CEMarque

What are the penalties for not complying with the EU Cyber Resilience Act?

Last verified 19 September 2026 · Facts v2026.09.4

There are two separate enforcement instruments, and they bite at different times.

The first is administrative fines. Breaching the essential cybersecurity requirements of Annex I, or the manufacturer obligations in Articles 13 and 14, carries fines of up to EUR 15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher [1]. Other listed obligations carry up to EUR 10,000,000 or 2%, and supplying incorrect, incomplete or misleading information to authorities carries up to EUR 5,000,000 or 1% [1].

The second is market action. Market surveillance authorities may require corrective action, restrict availability, or order withdrawal or recall of a product that does not conform [2]. For a small vendor this is often the more frightening instrument: a fine is negotiated after the fact, a sales stop is immediate.

Which duties are enforceable when

The fine ceilings above attach to duties that come into force on two different dates, so exposure is staged.

The reporting duty is enforceable first: from 11 September 2026 a manufacturer must report actively exploited vulnerabilities and severe incidents, and that duty sits in Article 14 — inside the highest fine band [3] [1]. The rest — Annex I essential requirements, technical documentation, CE marking — becomes enforceable when the Regulation applies in full from 11 December 2027 [4] [5] [6].

A product already on the market before full application does not owe conformity until it is substantially modified, but the Article 14 reporting duty applies to it regardless, so there is no fully safe harbour for legacy products [7].

Who the fine lands on

The fine bands are written around the economic operator that breached the duty. For most readers of this page that is the manufacturer, and the manufacturer obligations in Articles 13 and 14 sit in the top band [1]. Importers and distributors have their own listed obligations in the middle band [1].

Two things about proportionality are worth knowing. The percentages are of worldwide turnover, not EU turnover, mirroring how the GDPR ceilings were drawn [1]. And the ceilings are maximums: national authorities impose the actual amounts, weighing the seriousness of the breach, cooperation and prior conduct. A solo developer who made an honest scoping mistake and fixed it is not the target these numbers were written for — but a manufacturer who ignored a reporting duty after 11 September 2026 is squarely inside them [3].

What reduces exposure

Exposure tracks the duties, so the reduction path is mechanical: know whether you are in scope, know your class, and have the reporting path ready before the duty is enforceable — Article 14 readiness first, because that duty is already live from 11 September 2026 [3]. Then the documentation and conformity work on the second clock, applying from 11 December 2027 [4].

Check where you stand

The two-minute checker tells you whether your product is in scope, which duties apply and on which dates, with the exact citation for each answer.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. Fines up to EUR 15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher (essential requirements in Annex I; obligations in Arts. 13 and 14); up to EUR 10,000,000 or 2% (other listed obligations, incl. Arts. 18–23, 28, 30, 31, 32); up to EUR 5,000,000 or 1% (incorrect, incomplete or misleading information to notified bodies or authorities). Microenterprises and small enterprises are not fined for missing the 24-hour early-warning deadline; open-source software stewards are not subject to fines. Art. 64(2)–(4), (10)EUR-Lex
  2. Market surveillance authorities may require corrective action, restriction, withdrawal or recall for non-compliant products. Chapter V (Arts. 52–60)EUR-Lex
  3. Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(2)EUR-Lex
  4. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex
  5. Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m). Annex I Part IEUR-Lex
  6. Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8). Annex I Part IIEUR-Lex
  7. Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless. Art. 69(2)–(3)EUR-Lex

Related

  • Does the CRA apply to products placed on the market before December 2027?

    Partly. Products placed on the market before full application need conformity only if substantially modified after it — but the Article 14 reporting duty applies to them regardless, and ordinary software updates can cross the modification line.

  • Does the CRA require a coordinated vulnerability disclosure policy?

    Yes. Every manufacturer must have a coordinated vulnerability disclosure policy in place, a contact address for reports, a single point of contact for users, and a practice of publishing fixed vulnerabilities.

  • What are the CRA rules on security updates?

    Security updates must be free, timely, securely distributed and accompanied by advisories; consumer products install them automatically by default with an easy opt-out; and the duty runs for the whole declared support period.

  • What goes in the CRA technical file?

    A technical file in the Annex VII structure — product description, design and vulnerability-handling documentation, risk assessment, SBOM, test reports — drawn up before market placement and kept for ten years or the support period.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.