What specific violations trigger administrative fines and penalties under CRA Article 64?
Also asked
- Can a company face multiple Article 64 fines for the same product?
- How are CRA fines scaled for small and medium-sized enterprises?
- What market surveillance authority issues CRA administrative fines?
Administrative fines under Article 64 follow a three-tier statutory structure based on the category of infringement. Tier 1 imposes fines up to €15,000,000 or 2.5% of worldwide turnover for breaches of Annex I essential requirements, Article 13 obligations, or Article 14 statutory reporting duties. Tier 2 applies penalties up to €10,000,000 or 2% for non-compliance with conformity assessment procedures, CE marking rules, technical documentation mandates, or distributor obligations. Tier 3 levies up to €5,000,000 or 1% for providing false or misleading information to market surveillance authorities.
Fines are issued by Member State market surveillance authorities under national procedural law and must remain proportionate to company scale and breach severity.
Key takeaways
- CRA Article 64 establishes three graduated tiers of administrative fines scaling with company size and violation severity.
- Substantive failures under Annex I and missed Article 14 24-hour notifications trigger the highest penalty tier of €15,000,000 or 2.5%.
- Procedural violations including absent technical files or missing Declarations of Conformity trigger Tier 2 fines up to €10,000,000 or 2%.
- Providing incomplete or misleading compliance documentation to authorities attracts Tier 3 fines up to €5,000,000 or 1%.
At a glance
- Tier 1 fine cap
- €15,000,000 or 2.5% of worldwide turnover (Article 64(2))
- Tier 1 breaches
- Annex I essential requirements, Article 13, and Article 14 reporting
- Tier 2 fine cap
- €10,000,000 or 2% of worldwide turnover (Article 64(3))
- Tier 2 breaches
- Conformity assessment, technical documentation, CE marking, DoC
- Tier 3 fine cap
- €5,000,000 or 1% of worldwide turnover (Article 64(4))
- Tier 3 breaches
- Misleading or false information provided to authorities
Last reviewed 11 September 2026
Verified against Regulation (EU) 2024/2847 Articles 28, 31, and 64 as published in OJ L, 20.11.2024, verified on EUR-Lex on 11 September 2026.
Tier 1: Substantive security and statutory reporting breaches
Article 64(2) establishes the highest administrative penalty tier, capping fines at €15,000,000 or 2.5% of total worldwide annual turnover in the preceding financial year, whichever is higher.[1]
This tier applies directly to three critical areas:
- Essential cybersecurity requirements set out in Annex I Part I (security properties including secure default configurations, access protection, and data confidentiality).
- Vulnerability handling obligations set out in Annex I Part II (software bill of materials, coordinated vulnerability disclosure, and security update mechanisms).
- Manufacturer obligations under Article 13 and statutory reporting obligations under Article 14 (submitting the 24-hour early warning and 72-hour notification for actively exploited flaws).
Tier 2: Procedural and conformity documentation failures
Article 64(3) sets mid-tier fines of up to €10,000,000 or 2% of global annual turnover for procedural and technical documentation violations.[1]
Key triggers include:
- Failure to draw up and maintain technical documentation under Article 31 and Annex VII.[2]
- Failure to draw up or update an EU Declaration of Conformity under Article 28, or placing CE marking without completing conformity assessment.[3]
- Non-compliance with conformity assessment procedures under Article 32 (for instance, conducting internal self-assessment when a notified body is mandatory).
- Violations of importer obligations under Article 19 or distributor obligations under Article 20.
Tier 3: Misleading information and authority cooperation
Article 64(4) imposes fines of up to €5,000,000 or 1% of global annual turnover for supplying incorrect, incomplete, or misleading information to market surveillance authorities or notified bodies.[1]
Market surveillance relies on verifiable technical documentation and honest disclosures. Providing fabricated risk assessments, incomplete SBOMs, or misleading mitigation claims constitutes a separate statutory violation under this tier, in addition to any underlying substantive failure.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 64(1) to (4) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
- [2]
Publications Office of the European Union · Article 31(1) to (4) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
- [3]
Publications Office of the European Union · Article 28(1) to (3) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-09-11
The provisions behind this answer
Terms used in this answer
This answer is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.