← Back to CRA Guide Last updated: September 10, 2026
EU Regulation 2024/2847 • Article 64

CRA Penalties: Fines, Enforcement, and How Non-Compliance Is Discovered

Article 64 sets three tiers of administrative fines — up to €15M or 2.5% of global turnover for the most serious violations. Understand what triggers each tier and how market surveillance authorities discover non-compliance.

Why Penalties Matter for Product Teams

The CRA is enforced through national market surveillance authorities (MSAs) in each EU Member State. These authorities have broad powers to audit products, request documentation, order product withdrawals, and impose fines. Penalties apply to economic operators — manufacturers, importers, and distributors — depending on which obligation was breached.

Three Penalty Tiers

CRA fines use the higher of a fixed amount or a percentage of global annual turnover, whichever is greater. This means large companies face proportionally larger fines.

Penalty Tiers Under Article 64

T1

Up to €15,000,000 or 2.5% of Global Annual Turnover

Applies to breaches of the most essential obligations.

What triggers Tier 1 (Article 64(2)):

  • Non-compliance with essential cybersecurity requirements (Annex I)
  • Failure to meet manufacturer obligations under Article 13 — including risk assessment, technical documentation, vulnerability handling, and support period obligations
  • Failure to report an actively exploited vulnerability or severe incident to ENISA and the national CSIRT within 24 hours as required by Article 14
  • Continuing to make a non-compliant product available after a market surveillance order to stop
Article 64(2) explicitly covers Annex I requirements and both Articles 13 and 14. Failure to report actively exploited vulnerabilities is a Tier 1 offence, not Tier 2.
T2

Up to €10,000,000 or 2% of Global Annual Turnover

Applies to breaches of other manufacturer, importer, and distributor obligations.

What triggers Tier 2 (Article 64(3)):

  • Non-compliance with CE marking requirements (Articles 30–31)
  • Failure to draw up or maintain the EU Declaration of Conformity (Article 28)
  • Non-compliance with conformity assessment procedures (Article 32(1), (2) and (3))
  • Failure to appoint an authorised representative where required (Article 18)
  • Failure to comply with importer obligations (Article 19) or distributor obligations (Article 20)
  • Failure to comply with obligations of open-source software stewards (Article 23) or online marketplace operators (Article 22)
Note: Article 14 reporting (actively exploited vulnerabilities) is a Tier 1 offence — see above. Tier 2 covers Articles 18–23, 28, 30–32 per Article 64(3).
T3

Up to €5,000,000 or 1% of Global Annual Turnover

Applies to providing incorrect, incomplete, or misleading information to authorities.

What triggers Tier 3:

  • Providing incorrect or misleading information to market surveillance authorities
  • Providing incomplete documentation in response to an official request
  • Submitting false declarations (e.g., in the EU Declaration of Conformity)
  • Falsely claiming harmonised standard conformity or certification

How Fines Are Actually Calculated

Article 64 sets maximum fines. National MSAs have discretion within these ceilings and must consider mitigating and aggravating factors when determining the actual fine amount.

Mitigating Factors (Reduce Fine)

  • Good faith cooperation with authorities
  • Prompt corrective action once notified
  • First-time violation with no prior record
  • Voluntary disclosure of the issue
  • SME / microenterprise status (see below)
  • Limited severity or scope of the violation
  • No financial gain from the violation

Aggravating Factors (Increase Fine)

  • Repeated or intentional violations
  • Refusal to cooperate with authorities
  • Concealment of non-compliance
  • High risk to users or critical infrastructure
  • Large number of users affected
  • Duration of non-compliance before discovery
  • Financial gain obtained from the violation

SME and Microenterprise Provisions (Article 64(10))

Article 64(10)(a) provides that administrative fines under Article 64(3)-(9) shall not apply to microenterprises and small enterprises for missing the Article 14(2)(a) or 14(4)(a) reporting deadline — this is a genuine, narrow statutory exemption from that specific fine, not merely a procedural accommodation.

EU law requires national authorities to take into account the economic capacity of the operator when setting fine amounts, which in practice means SMEs typically face lower absolute fines than large enterprises for equivalent violations.

EU SME Definition (for reference)

  • Microenterprise: <10 employees, ≤€2M turnover or balance sheet total
  • Small enterprise: <50 employees, ≤€10M turnover or balance sheet total
  • Medium enterprise: <250 employees, ≤€50M turnover or ≤€43M balance sheet total

Penalties for Open Source Software Stewards

OSS stewards have reduced obligations under CRA (Article 24) and correspondingly reduced penalty exposure. Stewards are subject to:

  • Article 64(10)(b) exempts OSS stewards from administrative fines under Article 64(3)-(9) entirely — for any infringement of the Regulation (their obligations are set out in Article 24: cybersecurity policy, cooperation with market surveillance authorities, CVD policy).
  • Stewards are not exempted from the Tier 1 fine under Article 64(2), which covers non-compliance with the Annex I essential requirements and Articles 13/14 — Article 24(3) extends some Article 14 reporting duties to stewards in specific circumstances.
OSS Steward Obligations →

How Non-Compliance Is Discovered

Market surveillance authorities use several mechanisms to identify non-compliant products:

Mkt

Market Sweeps (Article 60)

MSAs can conduct coordinated "sweeps" — simultaneous checks of products in a product category, including purchases under a cover identity — to test compliance with essential requirements. ENISA coordinates joint sweeps across Member States.

Cmp

Complaints From Users or Competitors

Any person — including users, security researchers, or competitors — can report a suspected non-compliant product to the national MSA. Security researcher reports are a common trigger.

Inc

Incidents and Vulnerability Reports

A publicly disclosed vulnerability or security incident can trigger an MSA investigation — especially if the manufacturer failed to report it under Article 14 or failed to patch it promptly.

Doc

Proactive Document Checks

MSAs can request the EU Declaration of Conformity, technical documentation, and SBOM from any manufacturer. Missing, incomplete, or incorrect documentation is itself a Tier 1 or Tier 3 violation.

EU

ICSMS / RAPEX Information Exchange

EU Member States share information about non-compliant products through the ICSMS (Information and Communication System for Market Surveillance) and RAPEX (Rapid Alert System). A finding in one Member State can trigger action in all others.

Enforcement Timeline and Process

When an MSA identifies a potentially non-compliant product, the process typically follows:

1

Initial Assessment

MSA gathers information, may request documentation or testing from the manufacturer/importer.

2

Notification of Concerns

MSA informs the economic operator of the identified concerns and provides an opportunity to respond and take corrective action.

3

Corrective Action Period

Where the risk is not immediate, the operator may be given time to remedy the non-compliance before further action.

4

Formal Enforcement Measures

If non-compliance persists: withdrawal orders, market bans, and/or administrative fines. MSAs notify other Member States via ICSMS.

5

Right of Appeal

Economic operators can challenge MSA decisions through national administrative and judicial channels.

Related Guidance