NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
CRA Penalties and Deadlines: What Applies When
Learn

CRA Penalties and Deadlines: What Applies When

·Alexander Sverdlov

Cyber Resilience Act penalties top out at 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, but no CRA fine can be imposed for anything that happens before 11 September 2026. That is the date the Article 14 reporting duties start to apply. The rest of the Regulation, including the essential requirements in Annex I, the manufacturer duties in Article 13 and conformity assessment, applies from 11 December 2027. The ceilings come from Article 64, the dates from Article 71, and the rule for products already on the market from Article 69.

Read together, those three articles answer the question most summaries skip: not how much the fine is, but which fine can be applied on which date, and to which products. The tier follows the obligation you breach, and the obligation has a start date of its own.

DateWhat starts to applyPenalty exposure
10 December 2024Entry into force, 20 days after publication in the Official Journal on 20 November 2024.None. No obligation applies yet.
11 June 2026Chapter IV, Articles 35 to 51: notification of conformity assessment bodies.None for operators. Member States can begin designating notified bodies.
11 September 2026Article 14: reporting of actively exploited vulnerabilities and severe incidents.Top tier, 15 million euros or 2.5%, for manufacturers.
11 December 2027The Regulation in full: Annex I, Article 13, importer and distributor duties, conformity assessment, CE marking.All three tiers.
11 June 2028EU type-examination certificates and approval decisions issued under other Union harmonisation legislation stop being valid for CRA purposes, unless they expire earlier or that legislation says otherwise.Products relying on them need a CRA route by then.
Five dates on the Cyber Resilience Act penalty clock: entry into force on 10 December 2024, notified bodies from 11 June 2026, reporting duties from 11 September 2026, full application on 11 December 2027 and old certificates valid until 11 June 2028

What are the penalties under the Cyber Resilience Act?

Article 64 sets three ceilings. Article 64(2): non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14 carries fines of up to 15 million euros or, for an undertaking, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 64(3): non-compliance with the obligations in Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1) to (3), Article 33(5) and Articles 39, 41, 47, 49 and 53 carries up to 10 million euros or 2%. Article 64(4): supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request carries up to 5 million euros or 1%.

Member States lay down the rules and national market surveillance authorities apply them, so the amount actually imposed is a national decision inside an EU ceiling. Article 64(5) lists what must be weighed: the nature, gravity and duration of the infringement and its consequences; whether the same or another market surveillance authority has already fined the same operator for a similar infringement; and the size and market share of the operator, with microenterprises and small and medium sized enterprises, including start-ups, named expressly. Article 64(9) allows a fine on top of any corrective or restrictive measure for the same infringement, so a recall and a fine are not alternatives.

Two groups are carved out by Article 64(10). Manufacturers that qualify as microenterprises or small enterprises cannot be fined for missing the 24 hour early warning deadlines in Article 14(2)(a) and Article 14(4)(a); the duty to report stays, the fine for lateness does not. Open-source software stewards cannot be fined for any infringement of the Regulation. Article 65 separately makes the CRA subject to representative actions under Directive (EU) 2020/1828.

The three Cyber Resilience Act fine ceilings in Article 64: 15 million euros or 2.5 percent, 10 million or 2 percent, 5 million or 1 percent, and no fines for open-source software stewards

When does each penalty start to apply?

Article 71(2) has one general date and two exceptions. The Regulation applies from 11 December 2027. Article 14 applies from 11 September 2026. Chapter IV, on the notification of conformity assessment bodies, applies from 11 June 2026.

The June 2026 date creates no exposure for manufacturers, importers or distributors. It exists so that Member States can designate notified bodies in time for the assessment work that follows. The September 2026 date is the first on which an operator can breach the Regulation. From then, a manufacturer that becomes aware of an actively exploited vulnerability in one of its products must file an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident affecting the security of the product, the same 24 and 72 hour clocks run, and the final report is due within one month of the incident notification. All of it goes through the single reporting platform under Article 16 to the CSIRT designated as coordinator and to ENISA.

Because Article 14 sits in Article 64(2), a late report from 11 September 2026 is a top tier breach. That is the only top tier breach possible before December 2027, and it is available to authorities 15 months earlier than the rest.

Which Cyber Resilience Act fine ceiling is live on which date: none on 11 June 2026, the 2.5 percent top tier for Article 14 reporting from 11 September 2026, and every tier from 11 December 2027

Which breaches sit in the top tier, and from when?

The top tier has two start dates. Annex I Part I, the product requirements, Annex I Part II, the vulnerability handling requirements, and the manufacturer obligations in Article 13 all apply from 11 December 2027. Article 14 applies from 11 September 2026. A manufacturer can therefore be fully compliant with the essential requirements as they stand today and still be exposed to the maximum fine on 12 September 2026, for the single reason that a report went out late.

The second tier follows the December 2027 date entirely. It covers the obligations of authorised representatives, importers and distributors in Articles 18 to 23, along with the conformity assessment, notified body and market surveillance duties listed in Article 64(3). Importers and distributors have no CRA penalty exposure at all until 11 December 2027, which is worth knowing if you are one and your supplier is telling you otherwise.

What the top Cyber Resilience Act penalty tier reaches: Annex I Parts I and II, Article 13 manufacturer duties, the Article 14 reporting clocks for vulnerabilities and incidents, and legacy products under Article 69(3)

What happens to products already on the market?

Article 69(2) says products with digital elements placed on the market before 11 December 2027 are subject to the Regulation only if, from that date, they undergo a substantial modification. Article 69(3) then removes reporting from that relief: the Article 14 obligations apply to all in-scope products placed on the market before 11 December 2027. Article 69(1) keeps existing EU type-examination certificates and approval decisions, issued for cybersecurity requirements under other Union harmonisation legislation, valid until 11 June 2028 unless they expire earlier.

The practical consequence is that legacy stock is inside the reporting regime from 11 September 2026 whether or not it will ever be updated to Annex I. If a product you shipped in 2021 has an actively exploited vulnerability in October 2026, the 24 hour clock runs on it. The Annex I exposure for that product only arrives when you substantially modify it, so the decision to push a major update to an old product line after December 2027 is also a decision to bring it into the top tier.

What the other results get wrong

The first error is collapsing the dates. Most articles say the CRA applies from December 2027 and treat the fines as starting then. Fines for late reporting are available from 11 September 2026, and they sit in the top tier.

The second is assuming legacy products are exempt. Article 69(2) exempts them from the essential requirements until they are substantially modified, and Article 69(3) puts them squarely inside Article 14. A product with no CRA conformity work at all can still trigger a top tier fine.

The third is inventing mitigating factors. Several summaries say authorities must weigh intent or the manufacturer's remediation effort. Article 64(5) lists nature, gravity, duration and consequences, prior fines for similar infringements, and the operator's size and market share. Prompt reporting matters because a late report is itself the breach, not because the Regulation promises a discount for it. Our guide to Cyber Resilience Act fines and penalties goes through each tier in detail.

The fourth is "whichever is lower". Every ceiling in Article 64 is the higher of the euro figure and the percentage of turnover.

Cyber Resilience Act penalty exposure on a readiness board: products with digital elements on the EU market, whether the Article 14 early warning has been rehearsed, products still unclassified and legacy products due a substantial modification

Map your own exposure by date

Fill this in. Each row pairs a question with the date on which the answer starts to cost money.

QuestionYour answerDate it matters
Which products with digital elements are on the EU market today, including old ones?11 September 2026: Article 14 applies to all of them under Article 69(3).
Who files the 24 hour early warning, and has the single reporting platform route been rehearsed?11 September 2026, top tier.
Which products will still be on sale on 11 December 2027 without a substantial modification?Outside Annex I until modified, Article 69(2).
Which products are Annex III important or Annex IV critical?Notified body capacity exists from 11 June 2026; assessment must be done by 11 December 2027.
Are you a microenterprise or small enterprise?Article 64(10)(a) relief on the 24 hour deadlines only.

Our guide to the Cyber Resilience Act deadlines for 2026 and 2027 has the full milestone list, and the CRA compliance timeline explains what closing each gap takes. A free compliance check across CRA gives you a starting position before you commit to a plan.

The bottom line on Cyber Resilience Act penalties and deadlines: the first CRA fine you can earn is for late reporting

Frequently asked questions

Can a CRA fine be imposed today?

No. The first obligation that can be breached is Article 14, which applies from 11 September 2026. Before that date there is nothing in the Regulation for an operator to infringe.

Does the September 2026 reporting duty cover products sold years ago?

Yes, if they are in scope. Article 69(3) applies Article 14 to all products with digital elements placed on the market before 11 December 2027, regardless of whether they will ever be brought up to Annex I.

What is the maximum CRA fine?

15 million euros or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Annex I or of Articles 13 and 14.

Are importers and distributors fined at the same level as manufacturers?

No. Their obligations sit in Articles 18 to 23, which Article 64(3) places in the 10 million euro or 2% tier, and none of those obligations applies before 11 December 2027.

Does self reporting reduce the fine?

Article 64(5) does not list it as a factor. Reporting on time keeps you out of the top tier altogether, which is the better outcome. Microenterprises and small enterprises additionally cannot be fined for missing the 24 hour deadlines under Article 64(10)(a).

Are open source projects exposed?

Open-source software stewards cannot be fined for any infringement, under Article 64(10)(b). A manufacturer that integrates open source components into a product it places on the market commercially is exposed in the normal way. Scope is covered in our guide to who must comply with the Cyber Resilience Act.

Primary sources

Fine ceilings and factors are taken from Article 64 of Regulation (EU) 2024/2847, the application dates from Article 71, the transitional rules from Article 69, the reporting clocks from Article 14, and the representative actions rule from Article 65. The Regulation was published in the Official Journal on 20 November 2024 and entered into force 20 days later. Context is from the European Commission's Cyber Resilience Act policy pages. Confirm the current text before relying on a date or figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING