Article 64 ยท Regulation (EU) 2024/2847

What are the fines under the EU Cyber Resilience Act?

Verified against the Official Journal text on

The CRA sets three administrative fine ceilings, each expressed as a euro amount or a percentage of total worldwide annual turnover, whichever is higher. Breaching the essential cybersecurity requirements (Annex I) or the core obligations of Articles 13 and 14 carries up to EUR 15,000,000 or 2.5% of turnover. A middle tier of up to EUR 10,000,000 or 2% covers a named list of other operator duties. Supplying incorrect, incomplete, or misleading information to notified bodies or market surveillance authorities carries up to EUR 5,000,000 or 1%. Member States set the actual national rules.

Basis: Art. 64(2), Art. 64(3), Art. 64(4)

Judgment call: These are ceilings, not fixed fines. Article 64(1) leaves the concrete penalties to Member States, requiring only that they be effective, proportionate, and dissuasive.

The top tier: up to EUR 15,000,000 or 2.5% Art. 64(2)

The highest ceiling attaches to the substance of the regulation. Non-compliance with the essential cybersecurity requirements set out in Annex I, and with the obligations in Article 13 (manufacturer obligations) and Article 14 (reporting), is subject to administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

The middle tier: up to EUR 10,000,000 or 2% Art. 64(3)

A middle ceiling covers a specific, enumerated set of duties rather than the essential requirements themselves. It applies to non-compliance with Articles 18 to 23 (authorised representatives, importers, distributors, and the cases where manufacturer obligations transfer), Article 28 (EU declaration of conformity), Article 30(1) to (4) (CE marking), Article 31(1) to (4) (technical documentation), Article 32(1), (2), and (3) (conformity assessment), Article 33(5), and Articles 39, 41, 47, 49, and 53.

For these, the fine is up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. In plain terms: getting the paperwork, the marking, or the assessment route wrong sits one tier below breaching the security requirements, but it is still a serious exposure.

The lowest tier: up to EUR 5,000,000 or 1% Art. 64(4)

The lowest of the three ceilings targets one thing specifically: supplying incorrect, incomplete, or misleading information to notified bodies and market surveillance authorities in reply to a request. That carries administrative fines of up to EUR 5,000,000 or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher. In short, how you answer the regulator is itself a distinct, fineable duty.

Beyond fines: corrective and restrictive powers Art. 54(1), Art. 54(5), Art. 57(1), Art. 64(9)

Fines are not the only lever. Where a market surveillance authority finds a product non-compliant, it can require corrective action, or require the product to be withdrawn from the market or recalled, within a reasonable period. If you do not act, the authority can take provisional measures to prohibit or restrict the product being made available, withdraw it, or recall it. Fines can be imposed in addition to these measures for the same infringement.

There is even a route for products that are technically compliant but still present a significant cybersecurity risk: authorities can require measures up to withdrawal or recall in that case too. So the commercial risk of getting this wrong is not only the fine, it is losing the ability to sell.

Relief for SMEs and open-source stewards Art. 64(5)(c), Art. 64(10)(a), Art. 64(10)(b)

The regulation builds in some proportionality. When setting a fine, authorities must give due regard to the size of the operator, in particular microenterprises and SMEs including start-ups. Two carve-outs go further: microenterprises and small enterprises cannot be fined for missing the 24-hour early warning deadline, and open-source software stewards are not subject to the administrative fines for any infringement of the regulation.

What you must do

  • Meet the essential requirements (Annex I) and the Article 13 and 14 duties: the top fine tier, up to EUR 15,000,000 or 2.5% of worldwide annual turnover, attaches here. (Art. 64(2))
  • Get conformity, marking, and documentation duties right (Art. 28, 30, 31, 32, and related): the middle tier, up to EUR 10,000,000 or 2%, attaches here. (Art. 64(3))
  • Answer notified bodies and market surveillance authorities accurately: misleading information carries up to EUR 5,000,000 or 1%. (Art. 64(4))

Frequently asked

How large can CRA fines get?

The top ceiling is up to EUR 15,000,000 or, for an undertaking, 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. It applies to breaches of the essential requirements and of Articles 13 and 14. (Art. 64(2))

Who actually sets and imposes the penalties?

Member States lay down the national rules on penalties and ensure they are effective, proportionate, and dissuasive. Depending on the legal system, fines may be imposed by competent authorities or by national courts. (Art. 64(1), Art. 64(8))

Can open-source software stewards be fined?

No. The administrative fines do not apply to any infringement of the regulation by open-source software stewards. Stewards carry a lighter set of duties in the first place and sit outside the fine regime. (Art. 64(10)(b))

Can a small company be fined for missing the 24-hour report?

Not for that specific deadline. Microenterprises and small enterprises are carved out of the fines for failing to meet the 24-hour early warning deadline for vulnerabilities or incidents. Other duties still apply. (Art. 64(10)(a))

Is a fine the worst that can happen?

No. Authorities can require corrective action, or order a product withdrawn from the market or recalled, and can restrict it being made available, even where a product is compliant but presents a significant cybersecurity risk. Fines can come on top. (Art. 54, Art. 57)

Exposure starts with being in scope

Before worrying about fine tiers, confirm whether the CRA applies to you. The free Vexwatch scope checker walks the cited decision tree and tells you which obligations you actually carry.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.