CRA penalties and enforcement

The Cyber Resilience Act, Regulation (EU) 2024/2847, backs its obligations with substantial penalties under Article 64. The most serious breaches can reach EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. The EUR figures are ceilings, and fines are set and imposed at national level, so the real risk depends on national enforcement as much as on the Regulation itself.

The Article 64 tiers

Article 64 sets tiered maximums according to what has gone wrong:

In each case the figure that applies is the higher of the fixed sum and the percentage, so for larger organisations the turnover-based figure can exceed the headline EUR ceiling.

Enforcement happens nationally

The CRA sets the ceilings, but it does not hand out the fines. Penalties are set and imposed at national level, meaning that the EUR figures are maximums the Regulation permits, and each Member State determines the actual penalties within that frame and enforces them through its own authorities. Two organisations committing the same breach in different Member States could face different outcomes.

Market surveillance

Fines are only part of enforcement. Products with digital elements fall under market surveillance, which can lead to corrective action, restriction or withdrawal of a non-compliant product from the market, alongside or instead of a financial penalty. CRA market surveillance and enforcement are governed principally by Chapter V, Articles 52 to 60, together with Regulation (EU) 2019/1020, with penalties addressed separately in Article 64. In practice, being ordered to fix or pull a product can matter as much as any fine.

The carve-outs

The Regulation tempers its penalties in two important ways:

These carve-outs narrow who is exposed to which penalty, but they do not switch off the underlying obligations.

How CRANIS2 helps

CRANIS2 reduces penalty exposure by keeping the obligations that carry the highest fines, the Annex I essential requirements and the Article 13 and 14 manufacturer duties, evidenced and current, and by making sure the information you supply to authorities is accurate rather than incomplete. Understand where you are exposed with our non-compliance guide.

Frequently asked questions

What is the maximum CRA fine?

For breaching the essential requirements in Annex I or the manufacturer obligations in Articles 13 and 14, the maximum under Article 64 is EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. These are ceilings; the actual fine is set at national level.

Can an open source steward be fined?

No. An open source software steward cannot be fined for any CRA infringement.

Who decides and imposes the fines?

Fines are set and imposed at national level. The CRA's EUR figures are maximums, and each Member State determines and enforces penalties within that frame.


Related guides: CRA reporting obligations from September 2026 and CRA timeline of key deadlines.