CRA Penalties (Article 64): Three Tiers, Real Carve-Outs, and What Triggers Each

· Eurtifact Platform Team

Context

The headline figure attached to the EU Cyber Resilience Act in most coverage is “up to €15 million or 2.5% of global turnover.” That is one of three tiers in Article 64, and the structure of the three tiers determines which obligations carry which risk. Article 64 also carves out derogations that are routinely misread — particularly for microenterprises, small enterprises, and open-source software stewards.

The penalty regime applies from full application on 11 December 2027. Member States must have rules and measures in place by then (Article 64(1)). This article walks through the text exactly as published in the Official Journal, identifies what each tier actually covers, and flags the derogations.

Reality Check

Common Belief

“CRA penalties are up to €15 million across the board, with no real exceptions for smaller players or open-source projects.”

Why That’s Incomplete

The €15 million figure is the first tier (Article 64(2)) and applies only to non-compliance with (a) the essential cybersecurity requirements in Annex I and (b) the obligations in Articles 13 and 14. Other tiers apply to other obligations. And Article 64(10) explicitly derogates from paragraphs 3 to 9 for two specific categories: microenterprises and small enterprises (for the 24-hour notification deadline only) and open-source software stewards (for any infringement).

Stating “the CRA can fine open-source stewards up to €15 million” repeats a simplification the OJ text does not support.

Engineering Implications

The Three Tiers

The Regulation states the tiers explicitly. The amounts apply up to the stated cap, with the actual amount determined under Article 64(5) by reference to nature, gravity, duration, prior fines, and the size of the offender (with special attention to microenterprises and SMEs, including start-ups).

Tier 1 — Article 64(2) — up to €15 000 000 or 2.5 % of total worldwide annual turnover (whichever is higher).

Triggered by non-compliance with:

  • The essential cybersecurity requirements set out in Annex I (both Part I — product properties — and Part II — vulnerability handling).
  • The obligations set out in Article 13 — obligations of manufacturers.
  • The obligations set out in Article 14 — reporting obligations of manufacturers.

This is the tier that maps to the substantive cybersecurity duties — getting the product right and reporting when it goes wrong.

Tier 2 — Article 64(3) — up to €10 000 000 or 2 % of total worldwide annual turnover (whichever is higher).

Triggered by non-compliance with the obligations set out in:

  • Articles 18 to 23 — authorised representatives, importers, distributors, application of manufacturer obligations to importers and distributors, identification of economic operators.
  • Article 28 — EU declaration of conformity.
  • Article 30(1) to (4) — rules and conditions for affixing the CE marking.
  • Article 31(1) to (4) — technical documentation.
  • Article 32(1), (2) and (3) — conformity assessment procedures.
  • Article 33(5) — a specific support obligation for microenterprises and SMEs.
  • Articles 39, 41, 47, 49 and 53 — duties of notified bodies (requirements, subcontracting, operational obligations, information duties) and access to data for market surveillance.

This is the tier for supply-chain and assessment duties — distribution, marking, documentation, and the conformity assessment ecosystem.

Tier 3 — Article 64(4) — up to €5 000 000 or 1 % of total worldwide annual turnover (whichever is higher).

Triggered by the supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request.

This tier is narrow and specific: it sanctions lying to regulators. It does not cover refusals or omissions in the underlying compliance work — those fall under tier 1 or tier 2.

How the Cap Is Calculated

Each tier uses the same formula: “up to EUR X 000 000 or, if the offender is an undertaking, up to Y % of its total worldwide annual turnover for the preceding financial year, whichever is higher.” For undertakings, the percentage is often the binding cap; for non-undertakings (e.g., natural persons placing products on the market), the absolute amount applies.

“Worldwide annual turnover” is read consistently across recent EU legislation — it is global, not EU-only.

The Microenterprise and Small Enterprise Derogation

Article 64(10)(a) reads:

“By way of derogation from paragraphs 3 to 9, the administrative fines referred to in those paragraphs shall not apply to the following: (a) manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a).”

Reading this precisely:

  • The derogation is from paragraphs 3 to 9 — which is a curious drafting choice, since the 24-hour deadlines in Article 14(2)(a) and 14(4)(a) are within the Article 14 obligations that paragraph 2 puts in tier 1.
  • The most natural reading is that micro and small enterprises are not subject to administrative fines specifically for the 24-hour early warning deadline. The 72-hour notification, the 14-day final report (vulnerabilities), the one-month final report (incidents), and the rest of Article 14 remain on the table.
  • “Microenterprise” and “small enterprise” follow the definitions in Recommendation 2003/361/EC, incorporated into the CRA by Article 3(19). Heads-of-staff and turnover thresholds apply.

This is a narrow, recognition-of-capacity carve-out — not an exemption from CRA reporting. The cybersecurity duty under Annex I and Article 13 remains.

The Open-Source Software Steward Derogation

Article 64(10)(b) reads:

“(b) any infringement of this Regulation by open-source software stewards.”

This derogates from paragraphs 3 to 9 administrative fines. Paragraph 2 — the €15M/2.5% tier — is not listed in the derogation. However, the underlying obligations that paragraph 2 references (Annex I, Articles 13 and 14) are largely not imposed on open-source software stewards in the first place. Article 24 sets a separate, narrower obligation set for stewards: a cybersecurity policy, cooperation with market surveillance authorities, and assistance to manufacturers integrating their products.

In practice, the combined effect of Article 24’s narrow obligations and Article 64(10)(b)'s derogation is that the Article 64 administrative-fine regime does not apply to open-source software stewards in the form it applies to manufacturers. Other corrective measures by market surveillance authorities under Chapter V may still apply.

Article 64(9): Penalties Are Stackable With Other Corrective Measures

Article 64(9) is short and worth noting:

“Administrative fines may be imposed, depending on the circumstances of each individual case, in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement.”

A withdrawal order, a recall, or a corrective action requirement under Articles 53–58 does not displace the fine. The fine sits on top.

Failure Modes

Pattern 1: Conflating Tier 1 and Tier 2

A team treats every CRA non-compliance as a €15M event. This produces three problems: it overstates risk to leadership (loss of credibility when stakes are misrepresented), it under-prioritises supply-chain duties (because everything looks equally bad), and it mis-sizes engineering investment.

In practice, getting Annex I and Article 14 right reduces tier 1 exposure; getting Articles 18–23, 28, 30–32 right reduces tier 2 exposure. They are different work streams owned by different teams.

Pattern 2: Assuming the SME Carve-Out Is Broader Than It Is

A small manufacturer reads “microenterprises and small enterprises are exempt from fines” and concludes the CRA is a lower priority. The derogation in Article 64(10)(a) covers one specific deadline — the 24-hour early warning under Article 14(2)(a) or 14(4)(a). Every other obligation remains, and the tier 1 penalty (Article 64(2)) is not in the derogation list.

The CRA does build in proportionality elsewhere — Article 33 requires Member States to provide support for SMEs and start-ups, including regulatory sandboxes, simplified technical documentation, and reduced fees. But that is a support mechanism, not a fine exemption.

Pattern 3: Open-Source Project Acting as Manufacturer Without Knowing It

A team maintains an open-source project commercially — sells subscriptions, support, hardened distributions. The team thinks the Article 24 open-source software steward regime applies. It does not. Article 24 explicitly covers entities that are not manufacturers and that support FOSS development in a sustained way without commercial activity in respect of the FOSS itself.

If the same entity places a hardened version on the market for payment, that entity is a manufacturer for that product, with full Article 13/14 obligations and full Article 64 fine exposure. The legal status depends on the specific product and activity, not on the project’s open-source heritage.

Pattern 4: Inaccurate Information to Regulators

Under pressure during an incident, a team submits a 72-hour notification with an over-confident assessment of root cause. The actual root cause turns out to be different. Article 64(4) sanctions “incorrect, incomplete or misleading” information to notified bodies and market surveillance authorities — a separate tier 3 offence on top of any underlying compliance failure.

The mitigation is to mark uncertainty explicitly. Article 14 contemplates phased notifications precisely because perfect information is not available at the 24-hour or 72-hour marks. Honest uncertainty is not “misleading”; over-confident assertion is.

What “Good” Looks Like

A manufacturer with a defensible posture on Article 64 has:

  1. A clear classification by tier of every CRA obligation: For each duty in the Regulation, an internal owner knows which tier governs penalty exposure and what evidence demonstrates compliance.

  2. A documented assessment of business-form status: Are we a manufacturer? An importer? A distributor? An authorised representative? An open-source software steward? For each product, this is unambiguous and dated. The penalty regime depends on the answer.

  3. A defensible SME analysis if applicable: If the organisation qualifies as a microenterprise or small enterprise, the qualification is documented under Recommendation 2003/361/EC, including the treatment of partner and linked enterprises (Article 6 of the Annex to the Recommendation).

  4. Regulator-communication discipline: Submissions to notified bodies and market surveillance authorities go through a defined process that flags uncertainty, separates fact from assessment, and is reviewable. Article 64(4) penalties target communications, not underlying conduct.

  5. A worst-case scenario understanding: Leadership has been briefed on tier 1 (€15M/2.5%) exposure for the specific obligations it covers — Annex I, Article 13, Article 14 — not as a catch-all number. This grounds investment decisions in the actual penalty surface.

Limits & Trade-offs

This does not:

  • Predict enforcement appetite: Article 64 sets caps. The amount in any specific case depends on Member State enforcement choices, the criteria in Article 64(5), and prior practice. National regulators have wide discretion within the caps.
  • Cover criminal sanctions: Article 64 is administrative. Some Member States may pursue criminal liability for related conduct under national law. That is outside the CRA’s harmonised scope.
  • Address private actions: Article 65 provides for representative actions under Directive (EU) 2020/1828. Class-style claims by consumers are a separate exposure surface, not in scope here.
  • Settle the legal status of complex business models: A platform that hosts third-party container images may simultaneously be a distributor (for some images) and a manufacturer (for its own builds). The penalty regime depends on the role for each specific transaction. Qualified legal counsel is essential for borderline cases.

Key Takeaways

  • Article 64 has three tiers — €15M/2.5%, €10M/2%, €5M/1% — each covering specific obligations. The €15M figure is the cap for substantive cybersecurity duties (Annex I, Articles 13 & 14), not for every CRA non-compliance.
  • The carve-out for microenterprises and small enterprises is narrow: it covers only the 24-hour early warning deadline in Article 14(2)(a) or 14(4)(a). Other obligations and tier 1 fines still apply.
  • Open-source software stewards under Article 24 have a narrower obligation set and are derogated from administrative fines under paragraphs 3-9. They are not subject to Article 64 in the form manufacturers are.
  • Fines stack with other corrective measures (Article 64(9)). A recall, withdrawal, or corrective action does not displace the penalty.
  • Article 64(4)'s tier 3 — for incorrect, incomplete or misleading information to regulators — is a separate offence triggered by communications, not by underlying compliance failures. It rewards honest uncertainty over confident error.

This article reflects the Eurtifact platform team’s reading of the Cyber Resilience Act as of May 2026. Article and Annex references were verified against the consolidated EUR-Lex text (CELEX 32024R2847) and are linked to the on-site CRA explorer. It is not legal advice. For obligations specific to your products or organisation, consult qualified legal counsel.