The Cyber Resilience Act (CRA) and NIS2 are both EU cybersecurity laws landing in 2026–2027, but they regulate different things. NIS2 governs how an organisation manages cyber risk; the CRA governs the security of the products a manufacturer places on the market. They don't compete — many companies are caught by both. So the real question isn't "CRA or NIS2?" — it's "which of my obligations is about how I operate, and which is about what I ship?"

CRA vs NIS2 at a glance

  • NIS2: Directive (EU) 2022/2555 — organisational security, 18 sectors, transposed into national law
  • CRA: Regulation (EU) 2024/2847 — product security for manufacturers, directly applicable EU-wide
  • Applies from: NIS2 (national rules) 18 Oct 2024 · CRA reporting 11 Sept 2026, full 11 Dec 2027
  • Relationship: complementary — NIS2 = how you operate, CRA = what you ship; both can apply

What is the CRA?

The Cyber Resilience Act — Regulation (EU) 2024/2847 — is the EU's product-cybersecurity law: essentially CE marking for cybersecurity. Manufacturers of products with digital elements (connected hardware and software) must build securely, ship with no known exploitable vulnerabilities, maintain a vulnerability-handling process and an SBOM, provide updates for a support period, obtain conformity assessment, and report actively exploited vulnerabilities to ENISA within 24 hours. See our full guide to the CRA.

NIS2, by contrast, is the horizontal organisational cybersecurity baseline across 18 sectors — risk management, governance, incident reporting, supply-chain security. For the full picture see our complete guide to NIS2.

CRA vs NIS2: the differences

NIS2CRA
What it regulatesHow an organisation manages cyber riskThe security of products placed on the market
Who it coversEssential & important entities in 18 sectorsManufacturers, importers & distributors of connected products
Legal instrumentDirective — transposed into national lawRegulation — directly applicable, uniform EU-wide
Signature dutiesRisk management, governance, supply-chain security, incident reportingSecure-by-design, SBOM, vulnerability handling, CE marking, updates
PenaltiesUp to €10M / 2% (essential); €7M / 1.4% (important)Up to €15M / 2.5% of global turnover

Which one applies to you?

Do I need to comply with both?

Often, yes — but they don't overlap the way NIS2 and DORA do (where DORA is lex specialis for financial entities). CRA and NIS2 regulate different objects — your products versus your organisation — so both can apply in full at the same time. The good news: the underlying discipline is shared. Both demand vulnerability management, incident reporting, and demonstrable governance. Get your exposure and vulnerability handling under control once, and you evidence it against whichever regime applies.

Quantify it once, map it to each

Whether you answer to NIS2, the CRA, or both, the starting point is the same: an objective read of what's actually exposed and exploitable. Cyber risk quantification maps your external attack surface, weights it by what's actively being exploited (EPSS, CISA KEV, SSVC), and translates it into an Expected Annual Loss in euros. Run a free calculation to see your exposure, or explore how the Nisura framework maps EU regulatory liability.

Sources & official references

General information, not legal advice. Whether CRA and/or NIS2 govern a specific entity or product depends on its activities and national implementing law — confirm with qualified counsel.