If you build hardware or firmware and sell it into the EU, you have probably been told that from 11 September 2026 a missed 24-hour report is a fineable offence. For a company with a handful of engineers, that is the sentence that turns CRA planning into panic buying.
It is also, for the smallest manufacturers, not what the Regulation does. Article 64(10) disapplies the administrative fines to “manufacturers that qualify as microenterprises or small enterprises with regard to any failure to meet the deadline referred to in Article 14(2), point (a), or Article 14(4), point (a)” — those two points being the 24-hour early warning for an actively exploited vulnerability and the 24-hour early warning for a severe incident. The same paragraph disapplies them to “any infringement of this Regulation by open-source software stewards.” The Commission’s own summary of the legislative text reads it the same way.
We are publishing that because it is true, not because it helps us sell. It narrows what we can honestly claim the readiness pack protects you from.
What the carve-out does not do
Read the wording closely, because it is narrow in three specific ways.
- It removes a fine, not a duty. The obligation to submit the early warning still applies to you on 11 September 2026. What the carve-out changes is the consequence of being late — not whether you are supposed to file.
- It names the 24-hour vulnerability deadline specifically. It is not a general exemption from CRA reporting. The 72-hour full notification and the final report are separate steps of the same cascade, and the published carve-out does not extend itself to them.
- It does nothing for December 2027. The essential requirements, conformity assessment and CE marking that apply from 11 December 2027 are untouched by it.
So the practical position for a small maker is this: you must still be able to file, you are still visible to a market surveillance authority that finds you never did, and you have one fewer worst-case number to plan around. That is a better reason to build the process than a fine was.
How large is “small”?
This is the question the carve-out turns on. The CRA does not define the terms itself — Article 3(19) says “microenterprises”, “small enterprises” and “medium-sized enterprises” mean what they mean in the Annex to Commission Recommendation 2003/361/EC. That Annex, Article 2, sets the cutoffs:
- Microenterprise — fewer than 10 staff, and annual turnover and/or annual balance sheet total not exceeding €2 million.
- Small enterprise — fewer than 50 staff, and annual turnover and/or annual balance sheet total not exceeding €10 million.
Both limbs matter: you need to be under the headcount and under the financial ceiling. Note also that the Recommendation does not let you count only the legal entity in front of you. Article 3 pulls in “partner” and “linked” enterprises — broadly, where another business holds 25% or more of your capital or voting rights, its headcount and figures come into the calculation. A ten-person hardware company owned by a larger group is frequently not a small enterprise for these purposes. If you are near any boundary, or you have an investor above that threshold, that is a question for counsel against the Regulation’s own text — not for a vendor page.
The dates that actually bind you
The CRA entered into force on 10 December 2024 and phases in across several dates rather than one. Three matter to a manufacturer:
- 11 June 2026 — Chapter IV, on the notification of conformity assessment bodies, starts to apply. This is infrastructure being stood up around you rather than a duty landing on you, but it is why assessment capacity starts to exist.
- 11 September 2026 — the Article 14 reporting obligations apply. Early warning within 24 hours of becoming aware, full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability, or within a month for a severe incident.
- 11 December 2027 — the main obligations apply in full.
Reports are filed once, through the single reporting platform in Article 16. You submit to the notification end-point of the CSIRT designated as coordinator for the member state where you have your main establishment in the Union, and the report is simultaneously accessible to ENISA — one submission, two recipients.
“Main establishment” is not your head office. Article 14(7) defines it as the member state where decisions about the cybersecurity of your products are predominantly taken, falling back to wherever you have the most EU employees if that cannot be determined. And if you have no establishment in the Union at all — the case for most non-EU makers selling into Europe — the coordinator is determined by a cascade: the member state of your authorised representative for the most products, then of the importer placing the most products on the market, then of the distributor. Working out which CSIRT you actually file to is a thing to settle before an incident, not during one.
What the fines actually are
Article 64 sets three ceilings, and which one applies depends on which obligation you broke. Reporting is in the top tier. Article 64(2) covers the essential requirements in Annex I and the obligations in Articles 13 and 14 — Article 14 being the reporting duty itself — at up to €15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.
The more commonly quoted €10 million / 2% figure is Article 64(3), and it applies to a different list of obligations that does not include reporting. The €5 million / 1% tier in Article 64(4) covers supplying incorrect, incomplete or misleading information to a notified body or market surveillance authority in reply to a request.
That Article 64(3) tier is worth a second look if you are budgeting, because it covers Article 32 — the choice of conformity assessment procedure. Self-assessing a product that the annexes route through a notified body is an infringement in its own right, and the carve-out below does not reach it. Which products keep the self-assessment route, and what CRA compliance actually costs a small maker, is a separate question from the reporting duty.
These are ceilings, not forecasts. Article 64(1) leaves the actual rules on penalties to each member state, and Article 64(5) requires the authority to weigh the nature, gravity and duration of the infringement, whether you have been fined before for something similar, and — explicitly — the size of the operator, “in particular with regard to microenterprises and small and medium sized-enterprises, including start-ups.”
One drafting detail worth knowing if you are relying on the carve-out: Article 64(10) exempts micro and small manufacturers “by way of derogation from paragraphs 3 to 9,” while the fines for Article 14 breaches sit in paragraph 2. The derogation names the 24-hour deadlines in Article 14(2)(a) and 14(4)(a) directly, and the Commission’s summary reads it as a straightforward exemption — but the cross-reference is to the paragraphs that do not contain the reporting tier. We flag it rather than resolve it. It is another reason to treat the carve-out as covering the fine and not the duty.
What this means for the readiness work
The honest case for preparing has never been the fine. It is that on 11 September 2026 a researcher can email you about a product you shipped three years ago, and you will have 24 hours to say something accurate about what is inside it. That requires knowing your components — which is why the SBOM is worth having in 2026 even though it is due in 2027 — and it requires a named person with the authority to file.
Our guide to the September 2026 reporting start covers why the duty reaches back over products already in the field. PartsProof builds the gap checklist, the SBOM and the reporting runbooks so that path exists before it is needed: $349 for the Readiness Pack, $649 for Readiness Plus with SBOM and runbooks, $899 with a retainer. See what the pack contains or get in touch.
Every figure and date above was verified on 29 July 2026 against the text of Regulation (EU) 2024/2847 as published in the Official Journal, and Commission Recommendation 2003/361/EC for the enterprise-size thresholds. Nothing here is legal advice.