Comparison Guide Last updated: September 5, 2026

CRA vs NIS2: Which EU Regulation Applies to You?

The EU has released two major cybersecurity regulations. The CRA targets products, while NIS2 targets organizations. Here's how they differ—and where they overlap.

CRA vs NIS2: Quick Comparison

Cyber Resilience Act (CRA) NIS2 Directive
Focus Product security Organizational security
Applies to Manufacturers, importers, distributors of digital products Essential and important entities (operators of critical services)
Legal type Regulation (directly applicable) Directive (requires national transposition)
Key deadline December 2027 (full application) October 2024 (national transposition)
Max penalty €15M or 2.5% global turnover €10M or 2% global turnover
CE marking Required for products Not applicable
Size threshold No size threshold (applies to all) Medium-size companies and above (50+ employees, €10M+ revenue)

Key Difference: Products vs Organizations

CRA: Product-Focused

The CRA regulates the products themselves:

  • Hardware with digital elements (IoT, connected devices)
  • Software products (apps, SDKs, libraries)
  • Security requirements built into the product
  • CE marking for EU market access

Think: "Is my product secure?"

NIS2: Organization-Focused

NIS2 regulates how organizations operate:

  • Incident reporting requirements
  • Risk management policies
  • Supply chain security
  • Management accountability

Think: "Is my organization cyber-resilient?"

The Simple Rule

CRA = CRA = If you make digital products sold in the EU
NIS2 = NIS2 = If you operate essential or important services in the EU

Where CRA and NIS2 Overlap

Both regulations share common goals and some organizations may need to comply with both: both:

Supply Chain Security

NIS2 requires organizations to manage cybersecurity risks in their supply chain. This means they must ensure third-party products they use are secure—which is exactly what CRA enforces on manufacturers.

Example: A hospital (NIS2 essential entity) procures medical IoT devices (CRA-regulated products). The hospital must verify the devices meet CRA security requirements as part of their NIS2 supply chain obligations.

Incident Reporting

Both regulations require reporting to authorities:

  • CRA: Report actively exploited vulnerabilities to ENISA within 24 hours
  • NIS2: Report significant incidents to national CSIRT within 24 hours

Dual Compliance Scenario

If your organization both:

  • Operates essential services (NIS2), AND
  • Manufactures digital products (CRA)

...you need to comply with both regulations. For example, a software company that provides critical infrastructure services and also sells commercial software products.

Implementation Timelines

October 2024

NIS2: National transposition deadline

December 2024

CRA: Published and enters into force

September 2026

CRA: Vulnerability reporting obligations apply

December 2027

CRA: Full application of all requirements

Key Takeaway

NIS2 is already in effect (via national laws). CRA has a longer runway until 2027, but organizations should start preparing now—especially for the September 2026 vulnerability reporting deadline.

Penalties Comparison

CRA Penalties

  • Non-compliance: Up to €15M or 2.5% global turnover
  • Documentation issues: Up to €10M or 2% turnover
  • Market access: Products can be banned from EU market

NIS2 Penalties

  • Essential entities: Up to €10M or 2% global turnover
  • Important entities: Up to €7M or 1.4% turnover
  • Management: Personal liability for executives

Which Regulation Applies to You?

"I'm a software company selling SaaS products"

CRA: Likely applies to downloadable components (apps, SDKs, agents). Pure SaaS (browser-only) may be exempt. NIS2: May apply if you're a "digital infrastructure" or "ICT service management" provider of sufficient size.

"I manufacture IoT/connected devices"

CRA: Definitely applies. Your devices must meet all essential cybersecurity requirements before selling in the EU. NIS2: Unlikely unless you also operate critical infrastructure.

"I run a hospital/utility/bank"

NIS2: Almost certainly applies as an "essential entity." CRA: Only applies if you also manufacture digital products. But you'll need to ensure procured products are CRA-compliant.

"I'm a small startup"

CRA: Applies regardless of company size if selling digital products in EU. NIS2: Likely exempt due to size thresholds (generally 50+ employees, €10M+ revenue).

Check Your CRA Obligations

Our free assessment helps you understand exactly which CRA requirements apply to your product category.

Take Free Assessment