Partner Academy / CRA regulation / Module 9

Conformity, Article 14 reporting, and penalties

The conformity assessment routes by tier, the three Article 14 reporting clocks, and the graduated penalty ladder.

Proving conformity by tier

The default route is Module A, internal control, where the manufacturer runs its own risk assessment, compiles the Annex VII technical documentation, draws up the EU Declaration of Conformity, and affixes the CE mark with no third party. Class I products move to a third-party route unless the relevant harmonised standards are fully applied. Class II products always need a third party, through EU type-examination with conformity to type or through full quality assurance. Critical products go through a European cybersecurity certification scheme. From 11 December 2027 the CE mark attests this conformity, and under full quality assurance it is followed by the notified body's identification number.

Reporting an exploited vulnerability

Article 14 runs three clocks from the moment the manufacturer becomes aware of an actively exploited vulnerability or a severe incident. An early warning goes out within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure becoming available for a vulnerability, or within one month for a severe incident. Reports go to the coordinating national CSIRT and to ENISA through its single reporting platform. Ordinary disclosure reports and internally discovered bugs stay under Article 13 rather than Article 14.

Article 14 is 24 hours, then 72 hours, then a final report. The 24 and 72 hour clocks both start when the manufacturer becomes aware.

The penalty ladder

Fines are graduated caps that national authorities set case by case. Breaching the Annex I essential requirements or the vulnerability-handling duties reaches 15 million euro or 2.5 percent of worldwide annual turnover. Other manufacturer, importer, and distributor obligations, such as failing to register a product or produce documentation, reach 10 million euro or 2 percent. Supplying incorrect, incomplete, or misleading information to authorities reaches 5 million euro or 1 percent. Each fine is the higher of the euro figure and the percentage, and proportionality applies to smaller firms.