Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CRA penalties explained

CRA Penalties: The 3 Fine Tiers up to €15 Million Explained

CRA penalties are set in three tiers by Article 64 of Regulation (EU) 2024/2847, and the top tier is larger than NIS2’s: up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher, for a product that fails the essential cybersecurity requirements of Annex I or a manufacturer that fails its Article 13 obligations or its Article 14 reporting duties. Below that sit EUR 10 million or 2% for the obligations of importers, distributors, notified bodies and the conformity-assessment machinery, and EUR 5 million or 1% for supplying incorrect, incomplete or misleading information to a notified body or market surveillance authority. The fines are imposed by national market surveillance authorities under national rules, they can be stacked on top of a withdrawal or recall, and two carve-outs — for micro and small enterprises that miss a reporting deadline, and for open-source software stewards — narrow who pays. This guide sets out the three tiers with the articles they attach to, the factors that scale a fine, the exemptions, the non-financial measures that arrive first, and when each exposure begins.

CRA penalties: the three tiers of Article 64
Tier 1 — EUR 15m / 2.5%: Annex I essential requirements, Article 13 manufacturer obligations, Article 14 reporting · Tier 2 — EUR 10m / 2%: Articles 18–23, 28, 30–33, 39, 41, 47, 49, 53 · Tier 3 — EUR 5m / 1%: incorrect, incomplete or misleading information.

The three tiers of CRA penalties

Tier Ceiling (whichever is higher) What it attaches to Article 64
1 EUR 15 000 000 or 2.5% of total worldwide annual turnover for the preceding financial year Non-compliance with the essential cybersecurity requirements in Annex I; the manufacturer obligations in Article 13; the reporting obligations in Article 14 64(2)
2 EUR 10 000 000 or 2% Articles 18 to 23 (authorised representatives, importers, distributors, cases where manufacturer obligations transfer, identification of economic operators); Article 28 (EU declaration of conformity); Article 30(1)–(4) (CE marking); Article 31(1)–(4) (technical documentation); Article 32(1)–(3) (conformity assessment); Article 33(5); Articles 39, 41, 47, 49 (notified bodies); Article 53 (access to data and documentation) 64(3)
3 EUR 5 000 000 or 1% Supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request 64(4)

Read the CRA penalties tiers by who they reach. Tier 1 is the manufacturer’s tier: a product without an SBOM, shipped with a known exploitable vulnerability, supported for less than the Article 13(8) minimum of five years, or whose actively exploited vulnerability was not notified within 24 hours, all sit here. Tier 2 reaches the rest of the supply chain — an importer that places a non-conforming product on the market, a distributor that fails its verification duties — and the manufacturer’s own paperwork failures around the declaration, the CE marking and the technical documentation. Tier 3 is about candour under investigation. Our guide to the EU CRA covers the obligations the tiers attach to.

What scales the fine

Article 64(1) leaves the rules to Member States, requiring only that penalties be “effective, proportionate and dissuasive”, and Article 64(5) lists what must be weighed in every case:

  • the nature, gravity and duration of the infringement and of its consequences;
  • whether administrative fines have already been applied by the same or another market surveillance authority to the same economic operator for a similar infringement;
  • the size — “in particular with regard to microenterprises and small and medium sized-enterprises, including start-ups” — and the market share of the operator.

Two structural rules sit alongside. Article 64(6) requires authorities that fine to tell the other Member States’ authorities through the Regulation (EU) 2019/1020 information system, so a fine in one country is known to the others before a similar case there. And Article 64(9) allows fines “in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement” — the fine and the recall are not alternatives.

Who is exempt from CRA penalties

Exemption Scope Article
Micro and small enterprises — reporting deadlines No administrative fine for missing the 24-hour early-warning deadline for an actively exploited vulnerability (Article 14(2)(a)) or a severe incident (Article 14(4)(a)). The 72-hour notification and the final report are not covered by the exemption 64(10)(a)
Open-source software stewards No administrative fines for any infringement of the Regulation 64(10)(b)
Public authorities and public bodies Each Member State decides whether and to what extent fines may be imposed on its own public bodies 64(7)

The first exemption is narrower than it is usually reported. A small manufacturer that misses the 24-hour early warning is spared the fine; one that never submits the 72-hour vulnerability notification or the 14-day final report is not. And the exemption is from the fine only — the reporting obligation itself still applies, and Article 14(8)’s duty to inform users still applies.

What arrives before the fine

CRA penalties are the last step of a market-surveillance procedure, not the first. Under Article 54 a national authority that finds a product presenting a significant cybersecurity risk requires the operator to bring it into conformity, withdraw it or recall it within a set period; if the operator does not, the authority takes the measures itself and notifies the Commission and the other Member States. Article 57 allows the same measures for a product that is compliant but still presents a significant risk. Article 58 covers formal non-compliance — CE marking wrongly affixed or missing, no declaration of conformity, technical documentation unavailable — and again leads to withdrawal or recall if not corrected. Article 60 gives authorities the power to run coordinated “sweeps” of product categories. The commercial consequence of withdrawal usually exceeds the fine, which is why the fine tiers are the wrong number to plan around.

When each exposure begins

Obligation Applies from Fine tier Note
Article 14 reporting — actively exploited vulnerabilities and severe incidents 11 September 2026 Tier 1 Applies to products already on the market before 11 December 2027 under Article 69(3)
Annex I essential requirements; Article 13 manufacturer obligations 11 December 2027 Tier 1 Products placed on the market earlier are caught only on substantial modification, Article 69(2)
Importer, distributor, declaration, CE marking, technical documentation, conformity assessment 11 December 2027 Tier 2
Notified body obligations 11 June 2026 (Chapter IV) Tier 2 Articles 39, 41, 47 and 49
Misleading information to authorities or notified bodies With the obligation being investigated Tier 3

The reporting exposure is the first of the CRA penalties to go live and reaches furthest. From 11 September 2026 a manufacturer with connected products on the EU market — whenever they were placed there — that learns of an actively exploited vulnerability and does not notify within 24 hours is in the top tier, and the exemption in Article 64(10)(a) covers only micro and small enterprises. Our guide to the CRA reporting deadline covers the workflow; the CRA vs NIS2 comparison sets the fines against the NIS2 scale of EUR 10 million or 2%.

Reducing exposure to CRA penalties

  1. Know which tier each obligation sits in. Keep a register of the Article 13 duties and the Annex I requirements — Tier 1 — separate from the Chapter III paperwork — Tier 2.
  2. Build the Article 14 workflow now. Awareness triggers, the 24/72-hour clocks, the single reporting platform end-point, user notification under 14(8). It is the earliest and highest exposure.
  3. Determine and document the support period. Article 13(8) requires at least five years and requires the reasoning to be in the technical documentation under Annex VII.
  4. Answer authorities completely. Tier 3 is cheap to avoid and turns a Tier 2 paperwork case into two fines.
  5. Classify before December 2027. Annex III and IV products need a notified body or a certification scheme; a self-assessed important product is a Tier 2 conformity-assessment breach on top of a Tier 1 essential-requirements exposure. Our guide to CRA classification covers the tiers.

Frequently asked questions

What is the maximum fine under the CRA?
Up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 64(2), for non-compliance with the Annex I essential cybersecurity requirements or the Article 13 and 14 obligations.

Who imposes CRA penalties?
National market surveillance authorities under rules each Member State lays down under Article 64(1); depending on the legal system, national courts may impose them under Article 64(8). Authorities notify each other of fines through the Regulation (EU) 2019/1020 system.

Are small companies exempt?
Only in one respect: Article 64(10)(a) exempts micro and small enterprises from fines for missing the 24-hour early-warning deadlines in Article 14(2)(a) and 14(4)(a). Every other obligation and its fine applies, with size weighed under Article 64(5)(c).

Do open-source projects face fines?
Open-source software stewards face no administrative fines under Article 64(10)(b). A manufacturer that monetises open-source software as a product remains a manufacturer and is fined as one.

Can a fine be added to a recall?
Yes. Article 64(9) allows administrative fines in addition to any corrective or restrictive measures applied for the same infringement.

Where this leaves you

Plan CRA penalties by tier and by date: the Tier 1 reporting exposure opens on 11 September 2026 for every product already on the market, the Tier 1 product and Tier 2 paperwork exposures open on 11 December 2027, and all of them sit behind withdrawal and recall powers that cost more than the fine. Build the reporting workflow first, document the support period, classify early, and answer authorities in full.

References

More on the EU CRA

The Reporting Obligations Procedure, the Legacy Product Reporting Readiness Assessment, the Notified Body Engagement Procedure and the EU Declaration of Conformity templates are in the EU CRA Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.