Back to Newsroom
CRA · NexCyber Editorial

€15M or 2.5% — How CRA Fines Are Actually Calculated

Cyber Resilience Act penalties under Article 64 reach €15 million or 2.5% of worldwide annual turnover, with the actual figure determined by documented conduct

The Cyber Resilience Act's headline penalty is the ceiling, not the expectation. What determines the actual figure is documented behaviour, not the breach.

---

The short answer

The Cyber Resilience Act sets a maximum of €15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of the essential requirements and the obligations of manufacturers.

"Whichever is higher" is the part that matters. For a company above €600 million in turnover, the percentage exceeds the fixed sum — and the fixed sum stops being the relevant number entirely.

But the ceiling is not the expectation. What determines the actual figure is conduct you can document.

---

The tiers, because they are not all the same

essential requirements and manufacturer obligations
    €15 000 000  or  2.5%  of worldwide annual turnover

other obligations under the Regulation
    €10 000 000  or  2%

incorrect, incomplete or misleading information
    supplied to notified bodies or authorities
    € 5 000 000  or  1%

The third tier deserves attention out of proportion to its size. It penalises what you *say* to an authority, independently of whether the underlying product was compliant.

A confident answer that turns out to be wrong is a separate exposure from the defect it described. This is the strongest practical argument for saying "we do not know yet, and here is when we will".

---

What actually moves the number

Penalties must be effective, proportionate and dissuasive, and authorities weigh a set of factors that will be familiar to anyone who has read GDPR enforcement decisions:

  • The nature, gravity and duration of the infringement
  • Whether it was intentional or negligent
  • Action taken to mitigate the damage
  • Previous infringements
  • Degree of cooperation with the authority
  • Whether the infringement was self-reported

Every one of these is about behaviour, and most are about documented behaviour. Which produces the practical conclusion:

what you cannot change once it happens   the defect
what you can change                      everything on that list

---

Why "duration" is the line that should worry you most

Duration is measured from when the situation began, not from when you noticed.

A product shipping without a compliant vulnerability handling process for eighteen months has an eighteen-month infringement, whether or not anyone was aware. There is no version of that record that improves later.

Which reverses how most teams prioritise. A dated determination made today is not merely a compliance artefact — it is a boundary on duration. Starting the clock on being right is the cheapest thing you can do about the size of a future penalty.

---

The part nobody puts in the slide deck

Fines are not the primary enforcement tool. Market surveillance authorities can restrict, prohibit, withdraw or recall a non-compliant product from the EU market.

For most companies, a withdrawal is a far larger event than a percentage of turnover. It stops revenue rather than taxing it, it affects customers directly, and it is public.

A penalty calculation that considers only Article 64 is measuring the smaller risk.

---

Who actually pays

Member States set the penalty regime and their authorities apply it. Ceilings are set at EU level; the framework within them is national, and it is not uniform.

Microenterprises and small enterprises get specific consideration, and the Regulation requires authorities to take company size and market share into account. This is real relief, but it is not an exemption — the obligations apply regardless of size, and only the penalty is moderated.

---

Four things that change your exposure this quarter

  1. 1Date your classification. It bounds duration, which is the factor you cannot repair later.
  2. 2Publish the vulnerability disclosure contact. Free, externally verifiable, and directly relevant to the mitigation factor.
  3. 3Decide who can self-report, and give them the authority. Self-reporting is an explicit mitigating factor and it needs a person, not a committee.
  4. 4Never guess in a response to an authority. The third penalty tier exists precisely for that.

---

Calculate your own exposure — free, no account

  • [Penalty calculator](/resources/penalty-calculator) — on your own turnover, across CRA, NIS2, DORA and the AI Act
  • [Free readiness assessment](/assess) — which obligations reach you, and which artefacts are missing

---

Further reading

CRA penaltiesImportant versus critical under the CRAAudit-ready evidence for the CRACRA Article 14 incident reporting

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Penalty regimes are set at Member State level within the EU ceilings and differ between jurisdictions. Verify against the current text and applicable national law, and consult your competent authority or a qualified adviser.*

Want the regulatory deep-dive ?

Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.

Browse Knowledge Base →