Quick-Reference Overlap Cards
Each card shows scope, CRA overlap, and your first implementation action.
NIS2 Directive
Scope: Entity-level cybersecurity and incident governance for essential and important entities.
CRA overlap: CRA secures products; NIS2 secures organisations operating critical services. Many companies need both.
First action: Align product security controls with NIS2 risk management and supplier governance evidence.
Open CRA vs NIS2 →EU AI Act
Scope: Risk-based obligations for AI systems, especially high-risk systems and transparency duties.
CRA overlap: CRA imposes cybersecurity-by-design for digital products; AI Act adds AI-specific governance and safety obligations.
First action: Map AI system risk class, then align AI lifecycle controls with CRA technical documentation and post-market processes.
AI Act overview →GDPR
Scope: Protection of personal data, lawful processing, accountability, and data subject rights.
CRA overlap: CRA drives security controls that support GDPR Article 32, but GDPR adds privacy-law obligations beyond product security.
First action: Link CRA security controls to your DPIA, records of processing, and breach response playbooks.
Open GDPR text →Machinery Regulation (EU) 2023/1230
Scope: Safety and cybersecurity requirements for machinery, industrial automation, and connected equipment.
CRA overlap: Industrial IoT and robotics often face both CRA and Machinery Regulation requirements.
First action: Plan one evidence package that covers functional safety and cybersecurity requirements together.
Open Machinery guide →General Product Safety Regulation (GPSR)
Scope: Horizontal consumer product safety framework, including online marketplace and recall obligations.
CRA overlap: CRA handles cybersecurity for digital elements; GPSR covers broader consumer product safety and corrective actions.
First action: Coordinate vulnerability disclosures, safety notices, and recall workflows across legal teams.
Open GPSR text →