CRA vs NIS2: Quick Comparison
| Cyber Resilience Act (CRA) | NIS2 Directive | |
|---|---|---|
| Focus | Product security | Organizational security |
| Applies to | Manufacturers, importers, distributors of digital products | Essential and important entities (operators of critical services) |
| Legal type | Regulation (directly applicable) | Directive (requires national transposition) |
| Key deadline | December 2027 (full application) | October 2024 (national transposition) |
| Max penalty | €15M or 2.5% global turnover | €10M or 2% global turnover |
| CE marking | Required for products | Not applicable |
| Size threshold | No size threshold (applies to all) | Medium-size companies and above (50+ employees, €10M+ revenue) |
Key Difference: Products vs Organizations
CRA: Product-Focused
The CRA regulates the products themselves:
- Hardware with digital elements (IoT, connected devices)
- Software products (apps, SDKs, libraries)
- Security requirements built into the product
- CE marking for EU market access
Think: "Is my product secure?"
NIS2: Organization-Focused
NIS2 regulates how organizations operate:
- Incident reporting requirements
- Risk management policies
- Supply chain security
- Management accountability
Think: "Is my organization cyber-resilient?"
The Simple Rule
CRA = CRA = If you make digital products sold in the EU
NIS2 = NIS2 = If you operate essential or important services in the EU
Where CRA and NIS2 Overlap
Both regulations share common goals and some organizations may need to comply with both: both:
Supply Chain Security
NIS2 requires organizations to manage cybersecurity risks in their supply chain. This means they must ensure third-party products they use are secure—which is exactly what CRA enforces on manufacturers.
Example: A hospital (NIS2 essential entity) procures medical IoT devices (CRA-regulated products). The hospital must verify the devices meet CRA security requirements as part of their NIS2 supply chain obligations.
Incident Reporting
Both regulations require reporting to authorities:
- CRA: Report actively exploited vulnerabilities to ENISA within 24 hours
- NIS2: Report significant incidents to national CSIRT within 24 hours
Dual Compliance Scenario
If your organization both:
- Operates essential services (NIS2), AND
- Manufactures digital products (CRA)
...you need to comply with both regulations. For example, a software company that provides critical infrastructure services and also sells commercial software products.
Implementation Timelines
NIS2: National transposition deadline
CRA: Published and enters into force
CRA: Vulnerability reporting obligations apply
CRA: Full application of all requirements
Key Takeaway
NIS2 is already in effect (via national laws). CRA has a longer runway until 2027, but organizations should start preparing now—especially for the September 2026 vulnerability reporting deadline.
Penalties Comparison
CRA Penalties
- Non-compliance: Up to €15M or 2.5% global turnover
- Documentation issues: Up to €10M or 2% turnover
- Market access: Products can be banned from EU market
NIS2 Penalties
- Essential entities: Up to €10M or 2% global turnover
- Important entities: Up to €7M or 1.4% turnover
- Management: Personal liability for executives
Which Regulation Applies to You?
"I'm a software company selling SaaS products"
CRA: Likely applies to downloadable components (apps, SDKs, agents). Pure SaaS (browser-only) may be exempt. NIS2: May apply if you're a "digital infrastructure" or "ICT service management" provider of sufficient size.
"I manufacture IoT/connected devices"
CRA: Definitely applies. Your devices must meet all essential cybersecurity requirements before selling in the EU. NIS2: Unlikely unless you also operate critical infrastructure.
"I run a hospital/utility/bank"
NIS2: Almost certainly applies as an "essential entity." CRA: Only applies if you also manufacture digital products. But you'll need to ensure procured products are CRA-compliant.
"I'm a small startup"
CRA: Applies regardless of company size if selling digital products in EU. NIS2: Likely exempt due to size thresholds (generally 50+ employees, €10M+ revenue).
Check Your CRA Obligations
Our free assessment helps you understand exactly which CRA requirements apply to your product category.
Take Free Assessment