FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Over-the-Air Updates

Must the manufacturer document how its OTA or other update-distribution mechanism is secured?

Yes.

The CRA technical-documentation rules do not treat secure update distribution as just an operational detail. Annex VII requires the technical documentation to include the necessary information and specifications of the manufacturer's vulnerability-handling processes, including a description of the technical solutions chosen for the secure distribution of updates.

So the manufacturer needs more than a working update channel. It also needs documentation showing what secure update-distribution approach it chose for the product.

Citations
CRA Over-the-Air Updates

Is using TLS or another protected transport channel by itself enough to make an OTA or update mechanism "secure"?

Not automatically.

The CRA itself speaks at a higher level and requires mechanisms to securely distribute updates. ETSI update-security guidance makes clear that protected transport can be one valid part of the trust model, but that secure update handling is about the overall mechanism resisting misuse and ensuring appropriate authenticity and integrity for the use case.

ETSI EN 303 645 explains that valid trust relationships can include authenticated communication channels, but it also points to verifying authenticity and integrity of updates and to anti-rollback measures. ETSI TS 103 701 says secure update mechanisms need security guarantees appropriate to the use case and that at least integrity and authenticity are required. ETSI TR 103 621 gives an example using TLS plus mutual authentication and digitally signed, versioned firmware packages. So a protected channel may be part of a compliant design, but it is not a shortcut that removes the need to ensure the update itself is trusted and protected against misuse.

Citations
ETSI EN 303 645 V3.1.3

Supports authentic servers, integrity-protected channels, anti-rollback controls, and update authenticity and integrity checks.

ETSI TS 103 701 V1.1.1

Supports testing secure update mechanisms for appropriate integrity and authenticity guarantees.

ETSI TR 103 621 V2.1.1

Provides examples combining protected transport, mutual authentication, signed packages, and version checks.

CRA Over-the-Air Updates

Can a product that is mostly offline or only intermittently connected still comply with the CRA's update obligations?

Potentially, yes.

The CRA does not say that a product must be permanently online. It requires that vulnerabilities can be addressed through security updates and that manufacturers provide mechanisms to securely distribute those updates.

ETSI examples show several models that fit that basic pattern: a smart kitchen appliance that can be initialized and used offline and checks for updates when first connected; a limited-bandwidth device that is securely updated via a manufacturer-prepared USB stick; and a smart tracker that only downloads updates when in range of a paired mobile device. Intermittent connectivity does not by itself make a product non-compliant, provided the manufacturer still ensures an update path that is secure and suitable to timely remediation. This is an inference from the CRA's functional wording together with the ETSI examples.

Citations
Cyber Resilience Act

Supports secure update distribution and timely remediation without requiring permanent connectivity.

ETSI TR 103 621 V2.1.1

Provides examples of offline, USB, and paired-device update paths for intermittently connected products.

CRA Over-the-Air Updates

What evidence should product teams keep for CRA OTA and update-distribution decisions?

Keep evidence that connects the update mechanism to the CRA cybersecurity risk assessment, vulnerability-handling process, and technical documentation.

For an OTA or other update path, the useful record is usually a short architecture description of the update channel, package-signing and verification model, rollback protection, user-notification and postponement flow, support-period statement, release availability policy, and exception rationale for products where automatic updates are not applicable.

For each security update, keep the vulnerability or issue being remediated, severity and exploitability assessment, affected versions, separation analysis for any bundled functionality change, release and advisory text, rollout controls, user-notification evidence, and the reason for any withdrawal, recall, or latest-version-only remediation decision.

Citations
Cyber Resilience Act

Supports technical documentation, vulnerability-handling, user-information, support-period, and secure update-distribution evidence.

ETSI EN 303 645 V3.1.3

Supports evidence around secure installation, update checks, authenticity and integrity verification, user notices, and published support periods.

CRA penalties and fines

Does the CRA set fines directly or leave penalties to Member States?

Both. Article 64 requires Member States to lay down penalty rules and take the measures needed to implement them. Those penalties must be effective, proportionate, and dissuasive.

At the same time, Article 64 sets the main administrative-fine ceilings. Member States therefore design the national enforcement system, but they do so within the CRA's EU-level maximum fine structure.

Citations
Cyber Resilience Act

Article 64(1) requires national penalty rules and Article 64(2) to (4) sets the main administrative-fine ceilings.

CRA penalties and fines

What is the highest CRA administrative fine cap?

The highest cap applies to non-compliance with the essential cybersecurity requirements in Annex I and with manufacturer obligations in Articles 13 and 14.

The maximum is up to EUR 15,000,000 or, for an undertaking, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Citations
Cyber Resilience Act

Article 64(2) covers Annex I, Article 13, Article 14, and the EUR 15 million or 2.5% turnover ceiling.

CRA penalties and fines

Which CRA breaches fall into the EUR 10 million or 2% tier?

Article 64(3) covers a wide set of CRA obligations beyond the manufacturer core: authorised representatives, importers, distributors, simplified technical documentation for micro and small enterprises, EU declarations of conformity, CE marking, notified bodies, notification obligations, and market-surveillance cooperation.

The maximum is up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Citations
Cyber Resilience Act

Article 64(3) lists the covered provisions and sets the EUR 10 million or 2% turnover ceiling.

CRA penalties and fines

What is the fine cap for incorrect or misleading information?

Supplying incorrect, incomplete, or misleading information to a notified body or market-surveillance authority in reply to a request has its own Article 64 tier.

The maximum is up to EUR 5,000,000 or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Citations
Cyber Resilience Act

Article 64(4) sets the fine ceiling for incorrect, incomplete, or misleading replies to notified bodies and authorities.

CRA penalties and fines

Are the turnover percentages optional alternatives to the euro amounts?

No. For undertakings, the CRA ceiling is the fixed euro amount or the stated percentage of total worldwide annual turnover for the preceding financial year, whichever is higher.

That means the percentage can raise the applicable maximum above the euro figure for a large undertaking.

Citations
CRA penalties and fines

Does Article 64 automatically decide the final fine amount?

No. Article 64 sets maximum ceilings, not automatic fine amounts.

For each case, the authority must consider all relevant circumstances, including the nature, gravity, duration, and consequences of the infringement; whether the same or another market-surveillance authority already fined the same economic operator for a similar infringement; and the operator's size and market share, including whether it is a microenterprise, SME, or start-up.

Citations
CRA penalties and fines

Can several Member States fine the same economic operator?

The CRA does not create a single EU one-stop-shop for penalties. Market-surveillance authorities can apply administrative fines under their national systems.

However, Article 64 requires earlier fines by the same or other market-surveillance authorities for a similar infringement to be considered. Authorities that apply fines must communicate that through the EU market-surveillance information and communication system. Recital 120 also stresses proportionality where several Member States act against the same economic operator for the same type of infringement.

Citations
Cyber Resilience Act

Article 64(5)(b), Article 64(6), and Recital 120 address earlier fines, cross-authority communication, and proportionality.

CRA penalties and fines

Which economic operators can face CRA fine exposure?

Manufacturers face the highest exposure because Article 64(2) covers Annex I and Articles 13 and 14. Other economic operators can also be exposed where the breached provision applies to them.

Article 64(3) expressly covers obligations in Articles 18 to 23, which include authorised representatives, importers, distributors, and cases where importers or distributors become subject to manufacturer obligations. It also covers specified notified-body and market-surveillance provisions.

Citations
Cyber Resilience Act

Article 64(2) covers manufacturer obligations; Article 64(3) covers Articles 18 to 23 and specified notified-body and authority provisions.

CRA penalties and fines

Can CRA fines be added to recalls, withdrawals, or other market measures?

Yes. Article 64(9) says administrative fines may be imposed, depending on the circumstances of the case, in addition to corrective or restrictive measures for the same infringement.

That means fine exposure should be assessed separately from product restrictions, withdrawals, recalls, and other market-surveillance outcomes.

Citations
Cyber Resilience Act

Article 64(9) allows administrative fines in addition to corrective or restrictive measures.

CRA penalties and fines

How do CRA vulnerability and incident reporting duties affect fines?

Article 14 reporting obligations are in the highest Article 64(2) tier. Manufacturers must notify actively exploited vulnerabilities and severe incidents through the single reporting platform, with an early warning within 24 hours after becoming aware, a follow-up notification within 72 hours, and later final reporting.

For severe incidents, the final report is due within one month after the incident notification. For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure is available.

Citations
Cyber Resilience Act

Article 14(1) to (4) sets the reporting triggers and staged deadlines; Article 64(2) covers Article 14 non-compliance.

CRA penalties and fines

Are microenterprises and small enterprises exempt from CRA fines?

No. The carve-out is narrow.

After the 2 July 2025 corrigendum, Article 64(10)(a) derogates from paragraphs 2 to 9 only for manufacturers that qualify as microenterprises or small enterprises, and only for failure to meet the 24-hour early-warning deadline in Article 14(2)(a) or Article 14(4)(a). It is not a general exemption from CRA obligations, not an SME-wide exemption, and not a shield for other reporting failures.

Citations
Cyber Resilience Act

Article 14(2)(a), Article 14(4)(a), Article 64(10)(a), and Recital 120 define the narrow reporting-delay carve-out.

Page 34 of 58