Penalties under the Cyber Resilience Act

Last reviewed: 11 September 2026~4 min read

Three bands, topping out at 15 million euro or 2.5% of worldwide annual turnover, whichever is higher. But the fine is rarely the thing that hurts most. Market surveillance authorities can order a product withdrawn or recalled, and a recall of a connected product from the EU market is an existential event for a small manufacturer in a way a fine is not.

The three bands

Penalty bands under Article 64
BreachMaximum
Non-compliance with the essential cybersecurity requirements in Annex I, or with the manufacturer obligations in Articles 13 and 14€15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher
Non-compliance with any other obligation under the regulation€10,000,000 or 2%, whichever is higher
Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities in reply to a request€5,000,000 or 1%, whichever is higher
Note the third band. It penalises the response, not the product. A company that responds to a market surveillance request by overstating what it has done is exposed separately from whatever the original problem was — and that is a self-inflicted, entirely avoidable penalty. If your technical file is incomplete, say so.

What else an authority can do

Fines are one instrument. Under the market surveillance framework an authority can also:

  • Require you to bring the product into conformity within a set period.
  • Restrict or prohibit the product being made available on the market.
  • Order withdrawal from the market or recall from end users.
  • Require the SBOM and the technical documentation on a reasoned request — and a failure to produce them is itself a breach.
  • Inform other Member States, which extends any restriction EU-wide.

How penalties are set

Member States lay down the rules and must make them effective, proportionate and dissuasive. Authorities take into account the nature, gravity and duration of the infringement, whether it was intentional or negligent, action taken to mitigate the damage, previous infringements, the degree of cooperation, and — explicitly — the size and in particular the situation of SMEs and start-ups. That last factor is real, and it is another reason a contemporaneous, honest record of your compliance reasoning is worth building.

Sources