On 11 September 2026, Malta Named Its CRA Enforcement Authorities, and the National Patchwork Is Starting to Show
The Cyber Resilience Act is an EU regulation, directly applicable in every Member State without a national transposition law. But two jobs under it, approving conformity assessment bodies and policing products already on the market, are explicitly left to national governments to staff. On 11 septembrie 2026, Malta published Legal Notice 238 of 2026, the Cyber Resilience Regulations, naming the two agencies that will do that job domestically. It is a useful data point because it is one of the clearer examples yet of a pattern now visible across several Member States: the regulation is the same everywhere, but who enforces it against you is not.
What Malta set up
Malta split the work in two. The Malta Digital Innovation Authority (MDIA) became both the notifying authority for conformity assessment bodies and the market surveillance authority for products with digital elements, under Article 36 and Article 52(2) of the CRA respectively. It can investigate compliance, demand technical documentation, and order corrective measures, with decisions open to administrative review. The Malta Information Technology Agency (MITA) takes the separate role of national CSIRT and CRA coordinator, the body that receives Malta-routed reports forwarded through ENISA's Single Reporting Platform. The notice also allows for regulatory sandboxes for supervised product testing and commits to SME awareness support, alongside the EU-wide penalty ceiling the CRA itself sets under Article 64: up to €15 million or 2.5% of worldwide annual turnover, whichever is higher.
Other Member States are not copying the same structure
Malta's two-agency split is one model. It is not the only one being chosen:
- Hungary went the other way. Act CXXXV of 2025 gives a single body, the Supervisory Authority for Regulatory Affairs (SZTFH), both the notifying authority and the market surveillance authority roles, with three separate fine tiers (up to €15m/2.5%, €10m/2%, and €5m/1% of turnover depending on which obligation is breached) and a rule that repeat infringements draw at least 1.5 times the prior fine.
- Finland centralised differently again: a national act in force since 1 June 2026 gives the National Cyber Security Center Finland, inside the telecoms regulator Traficom, the market surveillance, vulnerability-reporting intake, and notified-body oversight roles together, while keeping Traficom's existing certification-authority function.
- Germany has proposed the same dual notifying-and-surveillance role for the BSI, including a dedicated consumer complaint office and a real-world testing lab, but as of this writing the implementing law has not yet passed the Bundestag.
Why the shape of the authority matters, not just its name
None of this changes where an actively exploited vulnerability or severe incident gets reported: Article 14 routes that to the CSIRT of your main establishment and to ENISA through the Single Reporting Platform regardless of which country you are in, as our ghid de raportare covers. What differs is who can audit your technical documentation years later, which notifying authority a conformity assessment body you want to use must be accredited by, and which national office actually issues a fine if something goes wrong. A manufacturer selling across the EU does not get to choose the friendlier structure. It answers to whichever one its own country, and each Member State where it places a product, has set up, and those are visibly not converging on one template.
What to check for your own markets
If you manufacture or import products with digital elements, it is worth confirming, for each Member State where you are established or placing products, which agency now holds the notifying-authority and market-surveillance roles, since that is also typically the office that will contact you first if a market check turns something up. Our matricea de conformitate tracks the obligations these authorities will be checking against; our Instrumentul de clasificare determines which of them, self-assessment, a notified body, or both, actually applies to your product.
Germany's equivalent law, which would give the BSI the same dual notifying-and-surveillance role described above, had not yet passed the Bundestag as of this writing. Its effective date is therefore not yet fixed, and the 95 to 141 additional BSI staff it proposes are not yet in place.
