CRA Liability and Penalty Exposure Checker
Article 64 of Regulation (EU) 2024/2847 (Cyber Resilience Act) defines administrative penalties for non-compliance. Maximum fines reach up to €15,000,000 or 2.5% of worldwide annual turnover.
The CRA Liability Checker at https://cvdportal.com/tools/cra-liability-check provides an interactive, client-side evaluation tool. It calculates your maximum statutory penalty exposure based on your operator role, product class, and completed conformity artifacts.
How liability works under the CRA
The CRA does not establish strict liability for the presence of a security flaw. Administrative fines penalise failures of cybersecurity diligence, missing technical files, and omitted statutory notifications.
Statutory exposure falls as conformity artifacts are completed:
- Product Classification (Article 13(4), Article 32). Confirms whether Module A self-assessment or a notified body assessment applies. Missing classification risks Tier 2 fines under Article 64(3) up to €10,000,000 or 2%.
- Annex I Assessment (Annex I Part I & Part II). Documents fulfillment of security properties and vulnerability handling duties. Missing assessment triggers Tier 1 fines under Article 64(2) up to €15,000,000 or 2.5%.
- Technical Documentation (Article 31, Annex VII). Compiles the comprehensive compliance dossier prior to placing products on the market. Missing documentation risks Tier 2 fines under Article 64(3).
- EU Declaration of Conformity (Article 28, Annex V). Attests compliance to substantiate CE marking. Unlawful CE marking without a valid declaration risks Tier 2 fines under Article 64(3).
- Article 14 Reporting Procedure (Article 14). Sets up 24-hour early warning and 72-hour full notification to ENISA and designated CSIRTs. Missing statutory reporting triggers Tier 1 fines under Article 64(2).
Exposure-reduction map
The tool maps each open conformity gap to a concrete product action:
- Classification gaps link to the product classifier (
/classify). - Annex I and DoC gaps link to the CRA self-assessment workspace (
/cra-self-assessment). - Technical file gaps link to the CRA maturity assessment (
/cra-maturity-assessment). - Article 14 reporting gaps link to the coordinated vulnerability disclosure intake onboarding (
/register).
Proportionality and legal disclaimer
Market surveillance authorities scale fines under Article 64 proportionality criteria, considering company size, mitigation actions, and compliance cooperation.
The tool provides technical compliance estimation. It does not provide legal advice.