Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What are the CRA penalty ceilings, and who enforces them?
Last verifiedArticle 64 of Regulation (EU) 2024/2847 sets three administrative-fine ceilings (EUR 15 000 000 or 2,5 %, EUR 10 000 000 or 2 %, EUR 5 000 000 or 1 %). Those are statutory maxima, not typical fines. This page is not legal advice and does not start a clock.
CRA penalties and enforcement guide, last verified 9 September 2026 against Regulation (EU) 2024/2847 Article 64 (including the 2 July 2025 corrigendum to Article 64(10)), Chapter V Articles 52, 54 and 58, and Article 71, the European Commission's CRA pages (Commission materials, not the regulation), and ENISA product-security materials (agency guidance, not the regulation). It is not legal advice, not a fine, not a market-surveillance decision, not a determination that the CRA applies, and not a substitute for counsel. This product does not issue fines.
This is Article 64 maxima, not YOUR fine
Audience: a founder, legal owner, CTO, or compliance lead at an organisation that might make products with digital elements available on the Union market. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that an infringement has occurred, or that a fine, withdrawal, or recall is due.
The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. Article 64 is in Chapter VII (confidentiality and penalties). Chapter V (Articles 52 to 60) is market surveillance and enforcement. This page quotes those articles. It does not apply them to YOU. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 52, 54, 58, 64 and 71 are legal requirements only if they apply. Commission CRA pages are Commission materials — guidance, not the regulation. ENISA product-security materials are agency guidance, not the regulation. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the ladder under breach reporting.
- A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.
- Those figures are statutory maxima, not typical fines, and not a prediction. This product does not issue fines, does not withdraw or recall a product, and is not a market surveillance authority.
Penalty-tier table — Article 64 ceilings, not typical fines
Last verified 9 September 2026 against Article 64 on EUR-Lex. The table quotes the three administrative-fine limbs and the Member-State rule in Article 64(1). The amounts are ceilings. They are not typical fines, not a tariff, and not a prediction of what an authority would impose. This product does not issue fines. Not legal advice.
| Limb | Ceiling | Kind of text | What this page does not do |
|---|---|---|---|
| Article 64(1) — Member States lay down the rules | No euro amount. Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall, without delay, notify the Commission of those rules and measures and shall notify it, without delay, of any subsequent amendment affecting them. | Legal requirement — Article 64(1). Only if the CRA applies. | Does not write YOUR Member State's implementing rules. Does not find that a penalty is due. |
| Article 64(2) — Annex I essential requirements and Articles 13 and 14 | Non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 2,5 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. | Legal requirement — Article 64(2). Statutory maximum, not a typical fine. | Does not find that YOU failed Annex I, Article 13, or Article 14. Does not compute YOUR turnover. Does not issue that fine. |
| Article 64(3) — listed other obligations | Non-compliance with the obligations set out in Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1), (2) and (3), Article 33(5), and Articles 39, 41, 47, 49 and 53 shall be subject to administrative fines of up to EUR 10 000 000 or, if the offender is an undertaking, up to 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. | Legal requirement — Article 64(3). Statutory maximum, not a typical fine. | Does not run those listed articles for YOU. Does not treat this ceiling as a typical amount. |
| Article 64(4) — incorrect, incomplete or misleading information | The supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request shall be subject to administrative fines of up to EUR 5 000 000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. | Legal requirement — Article 64(4). Statutory maximum, not a typical fine. | Does not find that YOUR information was incorrect, incomplete, or misleading. Does not issue that fine. |
Who enforces — Member States and market surveillance, not this product
Article 64(1) puts the penalty rules on Member States. Chapter V puts market surveillance on designated authorities. This page quotes those articles. It does not name YOUR authority and does not invent enforcement practice. Last verified 9 September 2026. Not legal advice.
| Mechanism | What the cited text says | Kind of text | What this page does not do |
|---|---|---|---|
| Market surveillance authorities — Article 52 | Article 52(1): Regulation (EU) 2019/1020 shall apply to products with digital elements that fall within the scope of this Regulation. Article 52(2): each Member State shall designate one or more market surveillance authorities for the purpose of ensuring the effective implementation of this Regulation. Member States may designate an existing or new authority to act as market surveillance authority for this Regulation. Article 52(3): those authorities are also responsible for market surveillance of open-source software steward obligations in Article 24. | Legal requirement — Article 52. Chapter V. | Does not name YOUR market surveillance authority. Does not treat this product as one. |
| Corrective action, withdrawal, recall — Article 54(1) | Article 54(1): where the market surveillance authority of a Member State has sufficient reason to consider that a product with digital elements, including its vulnerability handling, presents a significant cybersecurity risk, it shall, without undue delay and, where appropriate, in cooperation with the relevant CSIRT, carry out an evaluation of the product with digital elements concerned in respect of its compliance with all the requirements laid down in this Regulation. Where, in the course of that evaluation, the market surveillance authority finds that the product with digital elements does not comply with the requirements laid down in this Regulation, it shall without delay require the relevant economic operator to take all appropriate corrective actions to bring the product with digital elements into compliance with those requirements, to withdraw it from the market, or to recall it within a reasonable period, commensurate with the nature of the cybersecurity risk, as the market surveillance authority may prescribe. Article 18 of Regulation (EU) 2019/1020 shall apply to the corrective actions. | Legal requirement — Article 54(1). Chapter V. Not typical-practice statistics. | Does not find that YOUR product presents a significant cybersecurity risk. Does not withdraw or recall it. |
| Provisional MSA measures — Article 54(5) | Article 54(5): where the economic operator does not take adequate corrective action within the period referred to in paragraph 1, second subparagraph, the market surveillance authority shall take all appropriate provisional measures to prohibit or restrict that product with digital elements from being made available on its national market, to withdraw it from that market or to recall it. That authority shall notify the Commission and the other Member States, without delay, of those measures. | Legal requirement — Article 54(5). Chapter V. | Does not prohibit YOUR product. Does not invent how often this is used. |
| Formal non-compliance — Article 58 | Article 58(1): where the market surveillance authority of a Member State makes one of the following findings, it shall require the relevant manufacturer to put an end to the non-compliance concerned: (a) the CE marking has been affixed in violation of Articles 29 and 30; (b) the CE marking has not been affixed; (c) the EU declaration of conformity has not been drawn up; (d) the EU declaration of conformity has not been drawn up correctly; (e) the identification number of the notified body which is involved in the conformity assessment procedure, where applicable, has not been affixed; (f) the technical documentation is either not available or not complete. Article 58(2): where the non-compliance referred to in paragraph 1 persists, the Member State concerned shall take all appropriate measures to restrict or prohibit the product with digital elements from being made available on the market or ensure that it is recalled or withdrawn from the market. | Legal requirement — Article 58. Chapter V. Formal, documentary non-compliance — not a typical-fine statistic. | Does not find that YOUR CE marking, EU declaration of conformity, or technical documentation is missing. Readiness in this product is not CE marking. |
| Fines in addition to other measures — Article 64(9) | Article 64(9): administrative fines may be imposed, depending on the circumstances of each individual case, in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement. | Legal requirement — Article 64(9). A ceiling and a corrective measure can sit together. That is not a typical combined amount. | Does not stack a fine and a recall for YOU. Does not issue either. |
How an amount is decided — Article 64(5), not a typical-fine table
Article 64(5): when deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following: (a) the nature, gravity and duration of the infringement and of its consequences; (b) whether administrative fines have been already applied by the same or other market surveillance authorities to the same economic operator for a similar infringement; (c) the size, in particular with regard to microenterprises and small and medium sized-enterprises, including start-ups, and the market share of the economic operator committing the infringement. That is how the regulation says an amount is decided. It is not a table of typical fines. This page does not invent one. Last verified 9 September 2026. Not legal advice.
Article 64(6): market surveillance authorities that apply administrative fines shall communicate that application to the market surveillance authorities of other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020. Article 64(7): each Member State shall lay down rules on whether and to what extent administrative fines may be imposed on public authorities and public bodies established in that Member State. Article 64(8): depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or other bodies according to the competences established at national level in those Member States. This page does not map YOUR Member State's court path.
Article 64(10) derogations — quoted, not a safe harbour from this product
Article 64(10), as corrected by the 2 July 2025 corrigendum (OJ L 90555, 2.7.2025): by way of derogation from paragraphs 2 to 9, the administrative fines referred to in those paragraphs shall not apply to the following: (a) manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a); (b) any infringement of this Regulation by open-source software stewards. That is the legal requirement. Recital 120 (a recital, not an operative article) records that Member States should not impose other kinds of penalties with pecuniary character on those entities, subject to the principle that penalties should be effective, proportionate and dissuasive. This page does not classify YOU as a microenterprise, small enterprise, or open-source software steward. Last verified 9 September 2026. Not legal advice.
When Article 64 applies — Article 71, not YOUR dates
Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Article 64 is not in those two exceptions. Chapter V market surveillance is not in those two exceptions. This page quotes those dates. It does not decide whether an Article 14 infringement before 11 December 2027 is subject to an Article 64(2) fine. Counsel applies Articles 64 and 71 to YOUR facts. This page does not start a clock. Last verified 9 September 2026. Not legal advice.
Legal requirement versus Commission and ENISA guidance
The table below labels each text. Do not treat guidance as the article, and do not treat a ceiling as a typical fine because a summary exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Articles 52, 54, 58, 64 and 71 | Legal requirement — the regulation, only if it applies. Article 64 ceilings are statutory maxima, not typical fines. | Does not apply those articles to YOU. Does not issue a fine. |
| Corrigendum of 2 July 2025 (OJ L 90555) to Article 64(10) | Corrigendum to the regulation. Legal requirement as corrected. | Does not classify YOU under Article 64(10). |
| European Commission CRA policy page and CRA summary page | Commission materials. Guidance, not the regulation. The EUR-Lex summary restates that non-compliance can result in fines of up to 2,5 % of worldwide annual turnover, prohibiting or restricting availability, or ordering withdrawal or recall. That summary is not Article 64. | Does not treat a Commission summary as a typical-fine statistic. |
| ENISA product-security pages | Agency guidance on product security. Not the regulation. Not a fine schedule. | Does not treat an ENISA page as starting YOUR clock or setting YOUR fine. |
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026. Full application, including Article 64 and Chapter V unless counsel says another article moves a duty, remains 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that a fine is due, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test. The who-is-covered guide on this site is the economic-operator roles page. Marking CRA in an obligation map is not that determination.
- Read the Article 64 limbs as statutory maxima, not typical fines. This product does not issue fines.
- If counsel says Chapter V may apply, treat withdrawal, recall, and formal non-compliance as quoted powers of a market surveillance authority — not a prediction of practice, and not a power of this product.
- Do not treat Commission or ENISA guidance as Article 64. Do not treat an in-scope mark as changing a ceiling. A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a fine, and not YOUR enforcement file. Walk it with counsel. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page.
- Does the CRA apply? Product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test.
- Which Article 64 limb, if any — 64(2), 64(3), or 64(4)? Those are ceilings, not typical fines. This page does not place YOUR conduct.
- Does Article 64(10) apply? Microenterprise or small-enterprise Article 14(2)(a) / 14(4)(a) deadline, or an open-source software steward infringement. This page does not classify YOU.
- Who enforces? Member States under Article 64(1); designated market surveillance authorities under Article 52; withdrawal and recall under Article 54; formal non-compliance under Article 58. This product does not issue fines.
- Article 71(2) dates: Article 14 from 11 September 2026; the rest from 11 December 2027. This page does not start a clock and does not decide the Article 64 start for an Article 14 infringement.
- Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not issue CRA fines, does not withdraw or recall a product, does not act as a market surveillance authority, does not start an Article 14 clock, and does not file with a CSIRT or ENISA. An in-scope mark does not change an Article 64 ceiling. None of the surfaces below is a fine, a withdrawal, or a market-surveillance determination.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that the CRA applies, and does not file with a CSIRT or ENISA. A named human still submits.
The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not CE marking and not a market-surveillance determination. The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. That mark is not a determination that the CRA applies, not a determination that you are a manufacturer, and not a change to an Article 64 ceiling. The cyber risk register lives under Security. None of those surfaces issues a fine.
This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Article 64 (penalties; Chapter VII) and Chapter V Articles 52, 54 and 58 (market surveillance and enforcement), plus Article 71, is a legal requirement only if it applies. Article 64(1): Member States shall lay down the rules on penalties; the penalties provided for shall be effective, proportionate and dissuasive. Article 64(2)–(4) set the three administrative-fine ceilings quoted above. Article 64(10) as corrected on 2 July 2025 (OJ L 90555) is the derogation for certain microenterprise and small-enterprise Article 14 deadline failures and for open-source software stewards. Article 14 applies from 11 September 2026; the rest from 11 December 2027 (Article 71(2)). The European Commission's CRA policy page and CRA summary page are Commission materials, not the regulation. ENISA's product-security pages are agency guidance, not the regulation. These are not a complete world list. Not legal advice.
The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the platform-flow page. The CSIRT guide on this site is the coordinator-interaction page. The vulnerability-disclosure guide on this site is the coordinated-disclosure page. The evidence-retention guide on this site is the keep-period page. A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.