Enforcement
CRA fines explained: €15M, €10M, and who owes which
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
The Cyber Resilience Act's headline number (fines "up to €15 million") is accurate but incomplete. Article 64 sets two brackets, and which one applies depends on what you are in the supply chain.
Bracket one: essential requirements and core manufacturer duties
“administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover” (Art. 64(2), verbatim from the OJ text, CELEX 32024R2847)
This bracket covers breaches of the essential cybersecurity requirements (Annex I) and the obligations in Articles 13–14: secure-by-default configuration, vulnerability handling, SBOM, and, critically, the reporting duties that apply from 11 September 2026.
Bracket two: operator obligations
| Role | Duties under | Maximum fine |
|---|---|---|
| Manufacturer | Annex I, Art. 13–14 | €15,000,000 or 2.5% of worldwide annual turnover |
| Importer / distributor | Art. 20–23 et seq. | €10,000,000 or 2% of worldwide annual turnover |
Three things worth noticing
- "Whichever is higher." For an undertaking with global turnover above roughly €600M, the percentage exceeds the fixed cap: the exposure scales with size.
- The reporting clock is already running. Bracket-one liability includes Art. 14 reporting, which applies from 11 September 2026, well before full application in December 2027.
- Resellers aren't off the hook. Distributor due-care duties sit in bracket two; knowingly supplying non-compliant products is a compliance failure on its own.
Which bracket are you in? Run the free Cybiq check: your role determines your duties, your duties determine your exposure, and every claim comes with the Official Journal citation.
Orientation, not legal advice. Member States set national penalty rules under Art. 64(1); verify locally before relying on any figure.