CRA Penalties: What You Risk

The Cyber Resilience Act carries severe financial penalties and market restrictions for non-compliance. Understand the risks and how to avoid them.

Maximum Penalty: €15 million or 2.5% of global annual turnover (whichever is higher) for cybersecurity requirement violations.

CRA Penalty Structure

Fines are tiered based on violation severity per Article 64, with the higher amount always applied

1

Highest Tier

Art. 64(2)
€15 million or 2.5% of global annual turnover

(whichever is higher)

Violations That Trigger This Penalty:

  • Breaching essential cybersecurity requirements (Annex I)
  • Non-compliance with manufacturer obligations (Art. 13)
  • Non-compliance with reporting obligations (Art. 14)
  • Failing to ensure product cybersecurity throughout lifecycle

Real-World Examples:

  • Selling IoT devices with known exploitable vulnerabilities
  • Products without security updates capability
  • Devices with default passwords that cannot be changed
  • Failure to report actively exploited vulnerabilities to ENISA
  • Missing or incomplete Software Bill of Materials (SBOM)
  • No coordinated vulnerability disclosure policy
2

Mid Tier

Art. 64(3)
€10 million or 2% of global annual turnover

(whichever is higher)

Violations That Trigger This Penalty:

  • Non-compliance with importer obligations (Art. 18-20)
  • Non-compliance with distributor obligations (Art. 21-23)
  • Missing or incomplete EU Declaration of Conformity (Art. 28)
  • Improper use of CE marking (Art. 30-32)
  • Inadequate conformity assessment procedures (Art. 33)
  • Non-compliance with notified body requirements (Art. 39, 41, 47, 49, 53)

Real-World Examples:

  • Importer placing product on EU market without verifying manufacturer compliance
  • Distributor failing to verify CE marking before making product available
  • Missing or incomplete EU Declaration of Conformity
  • Improper CE marking placement or format
3

Lower Tier

Art. 64(4)
€5 million or 1% of global annual turnover

(whichever is higher)

Violations That Trigger This Penalty:

  • Providing incorrect information to notified bodies
  • Providing incomplete information to market surveillance authorities
  • Providing misleading information in response to official requests

Real-World Examples:

  • False claims about security certifications
  • Inaccurate technical documentation submitted to authorities
  • Misleading statements about product compliance status

Who Is Exempt from CRA Fines?

The CRA includes specific exemptions that may reduce or eliminate penalty exposure for certain entities

Open-Source Software Stewards

Art. 64(10)(b)

Open-source software stewards are fully exempt from all administrative fines for any CRA infringement.

Scope: Complete exemption from all monetary penalties

Note: Other obligations (such as documenting cybersecurity policy and reporting vulnerabilities) still apply, but no fines can be imposed for non-compliance.

Micro and Small Enterprises

Art. 64(10)(a)

Microenterprises and small enterprises are exempt from fines related to reporting deadline violations.

Scope: Exemption from fines for missing the 24h/72h reporting deadlines in Art. 14(2)(a) and Art. 14(4)(a)

Note: This only covers reporting deadlines. Other violations (security requirements, documentation, etc.) can still result in fines, though enterprise size is a mitigating factor.

SME Penalty Mitigation

Art. 64(5)(c)

When calculating fines, authorities must consider the size of the enterprise, including microenterprises, SMEs, and start-ups.

Scope: Reduced penalties based on company size and market share

Note: This is not a full exemption but requires proportionate penalties for smaller businesses.

Beyond Fines: Other Enforcement Powers

Authorities have additional tools that can be more damaging than financial penalties

Product Withdrawal

Authorities can order immediate removal of non-compliant products from the EU market

Impact: Complete loss of EU market access until compliance achieved

Market Prohibition

Prohibition from placing products on the EU market

Impact: Cannot sell in EU until full compliance demonstrated

Recall Orders

Mandatory recall of products already distributed to customers

Impact: Significant costs for product retrieval and customer compensation

Corrective Measures

Forced implementation of specific security measures

Impact: Additional compliance costs and implementation timelines

Real-World Penalty Scenarios

See how CRA penalties could apply to common violation scenarios

1

Smart Home Device Manufacturer

Violation: Ships products with default passwords and no update mechanism

Financial Penalty:

€15 million or 2.5% turnover

Additional Consequences:

  • Product recall
  • Market withdrawal
  • Reputation damage
Prevention:

Implement unique default credentials and automatic security updates

2

Software Company

Violation: Fails to maintain proper vulnerability disclosure policy

Financial Penalty:

€10 million or 2% turnover

Additional Consequences:

  • Forced policy implementation
  • Ongoing monitoring
Prevention:

Establish clear coordinated vulnerability disclosure process

3

Industrial Equipment Manufacturer

Violation: Provides incomplete technical documentation to authorities

Financial Penalty:

€5 million or 1% turnover

Additional Consequences:

  • Documentation review
  • Compliance audit
Prevention:

Maintain comprehensive technical documentation from product design

Total Cost of Non-Compliance

Penalties are just the beginning - calculate the full impact

Direct Financial Impact

Administrative fines €5M - €15M
Product recall costs €100K - €10M+
Legal and compliance fees €50K - €500K
Market re-entry costs €200K - €2M

Operational Impact

Lost revenue during market ban Varies by market size
Customer compensation €10K - €1M+
Reputation and brand damage Long-term impact
Increased insurance premiums 10-50% increase

For a €100M Revenue Company

€2.5M
Maximum fine (2.5%)
€1-5M
Additional costs
€3.5-7.5M
Total potential impact

Penalty Calculation and Enforcement

How fines are determined and applied

Higher Amount Always Applies

Authorities apply the higher amount between the fixed euro amount and the percentage of global turnover.

Note: For a €1B revenue company, 2.5% = €25M, which exceeds the €15M fixed amount.

Factors Affecting Fine Amount

Fines are calculated based on: nature/gravity/duration of infringement, prior violations, and company size/market share.

Note: Per Art. 64(5), all relevant circumstances are considered, which may increase or decrease the final amount.

Cumulative Enforcement

Administrative fines may be imposed in addition to other corrective measures like product recalls or market bans.

Note: Per Art. 64(9), fines can be combined with withdrawal orders, recalls, and mandatory corrective actions.

How to Avoid These Penalties

Prevention is always better (and cheaper) than paying fines

🔍

Start with Assessment

Identify gaps before they become violations

Gap Analysis
📚

Follow the Guide

Step-by-step compliance implementation

Compliance Guide

Don't Wait

Start compliance work well before 2027

View Timeline
👥

Get Expert Help

Professional guidance reduces risk

Contact Experts

Official Source

Regulation (EU) 2024/2847 - Cyber Resilience Act, Chapter VII

Penalties and enforcement measures for violations of cybersecurity requirements for products with digital elements.

View on EUR-Lex

🤝 Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.