Stavenor

Guides

CRA Fines: The Three Penalty Tiers of Article 64

Updated 20 September 20262 min read

Article 64 of the Cyber Resilience Act sets three tiers of administrative fines. The ceiling does not depend on how serious a vulnerability was. It depends on which obligation was breached.

In every tier, the maximum is whichever is higher: the fixed amount, or the percentage of the undertaking's total worldwide annual turnover for the preceding financial year.


The three tiers

Paragraph Maximum Breach
64(2) €15,000,000 or 2.5% The essential cybersecurity requirements of Annex I, and the obligations in Articles 13 and 14
64(3) €10,000,000 or 2% Articles 18 to 23, 28, 30(1) to (4), 31(1) to (4), 32(1), (2) and (3), 33(5), and 39, 41, 47, 49 and 53
64(4) €5,000,000 or 1% Supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request

Reporting sits in the top tier

The Article 14 reporting obligations — in force since 11 September 2026 — fall under paragraph 2. Failing to report an actively exploited vulnerability sits in the same tier as placing on the market a product that does not meet the essential requirements.


How the amount is decided

Article 64(5) lists what authorities take into account, including: - the nature, gravity and duration of the infringement, and its consequences; - whether fines have already been imposed on the same operator for a similar infringement; - the size and market share of the operator — in particular for microenterprises, small and medium-sized enterprises and start-ups.

A ceiling is a maximum, not a price list.


Fines are not the only consequence

Fines may be imposed in addition to corrective or restrictive measures taken by market surveillance authorities for the same infringement. For a small manufacturer, measures affecting whether the product can stay on the market can hurt more than the fine itself.


The small-company exemption — read it twice

Article 64(10) disapplies fines for microenterprises and small enterprises that miss the 24-hour early warning deadline, and for open-source software stewards for any infringement.

But the paragraph opens with "By way of derogation from paragraphs 3 to 9" — and breaches of Article 14 are fined under paragraph 2, which sits outside that range. On a literal reading, neither carve-out reaches the top tier. Most summaries state both exemptions without qualification. This is a question for a lawyer, and a reason not to build any procedure on the exemption.

Sources

Position as at 20 September 2026. General information, not legal advice.