Why Penalties Matter for Product Teams
The CRA is enforced through national market surveillance authorities (MSAs) in each EU Member State. These authorities have broad powers to audit products, request documentation, order product withdrawals, and impose fines. Penalties apply to economic operators — manufacturers, importers, and distributors — depending on which obligation was breached.
Three Penalty Tiers
CRA fines use the higher of a fixed amount or a percentage of global annual turnover, whichever is greater. This means large companies face proportionally larger fines.
Penalty Tiers Under Article 64
Up to €15,000,000 or 2.5% of Global Annual Turnover
Applies to breaches of the most essential obligations.
What triggers Tier 1 (Article 64(2)):
- Non-compliance with essential cybersecurity requirements (Annex I)
- Failure to meet manufacturer obligations under Article 13 — including risk assessment, technical documentation, vulnerability handling, and support period obligations
- Failure to report an actively exploited vulnerability or severe incident to ENISA and the national CSIRT within 24 hours as required by Article 14
- Continuing to make a non-compliant product available after a market surveillance order to stop
Up to €10,000,000 or 2% of Global Annual Turnover
Applies to breaches of other manufacturer, importer, and distributor obligations.
What triggers Tier 2 (Article 64(3)):
- Non-compliance with CE marking requirements (Articles 30–31)
- Failure to draw up or maintain the EU Declaration of Conformity (Article 28)
- Non-compliance with conformity assessment procedures (Article 32(1), (2) and (3))
- Failure to appoint an authorised representative where required (Article 18)
- Failure to comply with importer obligations (Article 19) or distributor obligations (Article 20)
- Failure to comply with obligations of open-source software stewards (Article 23) or online marketplace operators (Article 22)
Up to €5,000,000 or 1% of Global Annual Turnover
Applies to providing incorrect, incomplete, or misleading information to authorities.
What triggers Tier 3:
- Providing incorrect or misleading information to market surveillance authorities
- Providing incomplete documentation in response to an official request
- Submitting false declarations (e.g., in the EU Declaration of Conformity)
- Falsely claiming harmonised standard conformity or certification
How Fines Are Actually Calculated
Article 64 sets maximum fines. National MSAs have discretion within these ceilings and must consider mitigating and aggravating factors when determining the actual fine amount.
Mitigating Factors (Reduce Fine)
- Good faith cooperation with authorities
- Prompt corrective action once notified
- First-time violation with no prior record
- Voluntary disclosure of the issue
- SME / microenterprise status (see below)
- Limited severity or scope of the violation
- No financial gain from the violation
Aggravating Factors (Increase Fine)
- Repeated or intentional violations
- Refusal to cooperate with authorities
- Concealment of non-compliance
- High risk to users or critical infrastructure
- Large number of users affected
- Duration of non-compliance before discovery
- Financial gain obtained from the violation
SME and Microenterprise Provisions (Article 64(10))
Article 64(10)(a) provides that administrative fines under Article 64(3)-(9) shall not apply to microenterprises and small enterprises for missing the Article 14(2)(a) or 14(4)(a) reporting deadline — this is a genuine, narrow statutory exemption from that specific fine, not merely a procedural accommodation.
EU law requires national authorities to take into account the economic capacity of the operator when setting fine amounts, which in practice means SMEs typically face lower absolute fines than large enterprises for equivalent violations.
EU SME Definition (for reference)
- Microenterprise: <10 employees, ≤€2M turnover or balance sheet total
- Small enterprise: <50 employees, ≤€10M turnover or balance sheet total
- Medium enterprise: <250 employees, ≤€50M turnover or ≤€43M balance sheet total
Penalties for Open Source Software Stewards
OSS stewards have reduced obligations under CRA (Article 24) and correspondingly reduced penalty exposure. Stewards are subject to:
- Article 64(10)(b) exempts OSS stewards from administrative fines under Article 64(3)-(9) entirely — for any infringement of the Regulation (their obligations are set out in Article 24: cybersecurity policy, cooperation with market surveillance authorities, CVD policy).
- Stewards are not exempted from the Tier 1 fine under Article 64(2), which covers non-compliance with the Annex I essential requirements and Articles 13/14 — Article 24(3) extends some Article 14 reporting duties to stewards in specific circumstances.
How Non-Compliance Is Discovered
Market surveillance authorities use several mechanisms to identify non-compliant products:
Market Sweeps (Article 60)
MSAs can conduct coordinated "sweeps" — simultaneous checks of products in a product category, including purchases under a cover identity — to test compliance with essential requirements. ENISA coordinates joint sweeps across Member States.
Complaints From Users or Competitors
Any person — including users, security researchers, or competitors — can report a suspected non-compliant product to the national MSA. Security researcher reports are a common trigger.
Incidents and Vulnerability Reports
A publicly disclosed vulnerability or security incident can trigger an MSA investigation — especially if the manufacturer failed to report it under Article 14 or failed to patch it promptly.
Proactive Document Checks
MSAs can request the EU Declaration of Conformity, technical documentation, and SBOM from any manufacturer. Missing, incomplete, or incorrect documentation is itself a Tier 1 or Tier 3 violation.
ICSMS / RAPEX Information Exchange
EU Member States share information about non-compliant products through the ICSMS (Information and Communication System for Market Surveillance) and RAPEX (Rapid Alert System). A finding in one Member State can trigger action in all others.
Enforcement Timeline and Process
When an MSA identifies a potentially non-compliant product, the process typically follows:
Initial Assessment
MSA gathers information, may request documentation or testing from the manufacturer/importer.
Notification of Concerns
MSA informs the economic operator of the identified concerns and provides an opportunity to respond and take corrective action.
Corrective Action Period
Where the risk is not immediate, the operator may be given time to remedy the non-compliance before further action.
Formal Enforcement Measures
If non-compliance persists: withdrawal orders, market bans, and/or administrative fines. MSAs notify other Member States via ICSMS.
Right of Appeal
Economic operators can challenge MSA decisions through national administrative and judicial channels.
Related Guidance
Article 14 Reporting
Reporting obligations that, if missed, trigger Tier 2 fines.
Declaration of Conformity
Missing or incorrect DoC is a Tier 1 violation.
Authorized Representative
Not appointing one when required is a Tier 2 violation.
Compliance Checklist
Systematic checklist covering all Tier 1 obligations.
Article 13 Obligations
Full picture of manufacturer obligations underlying penalty tiers.
Market Surveillance Guide
Chapter V authority processes, triggers, and preparation checklist.
Product Assessment
Identify your conformity assessment path to avoid Tier 1 violations.