Policy

EU Cyber Resilience Act Enters Enforcement Phase — Fines Up to €15M for Non-Compliance

EU Agency for CybersecurityMarch 12, 20262 min read
EU Cyber Resilience Act Enters Enforcement Phase — Fines Up to €15M for Non-Compliance

The European Union's Cyber Resilience Act has entered its enforcement phase, requiring manufacturers of digital products to meet mandatory cybersecurity requirements. Non-compliance penalties can reach €15 million or 2.5% of global annual turnover.

EU Agency for Cybersecurity reports the details above as part of its ongoing coverage in the policy space. The picture is likely to sharpen over the coming days as other researchers weigh in.

For security teams, the practical question is always the same: what changes because of this? Policy sets the floor for security programmes and carries real penalties. Confirm which obligations apply to you and where the current gaps are.

Follow the source link below for the full report and any indicators of compromise the original authors have published.

Related articles