Cyber Resilience Act fines and penalties: the cost of non-compliance
By the QuantumSec team
The Cyber Resilience Act is not a recommendation or a voluntary framework. It is a European regulation with a specific penalty regime that can reach 15 million euros or 2.5% of the company's total annual global turnover — whichever is higher. And it does not only affect manufacturers: importers and distributors can also be sanctioned. This guide details the three penalty tiers, which violations trigger them, who can be sanctioned and how to mitigate the risk.
The CRA's three penalty tiers
The CRA establishes three maximum penalty tiers according to the severity of the infringement.
Tier 1 — Breach of essential requirements: up to €15,000,000 or 2.5% of total annual worldwide turnover for the preceding financial year, whichever is higher. Triggered by: failure to comply with Annex I requirements; placing a non-assessed product on the market; or falsifying technical documentation.
Tier 2 — Breach of other obligations: up to €10,000,000 or 2% of total annual worldwide turnover. Triggered by: failure to notify ENISA of actively exploited vulnerabilities within the required timeframes (24/72 hours); no coordinated vulnerability disclosure policy; failure to provide security instructions to users; or failure to cooperate with market surveillance authorities.
Tier 3 — Incorrect information: up to €5,000,000 or 1% of total annual worldwide turnover. Triggered when incorrect, incomplete or misleading information is provided to authorities or users regarding CRA compliance.
Who can be sanctioned: manufacturers, importers and distributors
The CRA's penalty regime does not only affect the manufacturer. Three actors share responsibility.
Manufacturer: the primary responsible party. It must design the product to meet Annex I, carry out the conformity assessment, issue the EU declaration of conformity and manage vulnerabilities throughout the lifecycle. Most infringements and the severest penalties fall on the manufacturer.
Importer: a company placing products manufactured outside the EU on the European market must verify that the manufacturer completed the conformity assessment, that the product bears the CE marking and that the declaration of conformity is available.
Distributor: companies distributing the product on the EU market without being manufacturer or importer must verify the CE marking and that documentation is in order before distribution.
The most likely violations in practice
Violations most likely to generate penalties in the first years of enforcement:
Identical default passwords: having the same factory credentials across all devices of a model is a direct violation of the secure-by-default requirement — the most frequent vulnerability in IoT devices and consumer routers.
No security update process: products with no update mechanism, that charge for security updates, or whose security support cycle is under five years without justification.
Breach of the ENISA notification deadline: failing to notify an actively exploited vulnerability within 24 hours is one of the most easily verifiable Tier 2 violations.
No vulnerability disclosure policy: lacking a published CVD policy and a reporting channel for security researchers is easily verifiable.
Marketing products with known, documented vulnerabilities: if a product has a known NVD/ENISA vulnerability without a published patch for months, the market surveillance authority has grounds to open a penalty procedure.
The authorities that can impose sanctions
The CRA is a European regulation, but enforcement and penalties are the responsibility of each Member State's national market surveillance authority. These authorities can: request information from manufacturers, importers and distributors; order the withdrawal of products posing a significant cybersecurity risk; impose corrective measures; and propose and impose administrative sanctions. Products considered to pose a significant risk may be subject to a RAPEX notification, resulting in withdrawal from all EU markets simultaneously.
How to reduce the penalty risk
The best protection against the CRA's penalty regime is early and documented compliance. The measures that most reduce penalty risk: completing the conformity assessment before 11 December 2027; having an ENISA notification process operational before 11 August 2026; publishing a CVD policy and a vulnerability reporting channel; maintaining an updated SBOM to respond within hours when a new CVE affecting your dependencies is published; and retaining for 10 years the complete technical documentation evidencing the conformity assessment process.
FAQ
Are CRA penalties cumulative with those under NIS2 or the GDPR?
Yes. The CRA, NIS2 and the GDPR are separate regulations with independent penalty regimes. A security incident involving a product vulnerability can simultaneously trigger CRA penalties (for failing to notify ENISA in time), GDPR penalties (for the resulting personal data breach) and NIS2 penalties (if the affected party is an essential services operator).
Can the CRA generate civil liability towards affected users?
The CRA establishes administrative penalties, not direct civil liability. However, in many Member States non-compliance with regulatory security requirements may be relevant in civil liability proceedings. If a manufacturer places a product knowing it does not meet the CRA requirements and that product is exploited causing harm to a user, non-compliance may be used as evidence of negligence.
Can a startup with limited resources afford CRA compliance?
The CRA is designed to be proportionate to company size. The most demanding assessment procedures (involving notified bodies) only apply to Class II products. For most small-company products, self-assessment is sufficient and the main cost is engineering time to implement the Annex I controls, plus SBOM and dependency vulnerability analysis tooling — which in many cases offer free plans for small projects.