CRA fines and enforcement: what small companies actually risk
The EU Cyber Resilience Act carries fines up to €15 million or 2.5% of turnover — but that's the ceiling, not the likely outcome for a small manufacturer. How enforcement really works, what the tiers are, and where the sharper risk lies.
Not sure if you’re in scope?
Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.
Check if the CRA applies to youIn short
CRA fines reach up to €15 million or 2.5% of worldwide annual turnover, whichever is higher — but that is the ceiling for the most serious breaches, not the likely outcome for a small manufacturer. Penalties run in tiers and are enforced by national market surveillance authorities. For a small company the sharper practical risk is usually a market-withdrawal order or a lost sale, not the maximum fine.
"Fines up to €15 million or 2.5% of worldwide turnover" is the number every CRA article leads with, and it does its job: it gets attention. But for a small manufacturer trying to plan, the headline number is close to useless — it's the legal ceiling, not the probable outcome. This guide explains how CRA enforcement actually works, what the different penalty tiers are, who does the enforcing, and where the risk for a small company really sits (hint: it's usually not the €15M fine).
Not sure the CRA applies to your product? Run the free scope check first.
The three penalty tiers
The regulation sets maximum fines in three bands, depending on which obligation you breach:
| Breach | Maximum fine |
|---|---|
| Essential cybersecurity requirements (Annex I) and vulnerability-handling obligations | €15 million or 2.5% of total worldwide annual turnover, whichever is higher |
| Other obligations (reporting duties, technical documentation, CE marking, information duties) | €10 million or 2% of turnover |
| Supplying incorrect, incomplete or misleading information to authorities | €5 million or 1% of turnover |
Two things to read carefully. First, "whichever is higher" means the percentage protects large companies from trivial fines and the fixed amount catches small ones — but the fixed amounts are ceilings, and authorities set the actual figure proportionately. Second, these are administrative fines imposed by national market surveillance authorities, not automatic penalties.
How enforcement actually works
The CRA is enforced by national market surveillance authorities — the same bodies that already police CE marking and product safety in each member state. Enforcement is not a proactive audit of every product on the market; there aren't the resources for that. It is, in practice, triggered by:
- A complaint — from a competitor, a customer, or a security researcher.
- An incident — a breach or exploited vulnerability that surfaces publicly, prompting authorities to ask whether you met your obligations.
- A market surveillance campaign — periodic sweeps of a product category, where authorities pull a sample and check documentation.
- A failed check at import or sale — a distributor or customs authority noticing a missing CE marking.
The typical sequence is not "surprise fine." It is: request for documentation → if inadequate, an order to bring the product into conformity within a deadline → if ignored, escalation to restrictions (withdrawal or recall) and only then fines. Authorities are directed to be proportionate and to consider the size of the company, the nature of the breach, and whether it was deliberate.
What this means for a small manufacturer
The realistic risk profile for a company of 5–50 people looks nothing like a €15M fine on day one. It looks like this:
- Most likely: you get asked for your technical documentation — during a surveillance campaign, after an incident, or because a customer demanded proof. If you have it, the matter ends. If you don't, you get a deadline to produce it.
- Next most likely: a distributor or enterprise customer refuses to buy because you can't provide a Declaration of Conformity or an SBOM. This is a commercial loss, not a regulatory fine — and it's already happening in 2026, ahead of the deadlines.
- The real financial exposure: a product recall or withdrawal order if a serious non-conformity is found. Pulling a product from the EU market is far more expensive for most small companies than any fine — lost sales, logistics, reputation.
- Least likely but not zero: an actual fine, reserved for serious, deliberate, or persistent non-compliance — ignoring a conformity order, or hiding an exploited vulnerability instead of reporting it.
The pattern: for a good-faith small manufacturer, the CRA's teeth are market access and documentation demands, not a surprise multi-million-euro penalty. The company that gets fined is usually the one that ignored a warning.
The one thing that turns a manageable situation into a serious one
There is a bright line worth knowing. Failing to have perfect documentation is a correctable problem — you get a deadline. But concealing an actively exploited vulnerability instead of reporting it within 24 hours (see our ENISA reporting guide) moves you from "administrative shortfall" to "deliberate breach," and that is where the top-tier fines and the reputational damage live. The reporting obligation from 11 September 2026 is the one where silence is the expensive choice.
How to make enforcement a non-event
You don't reduce enforcement risk by being lucky. You reduce it by being able to answer the one question authorities and customers ask: "show us your documentation." That means:
- A technical file you can produce on request (SBOM, risk assessment, vulnerability-handling process)
- A signed EU Declaration of Conformity and CE marking
- A reporting process that's ready before an incident, not improvised during one
- A record of your vulnerability triage — decisions made and documented, not a to-do list
A company that has these treats an enforcement request as an email to answer, not a crisis. A company that doesn't treats it as an emergency. The difference is a few weeks of preparation done before the deadline. Our compliance checklist lays out exactly what to have ready, and CRA compliance software keeps that technical file current so the answer to "show us your documentation" is always ready.
When an authority or a customer says show us your documentation, assembling the technical file, Declaration of Conformity and vulnerability record on the spot is the nightmare scenario.
Nordchecks keeps that file continuously up to date — SBOM, monitoring log and documents — so an enforcement request is an email to answer, not a fire drill.
Try Nordchecks freeStart with the three-minute version: check your product's scope and obligations free — no signup, based on the regulation text.