NIS2 vs the Cyber Resilience Act: How They Overlap

Add as a preferred source on Google

NIS2 and the Cyber Resilience Act (CRA) are both cornerstone EU cybersecurity laws, but they govern fundamentally different things: NIS2 regulates how organizations manage cyber risk, while the CRA regulates the security of the digital products those organizations build and sell. Many companies are subject to both at once, which is precisely why the two are so often confused.

If you lead security or compliance at a company that operates critical services and ships software or connected hardware, understanding the boundary between "NIS2 vs Cyber Resilience Act" is not academic: it determines who inside your organization owns which obligation, and against which deadline. This analysis breaks down what each instrument covers, where they reinforce each other, and where they diverge.

What NIS2 governs

NIS2 is Directive (EU) 2022/2555, formally the Directive on measures for a high common level of cybersecurity across the Union. It replaced the original 2016 NIS Directive (Directive (EU) 2016/1148), with the transposition deadline for Member States set at 17 October 2024.

NIS2 is about organizational security. It applies to entities operating in sectors the EU considers critical or important: energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure (including cloud providers, data centres, DNS and TLD registries, and CDNs), public administration, space, postal services, waste management, food, and manufacturing of certain products, among others.

Entities in scope are split into two tiers:

  • Essential entities: typically larger operators in the most critical sectors (broadly, organizations above 250 employees, or with turnover exceeding EUR 50 million).
  • Important entities: medium-sized organizations in covered sectors (broadly, 50+ employees) and certain others.

Both tiers carry the same core obligations; the difference lies mainly in the intensity of supervision and the level of penalties. Those core obligations include implementing risk-management measures (Article 21) covering incident handling, supply-chain security, encryption, access control and business continuity; incident reporting (Article 23); and, notably, management-body accountability. Under Article 20, senior management must approve and oversee cybersecurity measures and can be held personally liable.

NIS2's incident-reporting timeline is one of its sharpest edges: an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within one month.

What the CRA governs

The Cyber Resilience Act is Regulation (EU) 2024/2847. Because it is a regulation rather than a directive, it applies directly and uniformly across all Member States without needing national transposition. It entered into force on 10 December 2024.

The CRA is about product security. It sets mandatory cybersecurity requirements for "products with digital elements": essentially any software or hardware product that connects to a device or network, from operating systems and password managers to smart home devices, industrial control components, and IoT hardware. The obligation attaches to economic operators (chiefly manufacturers, but also importers and distributors) who make such products available on the EU market.

Crucially, the CRA governs security across the entire product lifecycle. Manufacturers must:

  • Design and build products to meet essential cybersecurity requirements (no known exploitable vulnerabilities at release, secure default configuration, and so on).
  • Provide security updates, typically for a defined support period.
  • Handle vulnerabilities throughout the support period and maintain a coordinated disclosure process.
  • Produce technical documentation, carry out conformity assessment, and affix the CE marking to demonstrate compliance.

The CRA phases in over several years. The headline dates:

  • 11 June 2026: the provisions on notification of conformity-assessment bodies (Chapter IV) begin to apply, so the certification infrastructure can be stood up ahead of full application.
  • 11 September 2026: the reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of their products to ENISA and the relevant national CSIRTs.
  • 11 December 2027: the main body of obligations applies, including the essential requirements, conformity assessment, and CE marking.

Where they overlap and where they diverge

The clearest way to frame "CRA vs NIS2" is by object of regulation. NIS2 asks: Is your organization managing cyber risk to an adequate standard? The CRA asks: Are the products you place on the market secure by design and kept secure over their lifetime?

They overlap most visibly in vulnerability and incident reporting. Both regimes impose duties to report to authorities including ENISA and national CSIRTs, and both are concerned with actively exploited vulnerabilities. But the trigger differs: NIS2 reporting is triggered by a significant incident affecting your organization's services, whereas CRA reporting is triggered by a vulnerability or severe incident affecting a product you manufacture. A single event (say, an exploited flaw in software you both operate and sell) could conceivably engage both reporting channels on different timelines.

They also reinforce each other on supply-chain security. NIS2 requires in-scope entities to manage the security of their suppliers and products. When those suppliers become subject to the CRA, their products carry a demonstrable, CE-marked security baseline, which makes an NIS2 entity's supply-chain due diligence easier to evidence. In effect, the CRA raises the floor for the components that NIS2 organizations depend on.

Where they diverge is in mechanism and enforcement. NIS2 is a directive, so its precise obligations, thresholds, and penalties vary by Member State implementation. The CRA is a regulation with a single, uniform text and a product-conformity enforcement model built on market surveillance and CE marking, closer in spirit to product-safety law than to organizational risk regulation.

Dimension NIS2 Cyber Resilience Act
Legal instrument Directive (EU) 2022/2555 (requires national transposition) Regulation (EU) 2024/2847 (directly applicable)
What it regulates Organizational cybersecurity risk management of entities Cybersecurity of products with digital elements, across their lifecycle
Who's in scope Essential and important entities in critical/important sectors (broadly medium and large organizations) Manufacturers, importers and distributors placing products with digital elements on the EU market
Key obligations Risk-management measures, management accountability, incident reporting (24h / 72h / 1 month) Secure-by-design requirements, security updates, vulnerability handling, conformity assessment, CE marking
Timeline Transposition deadline 17 October 2024 Entered into force 10 Dec 2024; reporting from 11 Sep 2026; full application 11 Dec 2027
Penalties Essential: up to €10M or 2% of worldwide turnover; important: up to €7M or 1.4% (minimum floors; Member States may set higher) Fines up to €15M or 2.5% of worldwide turnover for breaches of essential requirements

Who is caught by both

Plenty of organizations sit squarely in both regimes. Consider a mid-sized industrial automation company: it operates within a NIS2 sector (manufacturing and, potentially, digital infrastructure), so it must meet NIS2's organizational obligations, and it ships programmable controllers and connected software, so those products fall under the CRA.

The same is true of many cloud and software vendors, medical-device makers with connected components, energy-sector technology suppliers, and IoT manufacturers that also run critical services. For these companies, NIS2 and the CRA are not alternatives to choose between; they are parallel obligations that land on different teams. NIS2 typically becomes the CISO's and the board's problem; the CRA typically becomes the product, engineering, and regulatory-affairs teams' problem. The risk is that each assumes the other has it covered.

The differing timelines

Timeline mismatch is one of the most practical pitfalls. NIS2's transposition deadline has already passed (17 October 2024), and enforcement in Member States is ramping up now. The obligation is live. The CRA, by contrast, phases in later: reporting duties from 11 September 2026 and the bulk of product requirements from 11 December 2027.

That gap means it is entirely possible to be fully exposed to NIS2 enforcement today while the CRA product obligations are still on the horizon. Teams that treat "EU cyber compliance" as a single project with one deadline will misjudge both. The correct posture is to treat them as two tracks with distinct milestones, and to recognize that CRA readiness (especially secure-by-design and vulnerability handling) benefits from being started well before the 2027 cliff.

Practical implications

For security and compliance leaders, a few conclusions follow directly from the NIS2-vs-Cyber-Resilience-Act comparison:

  • Map both regimes to owners. Confirm which parts of the organization are in NIS2 scope and which product lines are in CRA scope, and assign a named owner to each. Overlap is common; unassigned overlap is where failures happen.
  • Consolidate vulnerability and incident reporting. Because both regimes involve reporting to ENISA and national CSIRTs on overlapping subject matter, build a single internal process that can satisfy both triggers rather than two disconnected ones.
  • Use the CRA to strengthen NIS2 supply-chain evidence. CE-marked, CRA-compliant components give NIS2 entities a cleaner audit trail for supplier security.
  • Track the two timelines separately. NIS2 is enforceable now; CRA obligations arrive in September 2026 and December 2027. A single "done" date will leave gaps.
This article is general information, not legal advice. Always verify against the official texts on EUR-Lex.