Cyber Resilience Act penalties, fines and who imposes them in Spain

Cyber Resilience Act penalties are the administrative fines that Regulation (EU) 2024/2847 sets for anyone who makes products with digital elements available without complying with it. Article 64 establishes three tiers, with a maximum of 15 million euros or 2.5 % of total worldwide annual turnover, whichever is higher. The first obligation that can be penalised has applied since 11 September 2026: reporting actively exploited vulnerabilities and severe incidents. The remaining requirements arrive on 11 December 2027. Spain still lacks the piece that turns those maximums into actual proceedings, the designation of authorities and the national penalty regime. And a fine is not the only consequence, because the authority can order the product to be withdrawn and insecure software falls under the new product liability rules.

Table of contents

The three tiers of fines in Article 64

Article 64 of the Cyber Resilience Act splits infringements into three tiers according to the obligation breached. In each tier the maximum fine is a fixed amount or a percentage of total worldwide annual turnover for the preceding financial year, whichever is higher. The text is in Regulation (EU) 2024/2847, published in the Official Journal of the European Union.

TierWhat is breachedMaximum fine
FirstEssential cybersecurity requirements of Annex I and the manufacturer’s obligations in Articles 13 and 1415 million euros or 2.5 %
SecondObligations of authorised representatives, importers and distributors, formal rules on CE marking, the declaration and the technical documentation, assessment procedures, notified bodies and authorities’ access to data10 million euros or 2 %
ThirdIncorrect, incomplete or misleading information supplied to notified bodies or market surveillance authorities in reply to a request5 million euros or 1 %

The percentage only matters above a certain size. In the first tier, 2.5 % exceeds 15 million when the company’s annual turnover is above 600 million euros. Below that figure the ceiling is 15 million, and for an SME the fixed amount always sets the maximum.

Which infringement falls in each tier

The tier is decided by the article breached, not by how serious the damage is. One company can commit infringements in different tiers with a single product, for example if it sells it without meeting the essential requirements and also hands the authority incomplete documentation.

Essential requirements and manufacturer obligations

The first tier punishes the core of the regulation. It includes making available a product that does not meet the cybersecurity requirements of Annex I. It also includes any manufacturer obligation in Article 13, such as the risk assessment, vulnerability handling during the support period, the technical documentation or the EU declaration of conformity. And it covers Article 14, the reporting of actively exploited vulnerabilities and severe incidents, which we explain in our analysis of vulnerability reporting under the Cyber Resilience Act.

This tier is not only for manufacturers in the strict sense. Article 21 turns into a manufacturer any importer or distributor that sells the product under its own name or trademark, or that substantially modifies it. From that moment it is liable under Articles 13 and 14 and exposed to the highest fine.

Obligations of other operators and formal rules

The second tier reaches the other links in the chain. Articles 18 to 23 govern the authorised representative, the importer and the distributor, and the identification of economic operators. The tier also covers formal rules on the EU declaration of conformity, affixing the CE marking and the technical documentation, as well as applying a conformity assessment procedure that does not match the product’s category. The list is completed by several obligations of notified bodies and the obligation to give market surveillance authorities access to the data and documentation they request.

Misleading information to the authorities

The third tier penalises one specific conduct: supplying incorrect, incomplete or misleading information to a notified body or market surveillance authority that has requested it. It does not require the product to be insecure. A poor reply to a request is enough.

Who cannot be fined

Article 64(10) sets out two exceptions. Manufacturers that are microenterprises or small enterprises cannot be fined for missing the 24-hour early warning deadline, either for exploited vulnerabilities or for severe incidents. Open-source software stewards cannot be fined for any infringement of the regulation.

The first exception is narrow. It only covers the early warning deadline. It does not cover the duty to report, the 72-hour notification or the final report. A small company that warns late is protected from a fine for the delay, and one that does not warn at all is still exposed to the first tier. A small enterprise is one with fewer than 50 employees and an annual turnover or balance sheet of up to 10 million euros, under Recommendation 2003/361/EC, to which the regulation refers. A medium-sized enterprise does not benefit from the exception.

The open-source software steward is a figure specific to the Cyber Resilience Act. It is the legal person, other than a manufacturer, that provides sustained support for the development of free software intended for commercial activities, such as some foundations. It has light obligations under Article 24 and cannot be fined for any of them.

How the amount of the fine is set

The amounts in Article 64 are maximums. To set the specific amount, the authority takes into account all the circumstances of the case and, in particular, three criteria in Article 64(5).

  • The nature, gravity and duration of the infringement and of its consequences
  • Whether this or other market surveillance authorities have already fined the same operator for a similar infringement
  • The size of the operator, expressly mentioning microenterprises, SMEs and start-ups, and its market share

The second criterion has a European reach. The authorities that impose fines inform those of the other Member States through the market surveillance information system, so a penalty in another country counts as a precedent in Spain. The fine is also added to any corrective or restrictive measure the authority adopts for the same infringement.

Product withdrawal and sales bans

For many companies the most expensive measure is not the fine, it is losing the product. When the market surveillance authority considers that a product presents a significant cybersecurity risk, it evaluates it together with the CSIRT. If it does not comply, it requires the operator to correct it, withdraw it or recall it within a period proportionate to the risk, under Article 54.

Article 58 provides a faster route for formal non-compliance. The authority requires the manufacturer to remedy it when it detects any of these six situations:

  • CE marking affixed without following the rules in Articles 29 and 30
  • product without CE marking
  • EU declaration of conformity not drawn up
  • EU declaration of conformity drawn up incorrectly
  • missing notified body number where it is mandatory
  • technical documentation not available or incomplete

If the non-compliance persists, the Member State restricts or prohibits the product from being made available, or ensures that it is recalled or withdrawn from the market. The authorities can also run sweeps, simultaneous checks coordinated by the Commission on a category of products, which may include purchases under a cover identity, under Article 60.

Who imposes penalties in Spain

As of October 2026 Spain has not formally designated its Cyber Resilience Act authorities nor published the penalty regime that Article 64(1) entrusts to each Member State. The draft royal decree on designation, put out for public consultation in December 2025, assigns market surveillance to the Secretary of State for Telecommunications and Digital Infrastructure and the role of notifying authority to the National Cryptologic Centre (CCN). It does not include a regime of infringements and penalties.

That does not suspend any obligation. The regulation is directly applicable and vulnerability reporting has applied since 11 September 2026, with INCIBE listed by ENISA as Spain’s coordinating CSIRT. What remains open is whether an infringement committed before the Spanish regime exists can be penalised later, because the principle of legality requires the penalty to be laid down when the infringement is committed. That doubt offers no protection against measures on the product or against civil liability, which do not depend on the penalty regime.

Civil liability and collective actions

The Cyber Resilience Act opens two fronts that do not go through the authority. Article 65 allows infringements of the regulation that harm the collective interests of consumers to be pursued through representative actions under Directive (EU) 2020/1828. A consumer association can therefore bring a claim over an insecure product sold on a large scale.

The second front is the new Directive (EU) 2024/2853 on liability for defective products. It treats software as a product and takes cybersecurity requirements into account when assessing whether a product is defective. Nor does it exempt the manufacturer when the defect is due to the lack of security updates under its control. It applies to products placed on the market after 9 December 2026, the deadline for Member States to transpose it. The compensable damage is death or personal injury, damage to property and the destruction or corruption of data not used for professional purposes.

The same incident can also trigger other rules. If the manufacturer is an entity covered by the NIS2 Directive, it will have its own duty to report, and if personal data are affected the GDPR comes into play, with different authorities and deadlines.

Example: a small manufacturer of home security cameras

The case is fictitious and shows how the rules combine. Lumen Hogar, S.L. manufactures home security cameras in Vigo, with 32 employees and 8 million euros in turnover. It has sold in Spain and Portugal since 2025. On 2 October 2026 its technical team confirms that a firmware vulnerability is being exploited to access the cameras.

The company sends the early warning after 40 hours, outside the 24-hour deadline, and the full notification before 72 hours have passed since it became aware of the flaw. As a small enterprise, it cannot be fined for the late warning. Had it not reported at all, the Article 14 infringement would fall in the first tier, with a maximum of 15 million euros, because 2.5 % of its turnover would be a lower figure. The fact that the cameras were sold in 2025 does not release it, because the reporting obligation covers all products placed on the market before 11 December 2027.

If Lumen Hogar took weeks to publish the patch, the market surveillance authority could require corrective measures or the withdrawal of the cameras once it has been designated. And for the cameras it sells after 9 December 2026, damage caused by the lack of a security update could be claimed through product liability.

The classification of this product, which as a home security camera is important class I, is explained in our guide to product classification under the Cyber Resilience Act. The full framework of the regulation is in our guide to what the Cyber Resilience Act is and which companies it covers.

What is the maximum fine under the Cyber Resilience Act?

The maximum fine is 15 million euros or 2.5 % of total worldwide annual turnover for the preceding financial year, whichever is higher. It applies to breaches of the essential cybersecurity requirements of Annex I or of the manufacturer’s obligations in Articles 13 and 14, including the reporting of exploited vulnerabilities. The other two tiers reach 10 million or 2 % and 5 million or 1 %.

The reporting obligation has applied since 11 September 2026. As of October 2026, however, Spain has not designated its market surveillance authorities nor published the penalty regime required by Article 64(1). Whether breaches committed before that regime can be penalised later is an open question. The obligation itself is not in doubt, and failing to meet it exposes you to measures on the product and to civil claims.

It depends on its size and on the deadline missed. Microenterprises and small enterprises cannot be fined for missing the 24-hour early warning deadline. They can be fined for not reporting, or for missing the 72-hour notification or the final report. Medium-sized enterprises do not have this exception.

The lack of CE marking is a formal non-compliance under Article 58. The market surveillance authority will require it to be remedied and, if it persists, will restrict or prohibit the sale of the product or ensure that it is withdrawn or recalled from the market. In addition, affixing the marking is one of the manufacturer’s obligations in Article 13, so its absence can be fined in the first tier once the penalty regime is in force.

Yes. The distributor has its own obligations under Article 20, such as checking that the product bears the CE marking and comes with the required documentation. A breach falls in the second tier, of up to 10 million euros or 2 %. If it sells the product under its own name or trademark, or substantially modifies it, it becomes a manufacturer and is liable in the first tier.

The Cyber Resilience Act penalty regime is reaching Spain piece by piece. The reporting obligation already applies, the product requirements will apply in December 2027 and the authorities that impose penalties have not yet been designated. That gap is useful time to put the documentation, the reporting process and supplier contracts in order before there is anyone to check them. At Innovatech we support manufacturers, importers and distributors in complying with the Cyber Resilience Act. Write to us and we will give you a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.