CRA penalties and enforcement
Short answer. Article 64 sets three fine ceilings, and which one you are exposed to depends on which duty you breached.
- €15m or 2.5% of worldwide turnover — Annex I security requirements, Article 13, Article 14.
- €10m or 2% — the importer, distributor, CE-marking and notified-body obligations.
- €5m or 1% — giving an authority or notified body wrong, incomplete or misleading information.
In each case it is that euro figure or that percentage, whichever is higher. And Article 64(10) switches administrative fines off entirely in two situations, one of which almost certainly applies to you.
The €15m number is the one every article about this regulation leads with, and it is real. It is also the least useful sentence in Article 64, because a ceiling tells you nothing about what a one-person hardware business in Ireland is actually exposed to. The useful parts of the article are paragraphs 5 and 10, which nobody quotes.
- The three tiers, and what sits in each
- Why “whichever is higher” matters more than the euro figure
- The exemption in Article 64(10)
- What an authority must weigh before setting a fine
- Who actually enforces this
- Fines are not the main risk
- When any of this can first be used against you
- What to do about it
The three tiers, and what sits in each
| Ceiling | What triggers it | In plain terms |
|---|---|---|
| €15 000 000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher | The essential cybersecurity requirements in Annex I, and the obligations in Article 13 and Article 14 | The product was not built or maintained securely, the manufacturer's core duties were not met, or an actively exploited vulnerability or severe incident was not reported |
| €10 000 000 or 2%, whichever is higher | Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1), (2) and (3), Article 33(5), and Articles 39, 41, 47, 49 and 53 | The obligations that sit around the product rather than in it: authorised representatives, importers, distributors, the declaration of conformity, CE marking, conformity assessment procedures and notified bodies |
| €5 000 000 or 1%, whichever is higher | Supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request | You answered a formal request badly — a separate offence from the one they were asking about |
Three things are worth noticing in that table.
First, the top tier is where the manufacturer's own duties live. Annex I is the security requirements and the vulnerability-handling process. Article 13 is the long list of manufacturer obligations — the risk assessment, the technical documentation, the support period, the ten-year retention duties. Article 14 is reporting. If you make the product, the tier you are exposed to is the top one, by default.
Second, the middle tier is the paperwork tier, and it is the one importers, distributors and rebranders should read closely. If you put your own name on somebody else's product you take on manufacturer obligations, but the specific articles that govern importing, distributing and CE marking carry their own €10m exposure.
Third, the bottom tier is the one you can trigger accidentally after the fact. A market surveillance authority sends a reasoned request. You reply from memory, or with the current version of a document rather than the version that governed the units in question, and the answer turns out to be incomplete. That is a separate, independently fineable act. It is also the single strongest practical argument for keeping dated versions of everything rather than one live file — the honest answer to “what did your technical documentation say in March 2028” requires that the March 2028 version still exists.
Why “whichever is higher” matters more than the euro figure
Read the construction carefully: up to EUR 15 000 000 or, if the offender is an undertaking, up to 2.5% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
For a business with turnover under €600 million, 2.5% is less than €15m, so the euro figure is the operative ceiling. The percentage only becomes the binding number for very large companies. Which means the much-repeated “2.5% of turnover” framing is, for essentially every small and mid-sized manufacturer, the lower of the two — and irrelevant, because the ceiling is not what you will be assessed at anyway. That is paragraph 5's job.
Note also total worldwide annual turnover, not EU turnover. A manufacturer selling mostly in Australia or the United States with a small European channel is measured on the whole business. The exposure is sized by what you are, not by how much you sell into the EU.
The exemption in Article 64(10)
This is the paragraph worth knowing, and it is almost never quoted. Article 64(10) disapplies administrative fines for:
- (a) manufacturers that qualify as microenterprises or small enterprises, with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a); and
- (b) any infringement of the Regulation by open-source software stewards.
Point (a) is narrow and specific, and it is aimed squarely at the hardest deadline in the regulation. The deadlines in Article 14(2)(a) and 14(4)(a) are the 24-hour early warnings — the ones that require you to notice an actively exploited vulnerability or a severe incident and file something within a day. If you are a microenterprise or a small enterprise and you miss that 24-hour window, you cannot be administratively fined for missing it.
1. It covers the 24-hour deadline only. The 72-hour notification, the final report and the intermediate reports in the other points of Article 14 are not covered. Miss those and the top-tier exposure is back.
2. It exempts you from the fine, not from the duty. You are still legally required to report. Market surveillance authorities have corrective and restrictive powers — orders to bring a product into conformity, withdrawal, recall — that are independent of fines, and Article 64(9) makes clear that fines sit in addition to those measures rather than replacing them.
3. “Microenterprise” and “small enterprise” are defined terms, taken from the EU's standard SME definition, and the thresholds count headcount, turnover or balance sheet total, and include linked and partner enterprises. If your company is majority-owned by a larger one, you may not qualify even with three employees.
4. The introductory wording of Article 64(10) was corrected after publication. The text as published in the Official Journal read “By way of derogation from paragraphs 3 to 9”. A corrigendum dated 2 July 2025 changed that to “paragraphs 2 to 9”, which widens the derogation to cover paragraph 2 — the €15m tier — as well. Secondary sources reproduce all three versions of this sentence, including at least one that says “3 to 10”. If you are relying on this, read the corrigendum itself, not a summary of the article.
Point (b), the open-source steward exemption, is a different kind of carve-out and is frequently overstated. It exempts stewards — a specific role the Regulation defines, broadly a legal person providing sustained support for the development of open-source products intended for commercial activities — from administrative fines. It is not a blanket statement that open source is outside the regulation, and it does not help a company that ships an open-source-based product commercially. That company is a manufacturer.
What an authority must weigh before setting a fine
Article 64(5) is the paragraph that turns a ceiling into a number. When deciding the amount, the authority must give due regard to:
- the nature, gravity and duration of the infringement and of its consequences;
- whether administrative fines have already been applied by another market surveillance authority for the same infringement; and
- the size of the economic operator — expressly in particular with regard to microenterprises and small and medium-sized enterprises, including start-ups — and its market share.
So the size of your business is not a mitigating plea you get to make; it is a factor the authority is required to weigh. Combined with Article 64(1)'s requirement that penalties be effective, proportionate and dissuasive, the realistic exposure for a small manufacturer with a good-faith compliance effort and an incomplete file is not a headline fine. It is an order to fix it.
Which is exactly why the documentation matters more than the fine schedule. The difference between a business that gets a deadline to remediate and one that gets escalated is usually whether it can demonstrate a process on the day it is asked.
Who actually enforces this
Not the Commission, and not ENISA. Article 64(1) requires each Member State to lay down the rules on penalties applicable to infringements and to take all measures necessary to ensure they are implemented. Enforcement sits with national market surveillance authorities — the same kind of body that already enforces CE marking for radio equipment, EMC and machinery in each country.
Four consequences follow from that, and they are the practical ones:
- The numbers above are ceilings on national law, not a directly applicable tariff. Each Member State legislates its own penalty regime within them, so the same breach can be treated differently in Germany and in Portugal.
- Authorities talk to each other. Article 64(6) requires an authority that applies a fine to communicate that to the market surveillance authorities of other Member States. A problem does not stay in one country.
- Public bodies are a national question. Article 64(7) leaves it to each Member State to decide whether and to what extent fines may be imposed on public authorities and public bodies established there.
- Fines can come from a court rather than an authority. Article 64(8) lets Member States apply the rules so that fines are imposed by competent national courts or other bodies, to fit different legal traditions, provided the effect is equivalent.
Fines are not the main risk
For a small manufacturer, the realistic worst case is not a fine at all. It is the market surveillance toolkit: a requirement to bring the product into conformity within a set period, a restriction on making it available, withdrawal from the market, or recall. Article 64(9) confirms fines may be imposed in addition to those measures — they are not alternatives.
And there is a commercial layer under the legal one that arrives sooner. Your customers' procurement teams will ask for your declaration of conformity, and your distributors have their own Article 20 duties to verify that CE marking and documentation are in place before they sell your product. A distributor who cannot get a declaration of conformity out of you has a legal reason to stop stocking you. In practice that happens long before any authority is involved, and it is the mechanism that will make most manufacturers comply.
When any of this can first be used against you
Timing matters here, and it splits.
Article 14 — reporting — applies from 11 September 2026. It is live. It is also in the top fine tier. So the reporting duty is the one obligation currently capable of producing a top-tier breach, and the 64(10)(a) derogation for micro and small manufacturers is aimed at precisely that duty's hardest deadline.
The rest of the Regulation applies from 11 December 2027. Annex I, Article 13, the declaration of conformity, CE marking, the technical documentation — none of it can be enforced before that date. The deadline is not a grace period in any useful sense, though: the technical file has to describe a product that was designed and built to meet Annex I, and that is not a document you can assemble retrospectively about a product already shipping.
An honest note on confidence: the three fine tiers in paragraphs 2, 3 and 4, and the two derogations in paragraph 10, were each checked against three independent reproductions of the article which agreed on the figures and the wording. Paragraphs 5 to 9 are summarised here from a single reproduction and should be treated as less firmly established. The definition of microenterprise and small enterprise is not set out in Article 64 itself — if your qualification is marginal, that is a question for an adviser who can look at your ownership structure. Nothing here is legal advice.
The cheapest insurance against all three tiers is a file you can produce on the day
Every document the regulation asks for, written for your product, versioned and dated so you can answer a reasoned request with the version that actually applied — which is what keeps a paperwork problem from becoming a second, separately fineable one.
Not sure which tier you are even exposed to? Take the two-minute check — it tells you your class and your route.