Guides

CRA penalties: the three tiers and the one people skim

Ceilings, shares of turnover and what each tier covers under the Cyber Resilience Act, plus the costs that arrive long before any regulator does.

Penalty ceilings under the Cyber Resilience Act are set the way they are in other EU product legislation: a fixed amount or a share of worldwide annual turnover, whichever is higher. For a small vendor the fixed amount is the one that bites, because a percentage of a small turnover is small and the ceiling is not.

The three tiers

CeilingShare of turnoverWhat it covers
EUR 15 million2.5%Non-compliance with the essential requirements (Annex I) and with the vulnerability handling and reporting obligations
EUR 10 million2%Non-compliance with any other obligation under the Regulation
EUR 5 million1%Supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities

Whichever is higher, not whichever applies. A company with a turnover of two hundred million pays the percentage; a company with a turnover of two million pays the ceiling. The ceiling is not scaled down for size.

What the third tier is really about

The lowest tier covers supplying incorrect, incomplete or misleading information to notified bodies or market surveillance authorities. It is the one people skim, and it is the one most likely to catch a company that was otherwise trying.

The scenario is not fraud. It is a technical file that describes a version you no longer ship, an SBOM generated from a source tree rather than the release, a declared support period nobody updated. Each is an honest artefact that stopped being true, and each is incorrect information supplied to an authority.

Fines are the visible cost, not the largest one

  • Market surveillance authorities can require corrective action, restrict a product on the market or order its withdrawal. A product pulled from the EU market costs more than the ceiling for most small vendors.
  • Importers and distributors carry their own obligations. When they cannot get documentation from you, the commercially rational move is to stop carrying your product rather than to argue.
  • Enterprise buyers run procurement questionnaires. A no on a compliance question is a lost deal long before any authority has an opinion.

This is the part that changes behaviour. Enforcement is slow and selective; procurement is fast and universal. Most vendors will feel the Regulation through a customer questionnaire years before they hear from a regulator.

Member States set the actual amounts

The Regulation sets ceilings and requires that penalties be effective, proportionate and dissuasive. The rules that apply to you are laid down nationally, and they differ. Treat the ceilings as the outer bound of the risk rather than as the expected outcome, and ask a qualified adviser about your own jurisdiction before you put a number in a board paper.

What reduces exposure in practice

  1. Keep the inventory current, because most obligations downstream of it become mechanical once it exists.
  2. Keep the technical documentation attached to a version rather than to a date, so it cannot describe a product you no longer ship.
  3. Record what you decided and when. An authority asking why you concluded a vulnerability was not exploitable is asking for a contemporaneous record, and one written afterwards reads as one written afterwards.
  4. Report on time even when the answer is incomplete. The early warning exists precisely because you are not expected to know everything within a day.

Keep reading