The Cyber Resilience Act (CRA) and NIS2 are both EU cybersecurity laws landing in 2026–2027, but they regulate different things. NIS2 governs how an organisation manages cyber risk; the CRA governs the security of the products a manufacturer places on the market. They don't compete — many companies are caught by both. So the real question isn't "CRA or NIS2?" — it's "which of my obligations is about how I operate, and which is about what I ship?"
CRA vs NIS2 at a glance
- NIS2: Directive (EU) 2022/2555 — organisational security, 18 sectors, transposed into national law
- CRA: Regulation (EU) 2024/2847 — product security for manufacturers, directly applicable EU-wide
- Applies from: NIS2 (national rules) 18 Oct 2024 · CRA reporting 11 Sept 2026, full 11 Dec 2027
- Relationship: complementary — NIS2 = how you operate, CRA = what you ship; both can apply
What is the CRA?
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the EU's product-cybersecurity law: essentially CE marking for cybersecurity. Manufacturers of products with digital elements (connected hardware and software) must build securely, ship with no known exploitable vulnerabilities, maintain a vulnerability-handling process and an SBOM, provide updates for a support period, obtain conformity assessment, and report actively exploited vulnerabilities to ENISA within 24 hours. See our full guide to the CRA.
NIS2, by contrast, is the horizontal organisational cybersecurity baseline across 18 sectors — risk management, governance, incident reporting, supply-chain security. For the full picture see our complete guide to NIS2.
CRA vs NIS2: the differences
| NIS2 | CRA | |
|---|---|---|
| What it regulates | How an organisation manages cyber risk | The security of products placed on the market |
| Who it covers | Essential & important entities in 18 sectors | Manufacturers, importers & distributors of connected products |
| Legal instrument | Directive — transposed into national law | Regulation — directly applicable, uniform EU-wide |
| Signature duties | Risk management, governance, supply-chain security, incident reporting | Secure-by-design, SBOM, vulnerability handling, CE marking, updates |
| Penalties | Up to €10M / 2% (essential); €7M / 1.4% (important) | Up to €15M / 2.5% of global turnover |
Which one applies to you?
- You operate critical services (energy, health, transport, digital infrastructure…): NIS2 is your regime. Check whether NIS2 applies to you.
- You manufacture connected hardware or software sold in the EU: the CRA applies to those products — regardless of your size or sector.
- You do both (e.g. an industrial-equipment maker that is also an important entity): you'll answer to NIS2 for your organisation and the CRA for your products. They stack.
Do I need to comply with both?
Often, yes — but they don't overlap the way NIS2 and DORA do (where DORA is lex specialis for financial entities). CRA and NIS2 regulate different objects — your products versus your organisation — so both can apply in full at the same time. The good news: the underlying discipline is shared. Both demand vulnerability management, incident reporting, and demonstrable governance. Get your exposure and vulnerability handling under control once, and you evidence it against whichever regime applies.
Quantify it once, map it to each
Whether you answer to NIS2, the CRA, or both, the starting point is the same: an objective read of what's actually exposed and exploitable. Cyber risk quantification maps your external attack surface, weights it by what's actively being exploited (EPSS, CISA KEV, SSVC), and translates it into an Expected Annual Loss in euros. Run a free calculation to see your exposure, or explore how the Nisura framework maps EU regulatory liability.
Sources & official references
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — scope, essential requirements, and phased application.
- Directive (EU) 2022/2555 (NIS2) — sectors, entity classes, and organisational obligations.
- European Commission & ENISA — CRA product classes and coordinated vulnerability reporting.
General information, not legal advice. Whether CRA and/or NIS2 govern a specific entity or product depends on its activities and national implementing law — confirm with qualified counsel.