Can a director go to jail under the Cyber Resilience Act? Under the CRA itself, no. The Regulation creates no personal criminal liability for directors, officers, or board members. Its enforcement teeth are administrative fines, and by their own terms those fines bite the company, not the person who chairs its risk committee.
That answer reassures the wrong people. The board members who exhale when they hear it are often the ones carrying the real exposure, because the personal liability is real. It simply does not live in the CRA. It lives in a different instrument of EU law, and in national statutes the CRA never names. Close the file after reading the penalties article and you will mis-file the single largest governance question on your own desk.

The CRA penalty reaches the balance sheet, not the boardroom
Article 64 of the CRA is titled Penalties, and it does exactly one thing to an enforcement target: it sets administrative fines on the offender. Non-compliance with the essential cybersecurity requirements and the core manufacturer obligations can cost up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. The operator-side duties sit in a lower band at €10 million or 2%. The offender the article contemplates is "an undertaking", measured against "its total worldwide annual turnover". That is a legal person. It is your company, not your chief executive.
A fine of that shape is a corporate liability in the plainest sense. It draws down cash, it dents the reputation the board is there to steward, and it is the kind of number that belongs in the risk register with a euro figure beside it. What it does not do is name a natural person or send one anywhere. The arithmetic behind those two bands, and how a market-surveillance authority arrives at a specific figure inside them, is worked through in EP 8.01. For governance purposes the point is narrower: the CRA's own sanction is aimed at the entity. If personal exposure existed only here, a director could treat CRA compliance as an operational matter to be delegated and audited like any other. It does not exist only here.
Where the personal exposure is actually written down
The instrument that reaches the individual is the NIS2 Directive, Directive (EU) 2022/2555, and the provision is Article 20, titled Governance. It is short, and every board secretary in a regulated sector should be able to recite its shape. Member States must ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures the entity takes to comply with Article 21, oversee their implementation, and can be held liable for the entity's infringements of that obligation. A second paragraph requires that members of the management body follow training, so they can identify risks and assess the measures put in front of them.
Read those verbs as a director, not a lawyer. Approve, oversee, be held liable, train. The liability is not a general fiduciary abstraction imported from company law. It is written into a cybersecurity statute and attached to a specific, checkable set of acts. This is the clean line the two regimes draw between them: the CRA fine lands on the company's balance sheet, and NIS2 Article 20 is what reaches the individual sitting on the management body.

One caveat keeps this accurate rather than alarmist. NIS2 Article 20 reaches the management body of an entity that is in NIS2 scope, an essential or important entity as the Directive defines those categories: energy, water, transport, digital infrastructure, and manufacturers of certain product classes among them. Not every company that ships a product with digital elements under the CRA is automatically a NIS2 entity. So the director duty is conditional on the company's regulatory footing. In practice the condition bites hard anyway. Many CRA manufacturers are themselves NIS2 entities, and a large share of their industrial customers plainly are, which is why the operator liability threaded through sectors like water and wastewater utilities puts the same personal duty on the customer's board that the supplier is trying to satisfy. Where NIS2 applies, the obligation on the individual is explicit and cannot be delegated away.
Why the answer is "it varies by member state"
Above NIS2 sits a national layer, and here precision means resisting the urge to quote a statute you have not read. NIS2 is a directive, so member states transpose Article 20 into their own law, and they do it against existing regimes of director duty, company law, and in some cases criminal liability. Germany, France, and the Netherlands each carry general director-duty and gross-negligence doctrines, and several member states provide for director disqualification as a sanction in their own right. The exact reach, the threshold of fault, and whether any of it is criminal rather than civil all vary by member state, and a board operating across the Union has to map its real exposure jurisdiction by jurisdiction rather than assume a single European rule.
What is common across the transpositions is the pattern, not the penalty. Personal exposure attaches where a director knew, or on the evidence should have known, that the entity's cybersecurity measures were inadequate, and failed to act. That is a documentary test. It is answered by what the board did and recorded, or did not. Which is exactly why the discharge of the duty is a filing problem before it is a security problem.
The board discharges this duty on paper, or it does not discharge it
An authority reconstructing a board's conduct after an incident does not have access to the directors' intentions. It has the minutes. If the management body approved the risk-management measures, the approval has to be a minuted decision with a date and a version reference, not a shared assumption that someone signed off at some point. If the board oversaw implementation, oversight has to show up as a recurring agenda item with status reported against it, not a line that appears once a year. If members trained, the training has to be logged. An oversight duty that leaves no trace reads, to a regulator, as an oversight duty that was never performed.
This is where a risk committee earns its standing. The work is not to become fluent in cryptography. It is to run a cadence that produces, every quarter, a record that answers the three NIS2 verbs on their face. Below is the template I hand to boards that want that record to exist before they need it rather than after.

What to minute every quarter
Put this on the risk-committee agenda four times a year. Each line is written so the minute it produces answers a question an authority would otherwise ask you to answer under worse conditions.
Approve: record the decision, not the sentiment.
- The current cybersecurity risk-management measures, by named version and date, were tabled and approved by the management body this quarter (or reaffirmed, if unchanged, with that reaffirmation minuted).
- Any material change to those measures since the last meeting was identified, and the board recorded that it reviewed and approved the change.
Oversee: record that you looked, and what you saw.
- Implementation status was reported against the approved measures, with open gaps, owners, and target dates named in the minute.
- Open security incidents and their regulatory-reporting status were reviewed, including incident-reporting readiness for products still within their support period.
- Supplier and product obligations the company owes downstream (support-period commitments, vulnerability handling) were reviewed as a standing item, not raised ad hoc.
Train: record that the body is competent to judge what it approved.
- Training completion for each member of the management body is logged and current, with date and provider.
- Any newly appointed director has a scheduled onboarding on the cybersecurity risk picture before their first approval vote.
Attribution: keep the two regimes separate in your own papers.
- The corporate exposure (CRA Article 64 administrative fines, sitting on the company) and the personal exposure (NIS2 Article 20 plus national transposition, sitting on the individual) are tracked as distinct risks, so neither is mistaken for the other.
Run that four times a year and the record exists. Skip it, and the intention may well have existed — but the intention is not what gets read back to you in the proceeding. The minute is.