The top tier: up to EUR 15,000,000 or 2.5% Art. 64(2)
The highest ceiling attaches to the substance of the regulation. Non-compliance with the essential cybersecurity requirements set out in Annex I, and with the obligations in Article 13 (manufacturer obligations) and Article 14 (reporting), is subject to administrative fines of up to EUR 15,000,000 or, if the offender is an undertaking, up to 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
The middle tier: up to EUR 10,000,000 or 2% Art. 64(3)
A middle ceiling covers a specific, enumerated set of duties rather than the essential requirements themselves. It applies to non-compliance with Articles 18 to 23 (authorised representatives, importers, distributors, and the cases where manufacturer obligations transfer), Article 28 (EU declaration of conformity), Article 30(1) to (4) (CE marking), Article 31(1) to (4) (technical documentation), Article 32(1), (2), and (3) (conformity assessment), Article 33(5), and Articles 39, 41, 47, 49, and 53.
For these, the fine is up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. In plain terms: getting the paperwork, the marking, or the assessment route wrong sits one tier below breaching the security requirements, but it is still a serious exposure.
The lowest tier: up to EUR 5,000,000 or 1% Art. 64(4)
The lowest of the three ceilings targets one thing specifically: supplying incorrect, incomplete, or misleading information to notified bodies and market surveillance authorities in reply to a request. That carries administrative fines of up to EUR 5,000,000 or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher. In short, how you answer the regulator is itself a distinct, fineable duty.
Beyond fines: corrective and restrictive powers Art. 54(1), Art. 54(5), Art. 57(1), Art. 64(9)
Fines are not the only lever. Where a market surveillance authority finds a product non-compliant, it can require corrective action, or require the product to be withdrawn from the market or recalled, within a reasonable period. If you do not act, the authority can take provisional measures to prohibit or restrict the product being made available, withdraw it, or recall it. Fines can be imposed in addition to these measures for the same infringement.
There is even a route for products that are technically compliant but still present a significant cybersecurity risk: authorities can require measures up to withdrawal or recall in that case too. So the commercial risk of getting this wrong is not only the fine, it is losing the ability to sell.
Relief for SMEs and open-source stewards Art. 64(5)(c), Art. 64(10)(a), Art. 64(10)(b)
The regulation builds in some proportionality. When setting a fine, authorities must give due regard to the size of the operator, in particular microenterprises and SMEs including start-ups. Two carve-outs go further: microenterprises and small enterprises cannot be fined for missing the 24-hour early warning deadline, and open-source software stewards are not subject to the administrative fines for any infringement of the regulation.