Penalties under the Cyber Resilience Act
Three bands, topping out at 15 million euro or 2.5% of worldwide annual turnover, whichever is higher. But the fine is rarely the thing that hurts most. Market surveillance authorities can order a product withdrawn or recalled, and a recall of a connected product from the EU market is an existential event for a small manufacturer in a way a fine is not.
The three bands
| Breach | Maximum |
|---|---|
| Non-compliance with the essential cybersecurity requirements in Annex I, or with the manufacturer obligations in Articles 13 and 14 | €15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher |
| Non-compliance with any other obligation under the regulation | €10,000,000 or 2%, whichever is higher |
| Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities in reply to a request | €5,000,000 or 1%, whichever is higher |
What else an authority can do
Fines are one instrument. Under the market surveillance framework an authority can also:
- Require you to bring the product into conformity within a set period.
- Restrict or prohibit the product being made available on the market.
- Order withdrawal from the market or recall from end users.
- Require the SBOM and the technical documentation on a reasoned request — and a failure to produce them is itself a breach.
- Inform other Member States, which extends any restriction EU-wide.
How penalties are set
Member States lay down the rules and must make them effective, proportionate and dissuasive. Authorities take into account the nature, gravity and duration of the infringement, whether it was intentional or negligent, action taken to mitigate the damage, previous infringements, the degree of cooperation, and — explicitly — the size and in particular the situation of SMEs and start-ups. That last factor is real, and it is another reason a contemporaneous, honest record of your compliance reasoning is worth building.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.