Draft EU legislation, set to be unveiled next week, mandates IoT product makers to meet cybersecurity rules or face heavy fines of €15M or 2.5% of turnover
Companies will face fines of €15mn or 2.5% of turnover if they do not comply with cyber security requirements
Context & Ripple Effects
This draft is the next step in a decade-long Brussels arc: the EU passed its first cybersecurity law in 2016, imposing security and reporting duties on businesses and forcing member-state cooperation on network security, and the UK followed by fining laggards in critical industries up to £17M under the NIS directive. What changes here is the target — from network operators to the products themselves.
First-order effects
- IoT and smart-device makers selling into the EU must now treat security as a pre-market requirement, not a patch-after-ship practice, or face fines of €15M or 2.5% of turnover.
- The penalty structure copies the template floated in the leaked EU AI rules, which set non-compliance fines at €20M or 4% of turnover — signaling Brussels standardizing turnover-based penalties across tech regimes.
Second-order effects
- Device makers will push security testing and certification costs upstream to component suppliers and downstream into retail prices, reshaping who can profitably sell connected hardware into Europe.
- The proposal formalized days later as the Cyber Resilience Act gives compliant vendors a marketing wedge against cheaper rivals, pressuring the whole category toward audited-by-default products.
Third-order effects
- Enforcement credibility is the open question: the EU later chose to impose only minimal fines on Apple and Meta under the DMA, far below its caps, to avoid friction with Washington — if that restraint carries over, the €15M threat may bite selectively rather than uniformly.
- If the pattern holds, the EU's combined product-security regimes effectively write the default spec for global IoT hardware, since few manufacturers will build separate insecure SKUs for other markets.
The trend: Brussels is extending its regulatory reach from networks and platforms down to individual connected products, using turnover-based fines as the enforcement lever across successive tech laws.