CRA Fines: The Three Penalty Tiers of Article 64
Updated 20 September 20262 min read
Article 64 of the Cyber Resilience Act sets three tiers of administrative fines. The ceiling does not depend on how serious a vulnerability was. It depends on which obligation was breached.
In every tier, the maximum is whichever is higher: the fixed amount, or the percentage of the undertaking's total worldwide annual turnover for the preceding financial year.
The three tiers
| Paragraph | Maximum | Breach |
|---|---|---|
| 64(2) | €15,000,000 or 2.5% | The essential cybersecurity requirements of Annex I, and the obligations in Articles 13 and 14 |
| 64(3) | €10,000,000 or 2% | Articles 18 to 23, 28, 30(1) to (4), 31(1) to (4), 32(1), (2) and (3), 33(5), and 39, 41, 47, 49 and 53 |
| 64(4) | €5,000,000 or 1% | Supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request |
Reporting sits in the top tier
The Article 14 reporting obligations — in force since 11 September 2026 — fall under paragraph 2. Failing to report an actively exploited vulnerability sits in the same tier as placing on the market a product that does not meet the essential requirements.
How the amount is decided
Article 64(5) lists what authorities take into account, including: - the nature, gravity and duration of the infringement, and its consequences; - whether fines have already been imposed on the same operator for a similar infringement; - the size and market share of the operator — in particular for microenterprises, small and medium-sized enterprises and start-ups.
A ceiling is a maximum, not a price list.
Fines are not the only consequence
Fines may be imposed in addition to corrective or restrictive measures taken by market surveillance authorities for the same infringement. For a small manufacturer, measures affecting whether the product can stay on the market can hurt more than the fine itself.
The small-company exemption — read it twice
Article 64(10) disapplies fines for microenterprises and small enterprises that miss the 24-hour early warning deadline, and for open-source software stewards for any infringement.
But the paragraph opens with "By way of derogation from paragraphs 3 to 9" — and breaches of Article 14 are fined under paragraph 2, which sits outside that range. On a literal reading, neither carve-out reaches the top tier. Most summaries state both exemptions without qualification. This is a question for a lawyer, and a reason not to build any procedure on the exemption.
Sources
- Regulation (EU) 2024/2847, Article 64(2), (3), (4), (5) and (10); Article 14 — Official Journal of the European Union
Position as at 20 September 2026. General information, not legal advice.