandatory notification obligations. A manufacturer that fails to acknowledge a vulnerability report, fails to issue a security advisory within required timeframes, or places a product on the market without a valid declaration of conformity is at elevated risk of MSA scrutiny. PSIRT teams and compliance officers should treat MSA correspondence as urgent legal matters requiring senior management escalation.

CRA reference:Article 41, Article 14

How to Prepare for MSA Scrutiny

Manufacturers can reduce MSA investigation risk by maintaining audit-ready compliance artefacts at all times. Key preparations include: keeping technical documentation current and accessible per Annex VII requirements; maintaining a published CVD policy with verifiable response records; ensuring the declaration of conformity is signed by an authorised representative; retaining vulnerability handling logs with timestamps; and conducting annual internal compliance reviews. When an MSA does make contact, manufacturers should respond promptly and constructively, provide requested documentation without delay, and engage legal counsel familiar with EU product regulation. Demonstrating a good-faith effort to comply significantly influences MSA enforcement discretion.

CVD Portal makes Market Surveillance Authority (MSA) compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Which body acts as the MSA for the CRA in my country?+

Each EU member state designates its own MSA(s) for CRA purposes. In Germany this is the Bundesnetzagentur (BNetzA); in France the ANSSI plays a significant role; in the Netherlands the RDI is involved. The European Commission publishes a list of designated MSAs once member states notify their designations. Check your national regulator's website or the EU's NANDO database for the current designation in your jurisdiction.

Can an MSA ban a product from the entire EU market?+

A single MSA can ban a product from its own national market immediately. For an EU-wide ban, the MSA notifies the European Commission and other member states through RAPEX. If the Commission determines the risk is not adequately addressed, it can issue an implementing act requiring all member states to restrict or withdraw the product. This makes effective MSA enforcement in one country potentially decisive for market access across the entire EU.

What fines can an MSA impose under the CRA?+

The CRA sets a tiered fine structure. The most serious violations - such as placing a non-conforming product on the market or providing false information to authorities - can attract fines up to €15 million or 2.5% of global annual turnover, whichever is higher. Procedural breaches, such as failing to cooperate with MSA investigations, carry fines up to €5 million or 1% of global annual turnover.

Related terms

EU Cyber Resilience Act (CRA)The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is a horizontal EU regulation that establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on 10 December 2024, with most obligations applying from 11 December 2027.Conformity AssessmentConformity assessment is the process by which a manufacturer demonstrates that its product meets the CRA's essential cybersecurity requirements. The process required depends on the product's classification: Default and Class I products can self-assess; Class II and Critical products require third-party assessment by a notified body.EU Declaration of Conformity (DoC)The EU Declaration of Conformity is a formal document signed by the manufacturer (or authorised representative) declaring that a product meets the essential requirements of all applicable EU regulations, including the CRA. It must be drawn up before the CE mark is affixed and kept available for market surveillance authorities for at least 10 years.Technical Documentation (CRA)Technical documentation under the CRA is the comprehensive set of records a manufacturer must compile and maintain to demonstrate that a product with digital elements meets the Annex I essential cybersecurity requirements. It must be retained for at least 10 years and made available to market surveillance authorities on request.ENISA - EU Agency for CybersecurityENISA (the European Union Agency for Cybersecurity) is the EU's dedicated cybersecurity agency, headquartered in Athens with offices in Brussels. Under the CRA, ENISA operates the central EU vulnerability registry, receives Article 14 notifications of actively exploited vulnerabilities, and publishes guidance supporting manufacturer compliance.Economic Operator (CRA)Economic operators are the legal entities in the supply chain - manufacturers, authorised representatives, importers, and distributors - upon whom the EU Cyber Resilience Act places specific obligations. The manufacturer bears the primary and most extensive obligations, but importers and distributors have supplementary duties that can result in them inheriting manufacturer obligations if the original manufacturer is non-compliant.

Browse the full CRA Compliance Checklist

See how Market Surveillance Authority (MSA) fits into your complete CRA compliance programme.

View checklists →