Independent information resource Product security · EU CRA
CRA enforcement / 10

CRA Fines and Penalties Explained

Cyber Resilience Act fines and penalties explained, including the EUR 15 million or 2.5 percent tier, EUR 10 million or 2 percent tier, EUR 5 million or 1 percent information tier and the role of national penalty rules.

IN BRIEF

The CRA figures are maximum administrative-fine ceilings, not automatic penalties for every breach. Member States establish and apply their penalty rules, and the amount in an individual case depends on the circumstances specified in Article 64. Administrative fines can also be imposed alongside corrective or restrictive market-surveillance measures.

01 / 10

Article 64 Requires National Penalty Rules

Member States must lay down rules on penalties for CRA infringements and take the measures necessary to implement them. The penalties must be effective, proportionate and dissuasive. The CRA therefore sets the Union framework and maximum administrative-fine levels while national legal systems determine the competent authority or court and the detailed enforcement procedure.

02 / 10

The Highest Tier Reaches EUR 15 Million or 2.5 Percent

Non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14 is subject to administrative fines of up to EUR 15 million or, where the offender is an undertaking, up to 2.5 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. This tier reaches core manufacturer and reporting obligations.

03 / 10

A Second Tier Reaches EUR 10 Million or 2 Percent

Article 64 sets a second maximum tier of up to EUR 10 million or, for an undertaking, up to 2 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. It applies to the listed obligations in Articles 18 to 23 and specified provisions concerning declarations, documentation, conformity assessment, notified bodies and Article 53 authority access.

04 / 10

Incorrect or Misleading Information Has Its Own Tier

Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities in reply to a request can attract administrative fines of up to EUR 5 million or, for an undertaking, up to 1 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Authority responses should therefore be complete, controlled and traceable.

05 / 10

The Maximum Is Not an Automatic Fine

Article 64 requires the circumstances of the individual case to be considered when deciding the amount of an administrative fine. The statutory ceilings should not be presented as automatic penalties for any instance of non-compliance. Enforcement outcomes depend on the infringement, consequences, operator conduct and the applicable national procedure.

06 / 10

Article 64 Identifies Aggravating and Mitigating Factors

Relevant factors include the nature, gravity and duration of the infringement and its consequences, previous infringements, financial benefits gained or losses avoided, the size and market share of the undertaking, the degree of cooperation with competent authorities and whether other authorities have already imposed fines for the same infringement. These factors help make the final penalty proportionate to the case.

07 / 10

Fines Can Accompany Corrective or Restrictive Measures

Administrative fines are not necessarily an alternative to product enforcement. Article 64 allows fines, depending on the circumstances, to be imposed in addition to corrective or restrictive measures applied by market surveillance authorities for the same infringement. A company can therefore face both an obligation to correct, withdraw or recall a product and a financial penalty.

08 / 10

Small-Enterprise Reporting Relief Is Narrow

Article 64 contains a specific administrative-fine derogation for manufacturers that qualify as microenterprises or small enterprises when they fail to meet the early deadline identified in Article 14(2)(a) or Article 14(4)(a). This is not a blanket exemption from CRA compliance or from all enforcement action.

09 / 10

Open-Source Software Stewards Have a Tailored Penalty Rule

Article 64 also contains a specific derogation for open-source software stewards. This reflects the CRA's lighter regulatory regime for that role. The existence of the derogation does not remove the steward's substantive obligations or the ability of market surveillance authorities to require appropriate corrective action under Article 52.

10 / 10

Penalty Readiness Starts With Evidence and Cooperation

A defensible response to enforcement depends on accurate product records, timely corrective action and controlled communication with the authority. Companies should preserve the evidence showing what happened, which products were affected, when management became aware, what remediation was taken and how the organisation cooperated with the relevant authority.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.