CRA Penalties: What You Risk
The Cyber Resilience Act carries severe financial penalties and market restrictions for non-compliance. Understand the risks and how to avoid them.
Maximum Penalty: €15 million or 2.5% of global annual turnover (whichever is higher) for cybersecurity requirement violations.
CRA Penalty Structure
Fines are tiered based on violation severity per Article 64, with the higher amount always applied
Highest Tier
Art. 64(2)(whichever is higher)
Violations That Trigger This Penalty:
- Breaching essential cybersecurity requirements (Annex I)
- Non-compliance with manufacturer obligations (Art. 13)
- Non-compliance with reporting obligations (Art. 14)
- Failing to ensure product cybersecurity throughout lifecycle
Real-World Examples:
- Selling IoT devices with known exploitable vulnerabilities
- Products without security updates capability
- Devices with default passwords that cannot be changed
- Failure to report actively exploited vulnerabilities to ENISA
- Missing or incomplete Software Bill of Materials (SBOM)
- No coordinated vulnerability disclosure policy
Mid Tier
Art. 64(3)(whichever is higher)
Violations That Trigger This Penalty:
- Non-compliance with importer obligations (Art. 18-20)
- Non-compliance with distributor obligations (Art. 21-23)
- Missing or incomplete EU Declaration of Conformity (Art. 28)
- Improper use of CE marking (Art. 30-32)
- Inadequate conformity assessment procedures (Art. 33)
- Non-compliance with notified body requirements (Art. 39, 41, 47, 49, 53)
Real-World Examples:
- Importer placing product on EU market without verifying manufacturer compliance
- Distributor failing to verify CE marking before making product available
- Missing or incomplete EU Declaration of Conformity
- Improper CE marking placement or format
Lower Tier
Art. 64(4)(whichever is higher)
Violations That Trigger This Penalty:
- Providing incorrect information to notified bodies
- Providing incomplete information to market surveillance authorities
- Providing misleading information in response to official requests
Real-World Examples:
- False claims about security certifications
- Inaccurate technical documentation submitted to authorities
- Misleading statements about product compliance status
Who Is Exempt from CRA Fines?
The CRA includes specific exemptions that may reduce or eliminate penalty exposure for certain entities
Open-Source Software Stewards
Art. 64(10)(b)Open-source software stewards are fully exempt from all administrative fines for any CRA infringement.
Note: Other obligations (such as documenting cybersecurity policy and reporting vulnerabilities) still apply, but no fines can be imposed for non-compliance.
Micro and Small Enterprises
Art. 64(10)(a)Microenterprises and small enterprises are exempt from fines related to reporting deadline violations.
Note: This only covers reporting deadlines. Other violations (security requirements, documentation, etc.) can still result in fines, though enterprise size is a mitigating factor.
SME Penalty Mitigation
Art. 64(5)(c)When calculating fines, authorities must consider the size of the enterprise, including microenterprises, SMEs, and start-ups.
Note: This is not a full exemption but requires proportionate penalties for smaller businesses.
Beyond Fines: Other Enforcement Powers
Authorities have additional tools that can be more damaging than financial penalties
Product Withdrawal
Authorities can order immediate removal of non-compliant products from the EU market
Market Prohibition
Prohibition from placing products on the EU market
Recall Orders
Mandatory recall of products already distributed to customers
Corrective Measures
Forced implementation of specific security measures
Real-World Penalty Scenarios
See how CRA penalties could apply to common violation scenarios
Smart Home Device Manufacturer
Violation: Ships products with default passwords and no update mechanism
€15 million or 2.5% turnover
Additional Consequences:
- Product recall
- Market withdrawal
- Reputation damage
Implement unique default credentials and automatic security updates
Software Company
Violation: Fails to maintain proper vulnerability disclosure policy
€10 million or 2% turnover
Additional Consequences:
- Forced policy implementation
- Ongoing monitoring
Establish clear coordinated vulnerability disclosure process
Industrial Equipment Manufacturer
Violation: Provides incomplete technical documentation to authorities
€5 million or 1% turnover
Additional Consequences:
- Documentation review
- Compliance audit
Maintain comprehensive technical documentation from product design
Total Cost of Non-Compliance
Penalties are just the beginning - calculate the full impact
Direct Financial Impact
Operational Impact
For a €100M Revenue Company
Penalty Calculation and Enforcement
How fines are determined and applied
Higher Amount Always Applies
Authorities apply the higher amount between the fixed euro amount and the percentage of global turnover.
Note: For a €1B revenue company, 2.5% = €25M, which exceeds the €15M fixed amount.
Factors Affecting Fine Amount
Fines are calculated based on: nature/gravity/duration of infringement, prior violations, and company size/market share.
Note: Per Art. 64(5), all relevant circumstances are considered, which may increase or decrease the final amount.
Cumulative Enforcement
Administrative fines may be imposed in addition to other corrective measures like product recalls or market bans.
Note: Per Art. 64(9), fines can be combined with withdrawal orders, recalls, and mandatory corrective actions.
How to Avoid These Penalties
Prevention is always better (and cheaper) than paying fines
Official Source
Regulation (EU) 2024/2847 - Cyber Resilience Act, Chapter VII
Penalties and enforcement measures for violations of cybersecurity requirements for products with digital elements.
View on EUR-Lex