NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Cyber Resilience Act Fines and Penalties
Learn

Cyber Resilience Act Fines and Penalties

·Alexander Sverdlov

Cyber Resilience Act fines top out at 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher. That ceiling applies to the breaches the Regulation treats as most serious: failing the essential cybersecurity requirements in Annex I, and failing the manufacturer duties in Article 13 or the reporting duties in Article 14. Two lower tiers sit beneath it, at 10 million euros or 2%, and 5 million euros or 1%.

The structure matters more than the headline number. Article 64 does not scale the fine to the severity of the vulnerability. It scales it to which obligation you broke. A manufacturer that ships a flawed product and reports it correctly is in a very different position from one that ships the same product and stays quiet.

Maximum fineWhat it coversSource
15M euros or 2.5%Non-compliance with the essential cybersecurity requirements in Annex I, and with the obligations in Articles 13 and 14.Art. 64(2)
10M euros or 2%Non-compliance with the other obligations, including Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32, Article 33(5), and Articles 39, 41, 47, 49 and 53.Art. 64(3)
5M euros or 1%Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities in reply to a request.Art. 64(4)

In each tier the ceiling is the higher of the fixed sum and the percentage of turnover, so for any company with worldwide turnover above 600 million euros the percentage is the binding number in the top tier.

The three Cyber Resilience Act penalty ceilings under Article 64: 15 million euros or 2.5 percent, 10 million or 2 percent, and 5 million or 1 percent

What are the fines under the Cyber Resilience Act?

Three ceilings, set by Article 64 and applied by national authorities. The Regulation sets the maximum; Member States lay down the rules on penalties and enforce them, which means the amount actually imposed is a national decision taken inside an EU ceiling.

Article 64 also lists what authorities must weigh: the nature, gravity and duration of the infringement, whether it was negligent or intentional, action taken to mitigate the harm, previous infringements, and the size of the undertaking, with microenterprises and small and medium sized enterprises including start-ups explicitly called out. A first, self reported, promptly fixed failure by a small manufacturer is not the case the ceiling was written for.

Which breaches attract the top tier?

Three things, and it is worth being precise because this is where the published summaries blur.

Annex I: the essential cybersecurity requirements

Part I covers product properties: shipped without known exploitable vulnerabilities, secure by default, able to receive security updates. Part II covers vulnerability handling: an SBOM, coordinated disclosure, and timely distribution of security updates.

Article 13: manufacturer obligations

The cybersecurity risk assessment, the conformity assessment, the technical documentation, the support period, and the duty to keep the product compliant for its lifetime rather than only at the point of sale.

Article 14: reporting

Actively exploited vulnerabilities and severe incidents affecting product security must be reported, with an early warning inside 24 hours and a fuller notification inside 72 hours. This is the obligation most likely to be breached first, because it starts on 11 September 2026, well before the rest of the Regulation applies.

One narrow relief: Article 64(10)(a) removes fines for microenterprises and small enterprises that miss the specific deadlines in Article 14(2)(a) or Article 14(4)(a). The duty to report remains; the fine for lateness does not apply.

What sits inside the top Cyber Resilience Act penalty tier: Annex I Parts I and II, Article 13 manufacturer duties, and the Article 14 reporting clocks

Who issues the fines?

National market surveillance authorities, designated by each Member State, not the European Commission. Practically, that means the authority in the Member State where your product is on the market can act, and a manufacturer selling across the EU can face more than one authority looking at the same product.

Reports under Article 14 go to the CSIRT designated as coordinator and to ENISA through a single reporting platform, which is a notification channel rather than an enforcement one. The distinction matters: reporting promptly is what keeps you out of the top tier, and the body you report to is not the body that fines you.

How does enforcement escalate before a fine?

A fine is the end of a sequence, not the opening move. Market surveillance authorities typically evaluate the product, require corrective action within a set period, and escalate to restricting availability, then withdrawal or recall, if the operator does not act. Administrative fines sit at the end of that ladder.

The practical consequence is that the commercially painful outcome usually arrives before the fine does. A withdrawal order against a shipping product costs most manufacturers more than the penalty that might follow it.

How Cyber Resilience Act enforcement escalates from market surveillance review through corrective action and restriction to withdrawal and administrative fines

How do CRA fines compare with GDPR, NIS2 and the AI Act?

Lower than the headline regimes, and deliberately so. GDPR reaches 4% of worldwide turnover or 20 million euros. The EU AI Act reaches 7% or 35 million for prohibited practices. NIS2 reaches 2% or 10 million for essential entities. The CRA sits between NIS2 and GDPR at 2.5% or 15 million.

The comparison that matters is not the ceiling but the overlap. A single incident can engage more than one regime at once: a breach of personal data through a vulnerable product is a GDPR matter and a CRA matter, assessed by different authorities under different rules. Mapping the overlap once, across CRA, GDPR and NIS2, is cheaper than discovering it during an incident.

Cyber Resilience Act maximum fines next to GDPR, NIS2 and EU AI Act ceilings as a share of worldwide annual turnover

What the other results get wrong

The most common error is reporting the top tier as though it were the only tier. Most published summaries lead with 15 million euros or 2.5% and stop, which leaves readers assuming any CRA failure carries that exposure. It does not: the 10 million tier covers a much longer list of obligations, and it is the one most operators other than manufacturers will meet.

The second is describing the ceiling as 15 million euros or 2.5%, whichever is lower. It is the higher. For a large manufacturer, the euro figure is not the relevant number at all.

The third is omitting the SME provisions. Both the mitigating factors in Article 64(5) and the narrow relief in Article 64(10)(a) change the realistic exposure for smaller manufacturers, and neither appears in most summaries.

Working out your own exposure

Fill this in. The point is not to produce a number, it is to find out which tier your likely failure mode sits in.

QuestionYour answerTier it engages
What is your total worldwide annual turnover?Above 600M euros, the percentage binds rather than the euro ceiling.
Are you the manufacturer, or an importer or distributor?Manufacturer duties in Art. 13 are top tier. Importer and distributor duties in Arts. 19 to 23 are the 2% tier.
Could you file an Article 14 early warning inside 24 hours today?Top tier. Live from 11 September 2026.
Do you have an SBOM and a coordinated disclosure process?Annex I Part II, top tier.
Are you a microenterprise or small enterprise?Art. 64(10)(a) relief on Art. 14 deadlines, plus mitigation under Art. 64(5)(c).

If most rows are blank, the useful next step is not a legal opinion but a baseline. Our guide to the Cyber Resilience Act compliance timeline sets out what closing those gaps actually takes, and a free compliance check gives you a starting position.

The bottom line on Cyber Resilience Act penalties: the fine follows the missed report rather than the vulnerability itself

Frequently asked questions

What is the maximum CRA fine?

15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, for breaches of Annex I or of Articles 13 and 14.

Can we be fined before December 2027?

Yes. The Article 14 reporting duties apply from 11 September 2026, and they are in the top penalty tier. The rest of the Regulation applies from 11 December 2027.

Are open source developers exposed?

Generally not. Free and open source software supplied outside the course of a commercial activity falls outside the operator duties, and the Regulation creates a lighter touch role for open source software stewards. If you place a product on the market commercially, the components you integrate are your responsibility.

Does one incident mean one fine?

Not necessarily. Different Member States' authorities can act on the same product, and a single event can engage the CRA alongside GDPR or NIS2 obligations assessed separately.

Does self reporting reduce the fine?

Article 64(5) requires authorities to weigh action taken to mitigate damage and whether the infringement was negligent or intentional, so prompt reporting and remediation are relevant. It is not an automatic reduction, and reporting late is itself a top tier breach.

Primary sources

Fine ceilings and the obligations in each tier are taken from Article 64 of Regulation (EU) 2024/2847, together with Articles 13 and 14 and Annex I. Application dates come from the same Regulation, and context from the European Commission's Cyber Resilience Act policy pages. Comparative ceilings for GDPR, NIS2 and the EU AI Act come from those regulations' own penalty articles. Confirm the current text before relying on a figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING