acquis · Law · Cyber Resilience Act
Cyber Resilience Act · CELEX 02024R2847-20241120
Article 64
Verbatim text of the current consolidated version (consolidated 2024-11-20) · status: in force. Check it on EUR-Lex ↗
Cyber Resilience Act, Article 64(1) — Penalties
Member States shall lay down the rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall, without delay, notify the Commission of those rules and measures and shall notify it, without delay, of any subsequent amendment affecting them.
Cyber Resilience Act, Article 64(2) — Penalties
Non-compliance with the essential cybersecurity requirements set out in Annex I and the obligations set out in Articles 13 and 14 shall be subject to administrative fines of up to EUR 15000000 or, if the offender is an undertaking, up to 2,5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.
Cyber Resilience Act, Article 64(3) — Penalties
Non-compliance with the obligations set out in Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1), (2) and (3), Article 33(5), and Articles 39, 41, 47, 49 and 53 shall be subject to administrative fines of up to EUR 10000000 or, if the offender is an undertaking, up to 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Cyber Resilience Act, Article 64(4) — Penalties
The supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request shall be subject to administrative fines of up to EUR 5000000 or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Cyber Resilience Act, Article 64(5) — Penalties
When deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following: (a) the nature, gravity and duration of the infringement and of its consequences; (b) whether administrative fines have been already applied by the same or other market surveillance authorities to the same economic operator for a similar infringement; (c) the size, in particular with regard to microenterprises and small and medium sized-enterprises, including start-ups, and the market share of the economic operator committing the infringement.
Cyber Resilience Act, Article 64(6) — Penalties
Market surveillance authorities that apply administrative fines shall communicate that application to the market surveillance authorities of other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.
Cyber Resilience Act, Article 64(7) — Penalties
Each Member State shall lay down rules on whether and to what extent administrative fines may be imposed on public authorities and public bodies established in that Member State.
Cyber Resilience Act, Article 64(8) — Penalties
Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or other bodies according to the competences established at national level in those Member States. The application of such rules in those Member States shall have an equivalent effect.
Cyber Resilience Act, Article 64(9) — Penalties
Administrative fines may be imposed, depending on the circumstances of each individual case, in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement.
Cyber Resilience Act, Article 64(10) — Penalties
By way of derogation from paragraphs 2 to 9, the administrative fines referred to in those paragraphs shall not apply to the following: (a) manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a); (b) any infringement of this Regulation by open-source software stewards.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the Cyber Resilience Act
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46Art. 47Art. 48Art. 49Art. 50Art. 51Art. 52Art. 53Art. 54Art. 55Art. 56Art. 57Art. 58Art. 59Art. 60Art. 61Art. 62Art. 63Art. 64Art. 65Art. 66Art. 67Art. 68Art. 69Art. 70Art. 71
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage