Are manufacturers legally liable under the Cyber Resilience Act when a vulnerability occurs?
Also asked
- Can a company be sued if a CRA-compliant product is hacked?
- Does the CRA create strict liability for zero-day vulnerabilities?
- How do market surveillance authorities determine CRA fine amounts?
Manufacturers face regulatory liability and administrative fines under Article 64 of Regulation (EU) 2024/2847 when they breach essential requirements, fail to maintain technical documentation, or miss Article 14 statutory reporting deadlines. The regulation does not establish strict liability for the mere existence of a vulnerability. Instead, authorities penalise failures of cybersecurity diligence, absent vulnerability handling procedures, and failure to notify ENISA and designated CSIRTs within 24 hours of becoming aware of active exploitation. Completing conformity assessments and documenting ongoing vulnerability handling directly mitigates penalty exposure under statutory proportionality criteria.
The CRA regulates diligence, processes, and disclosure rather than guaranteeing total immunity from security flaws. Documenting each conformity artifact is the primary legal defence.
Key takeaways
- The Cyber Resilience Act does not impose strict liability for the mere existence of a discovered vulnerability.
- Administrative penalties penalise substantive non-conformity with Annex I and failures to report actively exploited flaws under Article 14.
- Proportionality criteria under Article 64 require authorities to consider documented compliance diligence and prompt remediation.
- Operating an active coordinated vulnerability disclosure policy and maintaining the technical file directly mitigate fine exposure.
At a glance
- Strict liability
- Not established; CRA penalises procedural and diligence failures
- Article 14 reporting
- Fines apply for missing 24h early warning or 72h notification
- Annex I breach
- Tier 1 penalty up to €15,000,000 or 2.5% of annual turnover
- Mitigating factors
- Documented conformity and prompt remediation mitigate fines
Last reviewed 11 September 2026
Verified against Regulation (EU) 2024/2847 Articles 13, 14, and 64 as published in OJ L, 20.11.2024, verified on EUR-Lex on 11 September 2026.
Diligence obligations rather than strict flawlessness
The Cyber Resilience Act establishes an obligation of cybersecurity diligence across the product lifecycle rather than strict liability for every software defect. Under Article 13 and Annex I, manufacturers must design, develop, and produce products in line with the essential cybersecurity requirements, maintain a vulnerability handling procedure, and supply security updates during the support period.[2]
When a zero-day vulnerability surfaces, market surveillance authorities investigate whether the manufacturer implemented appropriate state-of-the-art security controls during development, maintained a software bill of materials, and coordinated disclosure under Article 13. A manufacturer that documented its risk assessment and responded promptly to disclosure operates within regulatory compliance.
When regulatory liability and administrative fines trigger
Statutory liability under Article 64 triggers upon specific infringements of the Regulation. Article 64(2) assigns the highest tier of administrative fines—up to €15,000,000 or 2.5% of total worldwide annual turnover—to non-compliance with the essential requirements in Annex I, general manufacturer obligations in Article 13, and statutory notification obligations in Article 14.[1]
Failing to notify ENISA and the designated national CSIRT within 24 hours of becoming aware of an actively exploited vulnerability is an explicit breach under Article 14(1) and Article 64(2). The penalty applies to the failure to report, regardless of whether the underlying flaw was intentional or inadvertent.[3]
How documented conformity lowers penalty exposure
Article 64 requires penalties to be effective, proportionate, and dissuasive. In assessing fine levels, market surveillance authorities weigh the degree of diligence, the actions taken to mitigate damage, and the cooperation shown with competent authorities.[1]
Maintaining the five core conformity artifacts—product classification, the Annex I assessment, the Annex VII technical file, the EU Declaration of Conformity, and an operational Article 14 reporting intake—proves statutory diligence. Completing these artifacts eliminates procedural breach exposure under Article 64(3) and substantiates good-faith compliance under Article 64(2).
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 64(1) to (4) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
- [2]
Publications Office of the European Union · Article 13(1) to (14) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
- [3]
Publications Office of the European Union · Article 14(1) to (8) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
The provisions behind this answer
Terms used in this answer
This answer is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.