← All tools
Free Tool

CRA Liability & Penalty Exposure Checker

Article 64 of Regulation (EU) 2024/2847 establishes administrative fines up to €15,000,000 or 2.5% of worldwide turnover. Regulatory liability falls as conformity artifacts are completed and maintained.

Last updated 11 September 2026

Key takeaways

  1. CRA Article 64 establishes a graduated three-tier administrative fine structure with penalties reaching €15,000,000 or 2.5% of worldwide annual turnover.
  2. Breaches of Annex I essential cybersecurity requirements and Article 14 reporting duties attract the top penalty tier under Article 64(2).
  3. Procedural non-compliance including missing technical documentation or absent Declarations of Conformity falls under Article 64(3) with fines up to €10,000,000 or 2%.
  4. Regulatory liability falls as conformity work is completed, since documented diligence and timely reporting directly mitigate penalties under statutory proportionality criteria.
How CRA liability works: The Cyber Resilience Act does not impose strict liability for the mere existence of a security flaw. Administrative fines under Article 64 penalise failures of cybersecurity diligence, missing technical files, and omitted Article 14 reports. As conformity documentation is completed, statutory liability falls.

Step 1: Economic Operator Role

Statutory responsibilities vary by your legal role under CRA Chapter II.

Step 2: Product Classification Hint

Product classification determines if Module A self-assessment is permitted or if a third-party notified body is required.

Step 3: Conformity Self-Check

Indicate which core CRA conformity artifacts your organisation has completed for this product.

Product Classification & Assessment RouteMissing
Documented classification determining whether Module A self-assessment or a notified body applies.
Annex I Essential Requirements AssessmentMissing
Documented evaluation of security properties (Part I) and vulnerability handling / SBOM / CVD (Part II).
Annex VII Technical Documentation FileMissing
Complete technical dossier compiled prior to commercial release and retained for 10 years (Article 31).
EU Declaration of Conformity & CE MarkingMissing
Signed Declaration of Conformity (Article 28 / Annex V) supporting the affixed CE mark.
Article 14 24h/72h Reporting ProcedureMissing
Operational process to notify ENISA and designated CSIRTs within 24 hours of active exploitation.

Liability Assessment & Exposure Ceiling

Calculated based on Article 64 statutory fine caps and your current conformity completion.

Conformity Completion
0 / 5
0% baseline artifacts ready
Active Fine Tier (Max)
Tier 1
€15,000,000 or 2.5%
Regulatory Exposure Level
CRITICAL
Active compliance levers open
Role Context (manufacturer)

As the manufacturer, you bear primary statutory responsibility under the CRA for product classification, Annex I essential cybersecurity requirements, compiling the technical file, drafting the EU Declaration of Conformity, and meeting Article 14 24h/72h notification deadlines.

Assessment Route Context (default)

Default-class products qualify for Module A internal production control (self-assessment). Completing the five conformity artifacts achieves compliance self-assessment without requiring a notified body.

Exposure-Reduction Map: Your Compliance Levers

Each missing artifact represents a specific statutory breach. Closing each lever lowers statutory exposure and protects against administrative fines.

Product ClassificationTier 2 EXPOSURE
Selling products without formal classification creates risk of using an unauthorized conformity route (Module A self-assessment when a notified body is mandatory).
Statutory cap: €10,000,000 or 2% of annual turnover (Article 13(4), Article 32, Article 64(3))
Close gap
Annex I Essential Requirements AssessmentTier 1 EXPOSURE
Non-compliance with Annex I security properties or vulnerability handling (SBOM, CVD) triggers the maximum penalty tier under Article 64(2).
Statutory cap: €15,000,000 or 2.5% of annual turnover (Article 13, Annex I Part I & Part II, Article 64(2))
Close gap
Technical Documentation (Annex VII)Tier 2 EXPOSURE
Failure to draw up and maintain the Annex VII technical documentation file before market release violates Article 31.
Statutory cap: €10,000,000 or 2% of annual turnover (Article 31, Annex VII, Article 64(3))
Close gap
EU Declaration of ConformityTier 2 EXPOSURE
Affixing CE marking without drawing up an authorized EU Declaration of Conformity constitutes an unlawful CE mark under Article 64(3).
Statutory cap: €10,000,000 or 2% of annual turnover (Article 28, Article 30, Article 64(3))
Close gap
Article 14 24h/72h Reporting ProcedureTier 1 EXPOSURE
Missing statutory 24-hour early warning or 72-hour full notification to ENISA and CSIRTs attracts the top administrative fine tier under Article 64(2).
Statutory cap: €15,000,000 or 2.5% of annual turnover (Article 14, Article 64(2))
Close gap

Turn Conformity Work into Continuous Liability Protection

CVD Portal covers every obligation in one place: automated product classification, Annex I essential requirement tracking, technical documentation assembly, EU Declaration of Conformity drafting, and statutory Article 14 24h/72h notification management.

This tool provides technical compliance estimation under Regulation (EU) 2024/2847. It does not constitute legal advice. CVD Portal is an independent software platform and does not perform third-party notified body assessments.

Frequently asked

Does discovering a vulnerability in our product automatically make us liable under the CRA?+

No. The Cyber Resilience Act does not impose strict liability for the mere existence of vulnerabilities. Administrative fines penalise failures to meet Annex I cybersecurity requirements, absence of coordinated vulnerability disclosure procedures, and failure to notify ENISA and designated CSIRTs within statutory deadlines once aware of an actively exploited vulnerability.

How does completing conformity artifacts reduce our fine exposure under Article 64?+

Article 64 administrative fines must be effective, proportionate, and dissuasive. Market surveillance authorities assess mitigating factors under Article 64 and national law, including whether the manufacturer completed formal product classification, maintained the Annex VII technical file, and implemented prompt remediation. Documented conformity substantiates due diligence and directly lowers penalty exposure.

What is the difference between Tier 1 and Tier 2 fines under Article 64?+

Tier 1 under Article 64(2) carries maximum fines of €15,000,000 or 2.5% of global turnover for substantive security breaches: Annex I essential requirements, Article 13 manufacturer obligations, and Article 14 statutory reporting. Tier 2 under Article 64(3) carries fines of up to €10,000,000 or 2% for procedural breaches: absent technical documentation, missing Declarations of Conformity, and unauthorized CE markings.

Can importers and distributors be fined for manufacturer non-compliance?+

Yes. Importers under Article 19 must verify that manufacturers carried out conformity assessments and drew up technical documentation before placing products on the EU market. Distributors under Article 20 must act with due care. If an importer or distributor markets a product under its own brand or trademark, Article 21 deems them the legal manufacturer with full Tier 1 and Tier 2 liability.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →