Cyber Resilience Act

Micro, small and medium-sized enterprises

Legal definition Art. 3(19) CRA

“microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC”
Regulation (EU) 2024/2847, Art. 3(19) CRA

Microenterprises, small enterprises and medium-sized enterprises are not a separate class of obligations under the Cyber Resilience Act (CRA) but a size classification. Article 3, point (19) defines all three classes purely by reference to the Annex to Recommendation 2003/361/EC. To find out whether you qualify you therefore look not at the CRA itself, but at a recommendation twenty years its senior.

The classification does not decide whether a product has to meet the requirements. At a handful of specific points it decides what demonstrating compliance costs and how much paperwork it takes.

The thresholds

Article 2 of the Annex to the Recommendation sets three tiers, each pairing a staff criterion with a financial one:

  • Microenterprise: fewer than 10 staff, annual turnover or balance sheet total no higher than EUR 2 million
  • Small enterprise: fewer than 50 staff, annual turnover or balance sheet total no higher than EUR 10 million
  • The SME category as a whole, medium-sized enterprises included: fewer than 250 staff and either turnover of no more than EUR 50 million or a balance sheet total of no more than EUR 43 million

The staff criterion always has to be met, while on the financial side one of the two figures suffices. Headcount is measured in annual work units under Article 5 of the Annex, so part-time and seasonal work counts as a fraction. Apprentices and people on vocational training contracts are left out entirely, as is time spent on maternity or parental leave.

The figures come from the latest approved accounting period. Under Article 4(2) of the Annex, crossing a ceiling changes nothing unless it happens over two consecutive accounting periods. A single strong year does not yet cost you the status.

Group structure overrides the headcount

Your own payroll is not the whole calculation. Recital 5 of the CRA states that the provisions of the Annex should be applied in their entirety, including its Article 6 on establishing enterprise data. Data of partner enterprises, meaning a holding of 25 % or more, are added pro rata, and data of linked enterprises are added in full.

A subsidiary with eight employees is therefore no microenterprise if the group behind it clears the ceilings. Article 3(4) of the Annex goes further still: where 25 % or more of the capital or voting rights is controlled by public bodies, the enterprise is not an SME at all. The only exception is the categories of investor listed in the second subparagraph of Article 3(2).

What actually gets easier

The CRA tiers its relief. Part of it is open only to micro and small enterprises, the rest to all three classes.

Micro and small enterprises only:

  • Technical documentation may be submitted in a simplified format under Article 33(5). Notified bodies must accept that form for the purposes of conformity assessment.
  • No administrative fine for missing the 24-hour early warning deadline, Article 64(10), point (a).
  • National support measures under Article 33(1): awareness raising and training, a dedicated communication channel, support for testing and conformity assessment activities.
  • Facilitated access to Cyber resilience regulatory sandboxes under Article 33(2), and information on financial support from Union programmes under Article 33(4).

All three classes:

What does not change

The essential cybersecurity requirements in Annex I apply to a two-person company exactly as they apply to a corporate group. So do the manufacturer obligations in Article 13 and the reporting duties in Article 14. Whether a product counts as important or critical turns on the product, never on the size of whoever makes it.

For breaches of Annex I or of Articles 13 and 14, Article 64(2) provides for fines of up to EUR 15 000 000 or 2.5 % of total worldwide annual turnover for the preceding financial year, whichever is higher. The ceiling itself draws no distinction by size; size enters only when the amount is set in the individual case, Article 64(5), point (c).

The simplified form is no discount on substance either. It covers all the elements of the technical documentation specified in Annex VII and settles only how those elements may be presented concisely. An enterprise that opts for it must use the Commission form: failure to comply with Article 33(5) is itself subject to fines of up to EUR 10 000 000 or 2 % of total worldwide annual turnover for the preceding financial year under Article 64(3).

What is still open

The simplified form is not in the text of the regulation. Article 33(5) leaves it to an implementing act adopted under the examination procedure in Article 62(2). Until that act is in place, the full Annex VII format is the only one on offer.

The national measures are not guaranteed either. Article 33(1) binds Member States only “where appropriate”, and sandboxes are something they “may” establish. Whether a communication channel or a sandbox exists in your Member State is a question of national implementation, not of the regulation’s text.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.