
Last updated: 2026-10-09
The reporting obligation of the Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) has applied since 11 September 2026 and the rules on notified bodies in Chapter IV since 11 June 2026; the remaining provisions apply from 11 December 2027 (Article 71(2)). This raises a question for management: who answers for an infringement, the company, the managing directors personally, or both? This article sorts it into three levels and names the relevant provisions.
In short: the CRA's obligations and fines are aimed at manufacturers and the other economic operators, which for a GmbH or AG means the company. Whether members of management can also be fined personally depends on the German implementing act, which has not yet been adopted. Damages to the company itself only come into question where management has breached its duties, and the new product liability rules again apply to the economic operator.

Level 1: the company is the addressee
The CRA places obligations on economic operators. Under Article 3(12) these include manufacturers, authorised representatives, importers and distributors. Under Article 3(13), the manufacturer is whoever develops or manufactures products with digital elements, or has them designed, developed or manufactured, and markets them under its name or trademark. The obligations are in Articles 13 and 14 (manufacturers), 19 (importers) and 20 (distributors). An importer or distributor that places a product on the market under its own name or makes a substantial modification is considered a manufacturer under Article 21 (for other persons, Article 22). See the overview of roles under the CRA.
Where the manufacturer is a German GmbH or AG, the company is the manufacturer, not the person who runs it. Where a natural person runs the business directly, for example as a sole trader, that person is the manufacturer (Article 3(13)). The Regulation contains no provision placing obligations or liability on the manufacturer's management itself. By contrast, section 38 BSIG requires the management of particularly important and important entities under Germany's NIS2 transposition to implement and oversee risk management measures and to attend training regularly.
Administrative fines under Article 64 CRA
Article 64(1) requires Member States to lay down rules on penalties and notify them to the Commission; the penalties must be effective, proportionate and dissuasive. For administrative fines the Regulation sets three ceilings, each as a fixed amount or, if the offender is an undertaking, as a share of its total worldwide annual turnover for the preceding financial year, whichever is higher:
| Article 64 | Infringement | Ceiling |
|---|---|---|
| (2) | Non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14 | EUR 15 million or 2.5% |
| (3) | Non-compliance with Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1) to (3), Article 33(5) and Articles 39, 41, 47, 49 and 53 | EUR 10 million or 2% |
| (4) | Supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request | EUR 5 million or 1% |
These are maximum amounts. Under Article 64(5), all relevant circumstances of each individual case are taken into account, expressly the nature, gravity, duration and consequences of the infringement, earlier fines for similar infringements, and the size and market share of the economic operator, in particular for micro, small and medium-sized enterprises. Fines may be imposed in addition to corrective or restrictive measures (paragraph 9). Paragraph 10 provides exceptions for microenterprises and small enterprises regarding the early warning deadline under Article 14, and for open-source software stewards. Because paragraph 10 derogates only from paragraphs 3 to 9 while infringements of Article 14 fall under paragraph 2, and Article 24(3) applies parts of Article 14 to open-source software stewards as well, the scope of both exceptions is a question of interpretation; recital 120 assumes in both cases that no fines are imposed, and the German bill does not address the point specifically. More in our article on fines and penalties.
Market surveillance measures
Market surveillance authorities also have the powers in Chapter V (Articles 52 to 60) and Regulation (EU) 2019/1020 (Article 52(1)). Upon a reasoned request they get access to data and internal documentation (Article 53). Where a product presenting a significant cybersecurity risk does not comply and the economic operator takes no adequate corrective action, they prohibit or restrict making it available, withdraw it or recall it (Article 54(5)). Measures are also provided for compliant products presenting a significant cybersecurity risk and further risks, for instance to the health or safety of persons (Article 57), and for persisting formal non-compliance such as a missing CE marking or incomplete technical documentation (Article 58). For infringements harming the collective interests of consumers, Article 65 applies the Representative Actions Directive (EU) 2020/1828.
Status of German implementation (9 October 2026)
A German implementing act is to designate the authority and set the fining procedure; the government bill is Bundestag printed paper 21/6134 of 26 May 2026. The Bundestag held its first reading on 11 June 2026 and referred the bill to committee. In its first passage on 12 June 2026 the Bundesrat raised no objections. In the official sources we found no adoption by the Bundestag and no promulgation as of this article's date, so the act is still open and the bill may change.
Under the bill, the Federal Office for Information Security (BSI) would become the market surveillance authority (section 65(1) BSIG draft), the notifying authority (section 66(1) BSIG draft) and the fining authority for infringements under Article 64(2) to (4) CRA (section 70(1) no. 2(b) BSIG draft). For these infringements the German Administrative Offences Act (OWiG) would apply accordingly, except for section 17 OWiG, also in conjunction with section 30(3), and section 30(1) and (2) OWiG (section 69(1) BSIG draft). The explanatory memorandum calls the Regulation's penalty rules exhaustive and overriding in this respect. Under Article 4(2) of the bill, section 66 BSIG draft would enter into force as of 11 June 2026; the other provisions mentioned, including the fining rules, would enter into force on 11 December 2027 under Article 4(4).
Level 2: management personally
Administrative offences law: sections 9, 30 and 130 OWiG
Three provisions of the German Administrative Offences Act (OWiG) link companies and their managers:
- Section 9 OWiG (acting for another): where someone acts as an authorised representative body of a legal person or a member of it, a law under which particular personal characteristics establish liability to a fine also applies to them if those characteristics are present only in the person represented (subsection 1 no. 1). Subsection 2 applies the same to persons commissioned by the owner, or by someone otherwise authorised, to manage all or part of the business, or expressly commissioned to perform the owner's duties on their own responsibility, when acting on that commission; an undertaking is treated in the same way as a business.
- Section 30 OWiG (fines against legal persons): where a manager, for example an authorised representative body, has committed a criminal or administrative offence breaching duties of the legal person or (intended to be) enriching it, a fine may be imposed on the legal person.
- Section 130 OWiG (breach of supervisory duty): an owner of a business who intentionally or negligently omits the supervision required to prevent contraventions of the owner's duties that carry a criminal penalty or fine commits an administrative offence, if such a contravention occurs that proper supervision would have prevented or made considerably more difficult. Required supervisory measures include the appointment, careful selection and monitoring of supervisory staff (subsection 1). The provision is addressed to the owner; for a GmbH or AG that is the company, whose managers it reaches via section 9 OWiG.
Whether and how these provisions apply to CRA infringements depends on Germany's implementing law. The government bill applies the OWiG accordingly to infringements under Article 64(2) to (4) CRA and excludes only section 17 and section 30(1) and (2) OWiG; it neither mentions nor excludes sections 9 and 130 OWiG. Whether managers can themselves be fined for a company's CRA infringement is therefore open and depends on the adopted text and its interpretation. A fine under Article 64 CRA is directed at the economic operator; it is not the same as a personal fine on management.
Internal liability towards the company
A separate question is whether management owes damages to the company, for instance for the cost of a recall. Whether a fine imposed on the company can itself be claimed from management as damage is not expressly addressed by section 43 GmbHG or section 93 AktG; that is a matter for legal advice. Company law governs this:
- Section 43 GmbHG: managing directors must apply the care of a prudent businessperson in the company's affairs (subsection 1). A breach of duty makes them jointly and severally liable to the company for the damage (subsection 2).
- Section 93 AktG: members of the management board must apply the care of a prudent and conscientious manager (subsection 1). A breach makes them jointly and severally liable to the company for the damage; if their care is disputed, they bear the burden of proof (subsection 2).
Section 93(1), second sentence, AktG contains the business judgment rule: there is no breach of duty if, in making an entrepreneurial decision, the board member could reasonably assume to be acting on the basis of adequate information for the benefit of the company. Section 43 GmbHG has no equivalent wording; how the principle applies there is a matter for legal advice. Whether complying with statutory obligations is an entrepreneurial decision in this sense at all, and whether a CRA infringement by the company is at the same time a breach of duty by management, depends on the individual case.
Level 3: product liability under Directive (EU) 2024/2853
The new Product Liability Directive replaces Directive 85/374/EEC as of 9 December 2026 (Article 21). It applies to products placed on the market or put into service after 9 December 2026 (Article 2(1)), and Member States must transpose it by that date (Article 22(1)). Recital 31 of the CRA describes it as complementary to the Regulation. For manufacturers of digital products these points matter:
- Software is a product (Article 4(1)).
- Defectiveness: a product is defective where it does not provide the safety that a person is entitled to expect or that is required under Union or national law (Article 7(1)). Relevant factors include product safety requirements, including safety-relevant cybersecurity requirements (Article 7(2)(f)).
- Presumption: defectiveness is presumed, subject to rebuttal (Article 10(5)), where the claimant demonstrates that the product does not comply with mandatory product safety requirements intended to protect against the risk of the damage suffered (Article 10(2)(b)). Whether a CRA requirement qualifies in a given case is a question of interpretation.
- Software and security updates: the defence that the defect did not yet exist when the product was placed on the market is not available where the defect is due to software, including updates or upgrades, or to a lack of updates or upgrades necessary to maintain safety, if within the manufacturer's control (Article 11(2)(b) and (c)). The Directive itself imposes no obligation to provide updates (recital 51). Update duties follow from the CRA, for example Article 13(8) and Annex I Part II point 2 (see support period and update duty).
- Who is liable, and to whom: mainly the manufacturer, and also the manufacturer of a defective component integrated under the manufacturer's control that caused the product to be defective; if the manufacturer is established outside the Union, also the importer and authorised representative, failing those the fulfilment service provider (Article 8(1); further cases in paragraphs 2 to 4). Natural persons who suffer damage have the right to compensation, as do persons to whom their claim has passed or who act on their behalf (Article 5); damage to property used exclusively for professional purposes and to data used for professional purposes is not covered (Article 6(1)). Liability towards the injured person cannot be limited or excluded by contract (Article 15), and a third party exploiting a vulnerability does not reduce it towards that person (Article 13(1), recital 55).
This liability, too, lies with the company as economic operator; the Directive does not address personal liability of board members. On German transposition: on 8 October 2026 the Bundestag adopted the Federal Government's bill to modernise product liability law (printed paper 21/4297) in the version recommended by the Committee on Legal Affairs and Consumer Protection (printed paper 21/8429). The Bundesrat has scheduled the act for its session on 16 October 2026; its second passage and promulgation in the Federal Law Gazette were pending as of this article's date.
What management can do organisationally
Organisational measures do not release anyone from liability. They can, however, document that management informed itself, assigned responsibilities and exercised oversight, the points to which section 93(1), second sentence, AktG (adequate information) and section 130(1) OWiG (supervisory measures, selection and monitoring of supervisory staff) refer. Whether that suffices is a legal question. More in our article The Cyber Resilience Act for management.
- Assign responsibilities: who owns the CRA programme, who decides on notifications under Article 14, who deputises? External coordination is available from a product security officer.
- Set up reporting lines: regular reports to management with status per product, open risks and decisions required, plus an escalation route for vulnerabilities and incidents (see reporting process and PSIRT).
- Document decisions: for example on role, product class and support period, each with the information it was based on and, where needed, the view of your legal department or counsel.
- Establish where you stand: if there is no programme yet, a CRA gap analysis shows for each product how far it is from the requirements and ends with a prioritised action plan.
- Have the status reviewed independently: for a running programme, the CRA readiness audit by Blackfort Technology reviews its status on samples of the evidence and reports to management with a rating per product. If Blackfort Technology has contributed to your CRA programme, we disclose this before the engagement and mark parts we implemented ourselves in the report as not independently assessed. The audit is not a conformity assessment, not a certificate and not a legal service. On evidence, see checking CRA readiness.
Note
This article is general information as of 9 October 2026 and is not legal advice. Whether you or your company may be liable in a specific case is for your legal department or a law firm. Blackfort Technology does not provide legal services.
Frequently asked questions
Are managing directors personally liable for CRA fines?+
Can a recall be ordered in addition to a fine?+
Which authority is responsible for the CRA in Germany?+
Does the new product liability regime cover software and missing security updates?+
Does the business judgment rule protect management in CRA decisions?+
Does a CRA audit release management from liability?+
Can CRA fines be imposed today?+
Sources
- Verordnung (EU) 2024/2847 (Cyber Resilience Act), Art. 3, 13, 14, 19 bis 22, 24, 52 bis 60, 64, 65, 71, Anhang I, EUR-Lex
- Richtlinie (EU) 2024/2853 über die Haftung für fehlerhafte Produkte, EUR-Lex
- § 9 OWiG (Handeln für einen anderen)
- § 30 OWiG (Geldbuße gegen juristische Personen und Personenvereinigungen)
- § 130 OWiG (Aufsichtspflichtverletzung)
- § 43 GmbHG (Haftung der Geschäftsführer)
- § 93 AktG (Sorgfaltspflicht und Verantwortlichkeit der Vorstandsmitglieder)
- § 38 BSIG (Umsetzungs-, Überwachungs- und Schulungspflicht für Geschäftsleitungen besonders wichtiger Einrichtungen und wichtiger Einrichtungen)
- Bundestags-Drucksache 21/6134: Regierungsentwurf CRA-Durchführungsgesetz
- Deutscher Bundestag: Erste Lesung CRA-Durchführungsgesetz am 11. Juni 2026
- Bundesrat: Beratungsvorgang 260/26 (CRA-Durchführungsgesetz)
- Bundestags-Drucksache 21/6512: Stellungnahme des Bundesrates zum Entwurf des CRA-Durchführungsgesetzes
- Bundestags-Drucksache 21/4297: Regierungsentwurf Modernisierung des Produkthaftungsrechts
- Bundestags-Drucksache 21/8429: Beschlussempfehlung und Bericht des Ausschusses für Recht und Verbraucherschutz zur Modernisierung des Produkthaftungsrechts
- Deutscher Bundestag: Modernisierung des Produkthaftungsrechts, Beschluss vom 8. Oktober 2026
- Bundesrat: Tagesordnung der 1069. Sitzung am 16. Oktober 2026, TOP 46 (Gesetz zur Modernisierung des Produkthaftungsrechts und zur Änderung weiterer Vorschriften)
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).