Back to Knowledge Base
Knowledge Base · fundamentals

CRA penalties: maximum fines, violation tiers, and how exposure is calculated

7 June 2026 4 min read CRA

CRA penalties reach €15M or 2.5% of global turnover for essential requirement violations. Learn the three penalty tiers, what triggers each, and how to calculate your maximum exposure.

The short answer

The Cyber Resilience Act has three penalty tiers. The highest — up to €15 million or 2.5% of global annual turnover (whichever is higher) — applies to violations of the essential cybersecurity requirements in Annex I. The tier that applies to your situation depends on which obligation was violated, not on the severity of the resulting harm.

The three penalty tiers

| Tier | Maximum penalty | Applies to |

|---|---|---|

| Tier 1 | €15M or 2.5% global turnover | Non-compliance with essential cybersecurity requirements (Annex I) or vulnerability reporting obligations (Art. 14) |

| Tier 2 | €10M or 2% global turnover | Non-compliance with other obligations in the Regulation (Art. 13–20, 23–29) |

| Tier 3 | €5M or 1% global turnover | Supplying incorrect, incomplete, or misleading information to market surveillance authorities or notified bodies |

The percentage of global annual turnover applies to the preceding financial year. If the offender is an SME or start-up, penalties must be proportionate to turnover and economic viability (Art. 64(4)).

What triggers Tier 1 (€15M / 2.5%)

Tier 1 applies when a product with digital elements is placed on the market without meeting the essential cybersecurity requirements in CRA Annex I Part I and Part II, including:

Art. 14 is explicitly Tier 1. Failure to notify ENISA within 24 hours of an actively exploited vulnerability carries the same maximum penalty as shipping a product with known security vulnerabilities.

  • Known exploitable vulnerabilities present at market placement (Annex I Part I §1)
  • No secure by default configuration (Annex I Part I §2(2))
  • No capability to receive security updates (Annex I Part I §2(7))
  • No SBOM maintained (Annex I Part II §1)
  • No CVD policy (Annex I Part II §1)
  • No ENISA notification when an actively exploited vulnerability is discovered (Art. 14 — also Tier 1)

What triggers Tier 2 (€10M / 2%)

Tier 2 applies to violations of the manufacturer's other obligations, including:

  • Failure to perform a cybersecurity risk assessment before market placement (Art. 13(2))
  • Failure to draw up technical documentation (Art. 31)
  • Failure to maintain conformity documentation for 10 years (Art. 28)
  • Failure to affix CE marking or draw up EU declaration of conformity (Art. 28)
  • Failure to inform market surveillance authorities of a serious incident affecting third parties (Art. 14(3))
  • Failure to implement corrective measures when instructed by a market surveillance authority (Art. 47)

What triggers Tier 3 (€5M / 1%)

Tier 3 applies to administrative violations:

  • Providing false, incomplete, or misleading information to a market surveillance authority during a product investigation
  • Providing false information to a notified body during conformity assessment

How penalties are calculated

Market surveillance authorities must consider these factors when determining the actual penalty (Art. 64(5)):

The penalty tiers set the ceiling, not a fixed amount. Authorities retain discretion to set lower amounts based on mitigating factors.

  • Nature, gravity, and duration of the violation
  • Intentional or negligent character
  • Actions taken to mitigate damage
  • Degree of responsibility — technical and organisational measures in place
  • Previous violations by the same operator
  • Degree of cooperation with authorities
  • Category of product — higher risk class products weigh more heavily
  • Financial benefit obtained through the violation

SME and start-up provisions

CRA Art. 64(4) requires that penalties for SMEs and start-ups be proportionate to their turnover, economic viability, and size. In practice, this means:

  • For micro-enterprises (< 10 employees, < €2M turnover), €15M or 2.5% global turnover would typically be reduced significantly
  • The "whichever is higher" rule between fixed amount and percentage means that for very small companies, the percentage will often apply
  • Proportionality does not exempt SMEs from penalties — it limits their maximum size

Penalties vs. corrective orders

Monetary penalties are not the primary enforcement mechanism. Before assessing a penalty, market surveillance authorities typically:

Monetary penalties may be applied in addition to or instead of corrective orders, particularly when the manufacturer has failed to comply with a prior corrective measure order.

  • Issue a corrective measure order — requiring the manufacturer to bring the product into compliance within a set period (Art. 47)
  • Issue a withdrawal or recall order — requiring the product to be taken off the market (Art. 47(4))
  • Issue a restriction of access order — limiting the product's availability to end-users (Art. 47(4)(c))

Comparison with other EU cybersecurity regulations

| Regulation | Maximum penalty | Basis |

|---|---|---|

| CRA | €15M or 2.5% turnover | Annex I violations |

| NIS2 | €10M or 2% turnover | Essential entities (Art. 34) |

| AI Act | €35M or 7% turnover | Prohibited AI systems (Art. 99) |

| DORA | Periodic penalty payments (no fixed cap in Regulation) | Member State law applies |

| GDPR | €20M or 4% turnover | Art. 83(5) |

CRA penalties are the highest in EU cybersecurity product law, though lower than AI Act maximums for prohibited systems and GDPR maximums for data processing violations.

Calculate your exposure

→ Penalty Calculator — estimate your maximum CRA exposure

→ CRA Scope Checker — confirm whether CRA applies

→ CRA gap assessment — map your Annex I compliance

This page provides regulatory guidance for informational purposes. It is not legal advice. Final penalty amounts are determined by national market surveillance authorities with full discretion within the regulatory ceilings. For enforcement matters, consult a qualified legal adviser or your national competent authority.

NexCyber — EU Market Access Compliance Platform

This is an educational explainer. For the canonical regulation reference, see the dedicated CRA page — or run an assessment to see how it applies to your product.