Skip to content

COMPARISON · CRA

CRA vs NIS2: what is different, what overlaps

The two frameworks are often confused because both concern cybersecurity, but they regulate different things and apply to different obligations.

LAST REVIEWED

What is different

  • Subject of regulation: the CRA regulates the product; NIS2 regulates the operator's management of its own network and information systems.
  • Legal form: the CRA is a Regulation, directly applicable in all member states; NIS2 is a Directive, transposed into national law with some variation.
  • Who is in scope: the CRA applies to manufacturers, importers and distributors of products with digital elements; NIS2 applies to entities operating in listed essential and important sectors, such as energy, transport, health and digital infrastructure.
  • Obligations: the CRA sets product-level requirements — secure development, vulnerability handling, conformity assessment, CE marking; NIS2 sets organisational requirements — risk management measures, governance accountability and incident reporting for the operator's own operations.
  • Enforcement: the CRA is enforced through market surveillance authorities and conformity assessment; NIS2 is enforced through national competent authorities designated under each member state's transposing law.

What overlaps

Both frameworks require incident and vulnerability reporting on short timelines, both expect a documented risk-based approach, and both push organisations towards continuous security management rather than a one-off assessment. An operator subject to NIS2 that also manufactures or integrates connected products will find that CRA vulnerability handling and NIS2 incident response processes should share the same intake and escalation path, not run as separate systems.

Supply chain expectations also overlap: NIS2 asks operators to manage cybersecurity risk in their supply chains, and the CRA requires manufacturers to understand the security of the components they integrate. An organisation doing both should build one supplier risk process, not two.

Which applies to you

  • You manufacture or sell hardware or software products with digital elements into the EU market: the CRA applies to you as a manufacturer, regardless of sector.
  • You operate infrastructure or services in a sector listed in NIS2's annexes and meet the size thresholds: NIS2 applies to you as an operator.
  • You do both — for example, an energy operator that also develops its own connected control products: both apply, and your governance structure should reflect that a single vulnerability can trigger obligations under each framework.
  • You are a small supplier to a NIS2-regulated operator: you may not be directly in NIS2 scope, but your customer's supply chain obligations will reach you contractually.
Treat product security and operational security as one management system with two sets of reporting clocks, not two separate compliance programmes.

Frequently asked questions

Can a company be subject to both the CRA and NIS2?

Yes. A company that manufactures products with digital elements and also operates infrastructure in a sector covered by NIS2 is subject to both. The obligations are separate but should be managed through a shared risk and incident process to avoid duplicated or conflicting reporting.

Does complying with NIS2 satisfy CRA requirements?

No. NIS2 compliance addresses an organisation's own operational risk management; it does not cover product-level requirements such as secure-by-design development, vulnerability disclosure processes for a specific product, or CE marking under the CRA. The two must be assessed separately.

Do the CRA and NIS2 use the same incident reporting timelines?

Both use short, similarly structured timelines — an early notification followed by a fuller report — but they are legally distinct obligations to different authorities, for different triggering events. Organisations subject to both should map the definitions carefully rather than assume one report satisfies both.

Which came first, the CRA or NIS2?

NIS2 (Directive (EU) 2022/2555) was adopted first and member states transposed it into national law. The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024, with obligations phasing in through 2026 and 2027.

Is the CRA a directive like NIS2?

No. The CRA is a Regulation, which applies directly and uniformly across all EU member states without national transposition. NIS2 is a Directive, meaning each member state passes its own implementing law, which can introduce minor variations between countries.