← All posts

Small companies and CRA fines: the exemption most write-ups miss

8 August 2026 · 4 min read · by Admin

Last week I posted something confident and wrong.

I told small software vendors that the EU Cyber Resilience Act would expose them to fines of up to €15 million for missing its 24-hour vulnerability-reporting deadline. It's the kind of line that gets attention, and it's the kind of line half the CRA write-ups online are built on.

Then Marta Rybczynska, who actually works on CRA standardisation, corrected me in the comments: there's an exception for small companies, check the penalties part.

She was right. And it's worth getting exactly right, because the correction changes the pitch that almost every CRA tool (including an earlier version of mine) has been making.

What Article 64 actually says

The CRA's penalty ceilings are real: up to €15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and the core manufacturer obligations. Those numbers aren't fiction.

But Article 64 carves out the exact group most of the "you'll be fined" messaging is aimed at. Micro and small enterprises (broadly, companies under 50 staff) cannot be fined for failing to meet the reporting deadlines in Article 14. That's the 24-hour early warning, the 72-hour notification, all of it.

Open-source stewards get an even wider shield: they can't be fined for CRA infringements at all. And for every SME, the regulation tells authorities to weigh company size when setting any fine, so that penalties don't threaten a small business's viability.

So the honest version of my original post is this: the software shops I've been talking to (the 5-to-30-person ISVs) are, for the most part, exempt from the exact fine I was waving around.

So is that the end of it?

That was my next question. If the fine doesn't apply, why would a small vendor spend a minute (or a euro) on any of this?

Here's what the exemption doesn't touch:

  • The obligation still stands. Small enterprises are exempt from the fine for missing the deadline, not from the duty to report. Handling and disclosing actively exploited vulnerabilities is still required.
  • Your customers don't care about the exemption. This is the big one. Enterprise and public-sector buyers are already asking suppliers "what's in your software, and what's vulnerable in it?", through procurement questionnaires, security audits, ISO 27001 programmes. That question arrives whether or not a fine is attached, and "give us a week to find out" is not an answer that keeps a deal alive.
  • The 2027 obligations are finable. From December 2027 the full CRA applies; SBOMs, secure-by-design, CE marking, technical documentation and those carry their own penalties, with no small-company carve-out.
  • The exemption expires as you grow. Cross the small-enterprise threshold and the shield is gone. Nobody wants to build this capability under deadline pressure the quarter after they scale.
  • Fines aren't the only enforcement. Market-surveillance authorities can order corrective action or pull a non-compliant product from the market , outcomes that don't depend on a fine at all.

The real reason was never the fine

What I learned from being corrected in public is that the fear-of-fines framing isn't just slightly off, it's aimed at the wrong motivation entirely.

The reason to know what's in your product was never that a regulator might fine you for a late report. It's that someone is going to ask (a customer during procurement, an auditor during certification, eventually a regulator) and the vendors who can answer in minutes will keep winning deals the ones who can't will lose.

That's the actual problem the CRA is dragging into the open. Not fear. Readiness.

The vendors I've seen furthest ahead on this didn't do it because of the CRA at all. They did it because a big customer's security team demanded it and they wanted the contract. The regulation just put a date on something the market was already going to ask for.

Thanks to Marta Rybczynska for the correction. This space needs the precision, and it's a better argument without the scare number anyway.

More from the blog

See where your product stands under the CRA.

Run a free CRA Readiness Snapshot; what's in your product, what's actively exploited, in about a minute.

Run a free Snapshot