The CFO problem
EU cybersecurity regulation is now a financial risk line. CRA penalties reach €15 million or 2.5% of global annual turnover. The AI Act reaches €35 million or 7%. NIS2 reaches €10 million or 2%. These are not theoretical — enforcement is active and escalating.
Your compliance team needs budget. Your board needs a risk number. Neither gets what they need from a regulatory summary document. You need: maximum exposure by regulation, probability-weighted risk, compliance cost estimates, and the ROI case for investing in compliance infrastructure before enforcement.
Maximum penalty exposure by regulation
| Regulation | Maximum penalty | Basis | |---|---|---| | EU AI Act | €35M or 7% global annual turnover | Prohibited practice (Article 5) | | GDPR | €20M or 4% global annual turnover | Data protection violation | | CRA — Annex I violation | €15M or 2.5% global annual turnover | Essential cybersecurity requirement | | NIS2 | €10M or 2% turnover | Article 21 security or Article 23 reporting | | CRA — Article 14 violation | €10M or 2% global annual turnover | Vulnerability reporting failure | | CRA — incorrect information | €5M or 1% global annual turnover | False information to authorities | | DORA | Competent authority discretion | ICT risk management failure |
For a company with €100M global annual turnover:
- AI Act prohibited practice: up to €7M
- CRA Annex I violation: up to €2.5M
- NIS2 Article 21 failure: up to €2M
- Combined multi-regulation exposure: up to €11.5M
→ CRA penalty exposure calculator
Penalty calculation factors
Regulators consider these factors when setting actual penalties (CRA Article 64(5)):
- Nature, gravity, and duration of the infringement
- Number of persons affected
- Whether the infringement was intentional or negligent
- Actions taken to mitigate harm
- Degree of cooperation with authorities
- Prior infringements
- Financial benefit gained or loss avoided
- Company size and market share
Key implication for CFOs: A compliance programme with documented gap remediation and audit-ready evidence demonstrates cooperation and mitigation — the two factors most likely to reduce penalty magnitude.
EU market access risk
For non-EU manufacturers, CRA creates a market access gate: products not complying with essential cybersecurity requirements cannot be placed on the EU market. For US and Asian manufacturers, non-compliance is not just a penalty risk — it is a revenue risk.
→ EU Market Access Score — cross-regulation readiness score
Compliance cost benchmarking
NexCyber is designed as the lowest-cost path to compliance evidence:
- Gap assessment included in platform (vs. €15,000–40,000 consultant engagement)
- SBOM generation integrated (vs. bespoke tooling procurement)
- Evidence layer with 10-year retention (vs. manual document management)
- MRCC attestation as output (vs. notified body assessment for Class I products)
The platform cost is a fraction of a single penalty or a single notified body assessment.
MRCC — the financial signal to buyers
Enterprise buyers increasingly require evidence of EU regulatory compliance before procurement. A Machine-Readable Compliance Certificate (MRCC) from NexCyber gives your sales team a verifiable compliance signal — verifiable in 30 seconds, no NexCyber account required.
For CFOs: the MRCC reduces procurement friction, accelerates sales cycles in regulated sectors, and is a differentiator in EU public sector procurement where CRA compliance will become a selection criterion.
Tools
- Penalty Calculator — maximum exposure by regulation, sector, country, company size
- EU Market Access Score — cross-regulation readiness
- Responsibility Mapper — RACI by role across 5 regulations
Related answers
NexCyber — EU Market Access Compliance Platform