Cross-Regulation Quick Reference Last updated: September 10, 2026

Related EU Regulations

Use these five overlap cards to quickly identify how CRA intersects with other EU rules that commonly apply to software and connected products.

Quick-Reference Overlap Cards

Each card shows scope, CRA overlap, and your first implementation action.

NIS2 Directive

Scope: Entity-level cybersecurity and incident governance for essential and important entities.

CRA overlap: CRA secures products; NIS2 secures organisations operating critical services. Many companies need both.

First action: Align product security controls with NIS2 risk management and supplier governance evidence.

Open CRA vs NIS2 →

EU AI Act

Scope: Risk-based obligations for AI systems, especially high-risk systems and transparency duties.

CRA overlap: CRA imposes cybersecurity-by-design for digital products; AI Act adds AI-specific governance and safety obligations.

First action: Map AI system risk class, then align AI lifecycle controls with CRA technical documentation and post-market processes.

AI Act overview →

GDPR

Scope: Protection of personal data, lawful processing, accountability, and data subject rights.

CRA overlap: CRA drives security controls that support GDPR Article 32, but GDPR adds privacy-law obligations beyond product security.

First action: Link CRA security controls to your DPIA, records of processing, and breach response playbooks.

Open GDPR text →

Machinery Regulation (EU) 2023/1230

Scope: Safety and cybersecurity requirements for machinery, industrial automation, and connected equipment.

CRA overlap: Industrial IoT and robotics often face both CRA and Machinery Regulation requirements.

First action: Plan one evidence package that covers functional safety and cybersecurity requirements together.

Open Machinery guide →

General Product Safety Regulation (GPSR)

Scope: Horizontal consumer product safety framework, including online marketplace and recall obligations.

CRA overlap: CRA handles cybersecurity for digital elements; GPSR covers broader consumer product safety and corrective actions.

First action: Coordinate vulnerability disclosures, safety notices, and recall workflows across legal teams.

Open GPSR text →

Implementation Note

A single product can trigger multiple EU obligations at once. Keep one shared evidence inventory and map each artifact to every applicable regulation.