Kilde › Guides › CRA › CRA penalties: where Article 14 sits i…

CRA penalties: where Article 14 sits in the fine structure

Current to 26 August 2026 · updates land in the changelog.

The CRA's fine structure has three tiers — and the reporting duty sits in the top one. Article 64 sets maximum administrative fines, applied through national market-surveillance authorities.

The three tiers

CeilingWhat it attaches to
€15,000,000 or 2.5% of worldwide annual turnover, whichever is higherBreaches of the Annex I essential requirements or of the obligations in Articles 13 and 14 — which places the reporting duty in the top tier alongside the core security requirements.
€10,000,000 or 2%Breaches of other operator obligations under the regulation.
€5,000,000 or 1%Supplying incorrect, incomplete or misleading information to notified bodies and market-surveillance authorities.

Calibration: SMEs and open source

Fine amounts must take account of the operator's size and market share — with micro, small and medium-sized enterprises and startups expressly in the calibration factors. And open-source software stewards are exempt from administrative fines altogether (Article 64(10)(b)) — part of the light-touch regime for qualifying non-commercial open source.

The open question worth naming honestly

Enforcement runs through national authorities, and the fine provisions sit with the regulation's general application date. Whether administrative fines can attach to Article 14 breaches committed before 11 December 2027 — the reporting duty applies from 11 September 2026, the penalties chapter with full application — is a genuinely open question that may resolve differently across Member States' implementing laws. We present it as open rather than asserting either answer; what is not open is that from 11 December 2027 the top tier squarely covers reporting failures, and that a CSIRT's records of a manufacturer's 2026–27 reporting conduct will exist either way.

Related guides

Quick answers

What is the maximum fine for CRA reporting breaches?
Article 14 breaches sit in the top tier: up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher — the same tier as breaches of the essential security requirements.
Do CRA fines apply to small companies at full force?
The ceilings are the same, but Article 64 requires fine amounts to account for the operator's size — micro-enterprises, SMEs and startups are express calibration factors — and open-source stewards are exempt from administrative fines entirely.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com