Cyber Resilience Act
Penalties and administrative fines
Practical term
Penalties and administrative fines are the enforcement side of the Cyber Resilience Act (CRA). Article 64 sets the ceilings but leaves the design to the Member States. They lay down the rules on penalties, take the measures needed to implement them, and notify the Commission of both without delay. The penalties must be effective, proportionate and dissuasive.
Which tier applies does not depend on how serious the case looks. It depends on which provision was infringed, and that allocation sits directly in Article 64(2) to (4).
The three tiers
- Up to EUR 15 million or 2.5 % of worldwide annual turnover for the preceding financial year, whichever is higher: non-compliance with the Essential cybersecurity requirements in Annex I, and infringements of the manufacturer duties in Article 13 and the Reporting obligations in Article 14.
- Up to EUR 10 million or 2 %: infringements of Articles 18 to 23 (authorised representatives, importers, distributors, identification of economic operators), Article 28 (EU declaration of conformity), Article 30(1) to (4) (CE marking), Article 31(1) to (4) (technical documentation), Article 32(1) to (3) (conformity assessment procedures), Article 33(5) (simplified documentation for micro and small enterprises), Articles 39, 41, 47 and 49 (duties of notified bodies) and Article 53 (access to data and documentation).
- Up to EUR 5 million or 1 %: supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request.
The percentage ceiling applies only where the offender is an undertaking, and the reference figure is total worldwide annual turnover for the preceding financial year. Neither turnover from the product concerned nor turnover in the Union is the measure.
Infringements absent from all three paragraphs are not free of consequence either. Paragraph 1 obliges Member States to provide penalties for infringements of the Regulation as such; the CRA simply sets no ceiling of its own for them.
How the amount is set
Article 64(5) requires all relevant circumstances of the individual case to be weighed, and singles out three:
- the nature, gravity and duration of the infringement and of its consequences,
- whether the same or other market surveillance authorities have already fined the same economic operator for a similar infringement,
- the size of the economic operator, in particular with regard to Micro, small and medium-sized enterprises including start-ups, and its market share.
The second criterion cuts both ways. Recital 120 explains that an earlier fine can aggravate matters where the infringement continues in a further Member State, or mitigate them so that the total of all fines stays proportionate. To make that workable, market surveillance authorities that apply a fine communicate it to the market surveillance authorities of the other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.
Who actually imposes the fine is a question of national law. Paragraph 6 assumes market surveillance authorities applying fines; under paragraph 8 the fines may also be imposed by competent national courts or other bodies, depending on the legal system, as long as the application has an equivalent effect. Each Member State also decides for itself whether public authorities and public bodies can be fined at all.
A fine is rarely the first measure
For most manufacturers the ceiling is not what hurts most. Losing market access is. Under paragraph 9, fines may be imposed in addition to any corrective or restrictive measure a Market surveillance authority orders for the same infringement.
Article 54 sets out the usual sequence. Where an authority has sufficient reason to believe a product presents a Significant cybersecurity risk, it evaluates conformity and, on finding non-compliance, requires corrective action within a period appropriate to the risk. If that action does not follow, provisional measures come next: prohibiting or restricting the product on the national market, withdrawing it, or recalling it. Where neither a Member State nor the Commission objects within three months, the measure is deemed justified.
Article 58 bites considerably earlier. A missing or wrongly affixed CE marking, an EU declaration of conformity that was not drawn up or not drawn up correctly, a missing identification number of the notified body, where one was involved in the conformity assessment procedure, or technical documentation that is unavailable or incomplete each amount to formal non-compliance, and where it persists, the Member State concerned takes all appropriate measures to restrict or prohibit making the product available, or to ensure that it is recalled or withdrawn. Article 57 goes further still: even for a compliant product, the authority requires appropriate measures where that product presents a significant cybersecurity risk and, on top of that, a risk to the health or safety of persons, to compliance with obligations protecting fundamental rights, to services offered by essential entities, or to other aspects of public interest protection.
Access, answers and confidentiality
Article 53 gives market surveillance authorities access, on a reasoned request, to the data needed to assess design, development, production and vulnerability handling, including relevant internal documents of the economic operator, where that is necessary to assess conformity with the essential cybersecurity requirements in Annex I. Article 63 is the counterweight. Everyone involved in applying the Regulation must preserve confidentiality, expressly protecting intellectual property rights, confidential business information and trade secrets, source code included. Holding back is still the more expensive route, because incorrect, incomplete or misleading answers to a request form a fine tier of their own.
Two exemptions
Article 64(10) takes two cases out of the fines:
- manufacturers that qualify as microenterprises or small enterprises, for failing to meet the deadline in Article 14(2), point (a), or Article 14(4), point (a). That is the 24-hour early warning in each case. The 72-hour notification and the final report remain fineable, and medium-sized enterprises are outside the exemption.
- open-source software stewards, for any infringement of the Regulation. Market surveillance still reaches them: under Article 52(3) the authority requires appropriate corrective measures where the obligations in Article 24 are not met.
Recital 120 goes one step further and tells Member States not to impose other kinds of pecuniary penalties on these two groups. One imprecision survives in the wording: paragraph 10 derogates from paragraphs 3 to 9, whereas infringements of Article 14 are fined under paragraph 2. The legislator’s intention, however, is stated unambiguously in the recital.
Representative actions
Enforcement by authorities is not the only route. Under Article 65, Directive (EU) 2020/1828 applies to representative actions brought against infringements by economic operators that harm, or may harm, the collective interests of consumers. Recital 124 states that the Directive should apply to such representative actions from 11 December 2027, and that national transposition measures are not a precondition for it to apply.
From when
The Regulation applies from 11 December 2027, and only Article 14 (from 11 September 2026) and Chapter IV, Articles 35 to 51 (from 11 June 2026), come earlier. Article 64 is not among them, so the reporting duties apply more than a year before the fines meant to enforce them. The CRA sets no separate deadline of its own for adopting the national penalty rules; Article 64(1) only requires Member States to notify them to the Commission without delay.
Practical questions
-
As a rule, yes. For market surveillance corrective measures, Article 54 points to Article 18 of Regulation (EU) 2019/1020: every measure must state the grounds it rests on precisely, the economic operator must be told which remedies are available and within what time limits, and must be given the chance to be heard beforehand within a period of no less than ten working days. Only urgency can displace the hearing, and it then has to be granted as soon as possible with the measure reviewed promptly. The procedure for the fine itself is a matter of national law.
-
For the ceiling, Article 64 refers to total worldwide annual turnover for the preceding financial year without defining what counts as the undertaking. Classification as a micro, small or medium-sized enterprise works differently: recital 5 states that the Annex to Recommendation 2003/361/EC should be applied in its entirety, including its rules on partner and linked enterprises. A small subsidiary inside a large group will therefore rarely qualify as a small enterprise. Anyone relying on the reliefs and exemptions for Micro, small and medium-sized enterprises should keep that calculation documented.
-
The CRA does not answer this. Article 64 addresses Member States, and the percentage ceilings apply expressly only where the offender is an undertaking. Recital 121 nevertheless assumes that fines can reach a person who is not an undertaking, in which case the general income level in the Member State and that person’s economic situation should be weighed. Whether and how individuals answer therefore emerges only from the national rules adopted under Article 64(1).
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.