CRA Enforcement: What Happens If You Donβt Comply
The CRA has teeth. Non-compliance means your products can be removed from the EU market, and fines can reach β¬15 million. Understanding enforcement helps you prioritize compliance efforts.
Penalty Structure
| Violation | Maximum Fine |
|---|---|
| Essential cybersecurity requirements | β¬15M or 2.5% global annual turnover |
| Other CRA obligations | β¬10M or 2% global annual turnover |
| Incorrect/misleading information to authorities | β¬5M or 1% global annual turnover |
For each violation, the higher amount applies.
Market Surveillance
Member state authorities will conduct:
Reactive Surveillance
- Respond to vulnerability reports and incidents
- Investigate complaints from users or competitors
- Follow up on ENISA vulnerability notifications
Proactive Surveillance
- Random product testing and audits
- Verification of CE marking and documentation
- SBOM completeness checks
- Security testing of products on the market
What Authorities Can Do
- Request documentation β technical files, SBOMs, test reports
- Order product testing β at the manufacturerβs expense
- Require corrective action β fix vulnerabilities, update documentation
- Issue product recalls β remove non-compliant products from the market
- Ban market access β prevent future sales until compliance is achieved
- Impose fines β up to the maximum amounts above
How to Prepare for Inspection
Compliance Package (ready at all times):
βββ EU Declaration of Conformity
βββ Technical Documentation
β βββ Product description
β βββ Security risk assessment
β βββ Design and development documentation
β βββ Test reports
βββ Current SBOM
βββ Vulnerability handling procedures
βββ Security update policy and history
βββ Incident reports filed with ENISA
βββ Evidence of security testingRisk-Based Prioritization
Focus compliance efforts where enforcement risk is highest:
- Products involved in security incidents β these attract immediate attention
- Products with known unpatched vulnerabilities β visible in public databases
- Products without CE marking β easy to identify and enforce
- Class II/Critical products β higher scrutiny by design
Concerned about CRA enforcement? I help organizations build audit-ready compliance programs. Get in touch.
