CRA vs NIS2 is the comparison every European security team now has to make, because the two instruments arrived a year apart, use the same vocabulary — incidents, vulnerabilities, 24-hour early warnings — and regulate completely different things. NIS2, Directive (EU) 2022/2555, regulates organisations: essential and important entities in eighteen sectors must manage cyber risk and report significant incidents to their national authority, under national laws that applied from 18 October 2024.
The Cyber Resilience Act, Regulation (EU) 2024/2847, regulates products: anything with digital elements placed on the EU market must meet essential cybersecurity requirements, carry a CE marking and be supported for at least five years, with the manufacturer reporting actively exploited vulnerabilities to ENISA from 11 September 2026 and everything else applying from 11 December 2027. This guide sets out the seven differences that matter, the two places where the instruments deliberately touch, and how an organisation that is both a NIS2 entity and a CRA manufacturer should run the two programmes.

CRA vs NIS2 at a glance
| Dimension | NIS2 — Directive (EU) 2022/2555 | CRA — Regulation (EU) 2024/2847 |
|---|---|---|
| Legal form | Directive: transposed into 27 national laws by 17 October 2024, applied from 18 October 2024 (Article 41). The national law binds | Regulation: directly applicable in every Member State without transposition |
| Who is regulated | Essential and important entities — medium and large organisations in the Annex I and II sectors, plus some regardless of size (Article 3) | Manufacturers, importers and distributors of products with digital elements, wherever established, that place products on the EU market; open-source software stewards to a limited extent (Article 24) |
| What is regulated | The security of the network and information systems an entity uses for its operations and services (Article 21) | The product itself: design, development, production and vulnerability handling for the support period (Article 13, Annex I) |
| The core obligation | Ten risk-management measures, Article 21(2)(a)–(j), all-hazards | Essential requirements in Annex I Part I (product properties) and Part II (vulnerability handling); conformity assessment; CE marking; technical documentation |
| What is reported | Significant incidents affecting the entity’s services (Article 23) | Actively exploited vulnerabilities in the product and severe incidents affecting its security (Article 14) |
| To whom | The national CSIRT or competent authority | The CSIRT designated as coordinator and ENISA simultaneously, via the single reporting platform (Article 16) |
| Penalties | Essential entities: at least EUR 10 million or 2% of worldwide turnover; important entities: EUR 7 million or 1.4% (Article 34) | Up to EUR 15 million or 2.5% for Annex I, Article 13 and 14 breaches; EUR 10 million or 2% for other obligations; EUR 5 million or 1% for misleading information (Article 64) |
| Management accountability | Management bodies approve and oversee the measures and can be held liable (Article 20) | None equivalent; the manufacturer as economic operator is liable |
| Application | From 18 October 2024 (national laws) | Article 14 reporting from 11 September 2026; notified body chapter from 11 June 2026; the rest from 11 December 2027 (Article 71) |
Difference 1: an entity directive against a product regulation
The first CRA vs NIS2 difference is the question each instrument asks. NIS2 asks whether an organisation is in scope — by sector and by size, with the essential and important tiers of Article 3 — and then regulates how it runs its systems. The CRA asks whether a product is in scope — a product with digital elements whose intended or reasonably foreseeable use includes a data connection, Article 2(1) — and then regulates how it is built and maintained.
A hospital is a NIS2 essential entity; the software vendor whose product the hospital runs is a CRA manufacturer. The same company can be both, and the obligations do not merge. Our guide to NIS2 requirements covers the entity side; the EU CRA guide covers the product side.
Difference 2: what the reporting clocks measure
Both instruments use 24 hours and 72 hours, and the CRA vs NIS2 resemblance ends there. Under NIS2 Article 23(4) an entity submits an early warning within 24 hours and an incident notification within 72 hours of becoming aware of a significant incident affecting its own services, then a final report one month after the notification.
Under CRA Article 14 a manufacturer submits an early warning within 24 hours and a notification within 72 hours of becoming aware of an actively exploited vulnerability in its product, then a final report no later than 14 days after a corrective or mitigating measure is available; for a severe incident affecting the product’s security the final report is due one month after the 72-hour notification.
A NIS2 entity reports because something happened to it. A CRA manufacturer reports because something is wrong with what it sold — and Article 14(8) then obliges it to inform impacted users. Our guide to the CRA reporting deadline covers the 11 September 2026 obligation and Article 69(3), which extends it to products already on the market.
Difference 3: who receives the report
NIS2 reports go to the entity’s national CSIRT or competent authority. CRA reports go through the single reporting platform ENISA operates under Article 16, using the end-point of the CSIRT designated as coordinator in the Member State of the manufacturer’s main establishment, and are simultaneously accessible to ENISA. A manufacturer with no EU establishment reports through the Member State of its authorised representative, importer, distributor or largest user base, in that order under Article 14(7).
Difference 4: measures against essential requirements
NIS2 Article 21(2) lists ten measures an entity must take — risk-analysis policies, incident handling, business continuity, supply chain security, security in acquisition and development including vulnerability handling and disclosure, effectiveness assessment, cyber hygiene and training, cryptography, human resources and access control, and multi-factor authentication. They are organisational and outcome-based. CRA Annex I lists product requirements — no known exploitable vulnerabilities at release, secure-by-default configuration, security updates, access control, confidentiality and integrity protections, attack-surface minimisation, logging — and vulnerability-handling requirements including an SBOM, coordinated vulnerability disclosure and free security updates for the support period. They are demonstrated through conformity assessment, not through a supervisory audit.
Difference 5: enforcement
Enforcement is where CRA vs NIS2 diverges most in practice. NIS2 is supervised by national competent authorities — ex ante for essential entities under Article 32, ex post for important entities under Article 33 — with fines under Article 34. The CRA is enforced by market surveillance authorities under Regulation (EU) 2019/1020: products can be withdrawn or recalled under Articles 54 to 58, and fines under Article 64 fall on the economic operator. NIS2 also reaches the boardroom directly through Article 20; the CRA does not.
Difference 6: certification and CE marking
The CRA is CE-marking law. Default products self-assess; important products in Annex III and critical products in Annex IV need a notified body or a European cybersecurity certification scheme, as set out in Article 32 and worked through in our guide to CRA conformity assessment. NIS2 has no CE marking and no certification of the entity; Article 24 lets Member States require entities to use certified products or services, which is one of the two places the instruments touch.
Difference 7: dates
NIS2 has been live since 18 October 2024, in the form of national laws that differ in detail. The CRA’s obligations arrive in three steps under Article 71: Chapter IV on notified bodies from 11 June 2026, Article 14 reporting from 11 September 2026, and the essential requirements, conformity assessment and CE marking from 11 December 2027.
Where CRA and NIS2 meet
- Supply chain security. NIS2 Article 21(2)(d) requires entities to manage supplier and service-provider risk, and 21(2)(e) requires security in acquisition, including vulnerability handling and disclosure. A CE-marked CRA product with an SBOM and a stated support period is the evidence a NIS2 entity’s procurement can rely on; from December 2027 it becomes the default evidence.
- Shared plumbing. The CRA borrows NIS2’s definitions of incident and near miss, uses the CSIRTs NIS2 designated as coordinators under its Article 12, and feeds ENISA’s reports to the NIS2 Cooperation Group and EU-CyCLONe under Article 17. And Article 8(2)(a) lets the Commission add to the critical-product list any category on which NIS2 essential entities critically depend.
CRA vs NIS2 in one organisation: running both programmes
- Map the two scopes separately. One register of the entity’s NIS2 status by sector and size; one register of products with digital elements by CRA tier.
- Keep two reporting procedures with two triggers. Significant incident affecting services (NIS2) and actively exploited vulnerability or severe incident affecting a product (CRA); one event can trigger both, with different recipients and different final-report clocks.
- Use one vulnerability-handling process. NIS2 21(2)(e) and CRA Annex I Part II both want coordinated disclosure, an SBOM and a patch process; build it once to the CRA’s more specific requirements.
- Reuse the ISO 27001 core. Both programmes sit on the same risk assessment, asset inventory and incident process; our guide to NIS2 vs ISO 27001 covers the mapping.
- Watch the CRA vs NIS2 calendar. NIS2 is now; CRA reporting is 11 September 2026 and reaches the installed base; the rest is December 2027.
Frequently asked questions
What is the main difference between CRA vs NIS2?
NIS2 regulates organisations — essential and important entities must manage cyber risk and report significant incidents — while the CRA regulates products with digital elements, which must meet essential cybersecurity requirements, be CE marked and be supported with security updates, with manufacturers reporting exploited vulnerabilities.
Can a company be subject to both?
Yes. A manufacturer of connected products that is also a medium or large entity in a NIS2 sector owes both sets of obligations, with separate scopes, reporting triggers and recipients.
Are the reporting timelines the same?
Both use 24-hour early warnings and 72-hour notifications, but NIS2 clocks run from a significant incident affecting the entity’s services with a final report one month after notification; CRA clocks run from an actively exploited vulnerability or severe incident in a product, with the vulnerability final report due 14 days after a fix is available and the incident final report one month after notification.
Which has bigger fines?
The CRA’s top tier is higher — up to EUR 15 million or 2.5% of worldwide turnover under Article 64(2), against NIS2’s EUR 10 million or 2% for essential entities under Article 34. NIS2 adds management-body liability under Article 20, which the CRA does not.
Does a CE-marked product satisfy NIS2 supply-chain obligations?
It is strong evidence for Article 21(2)(d) and (e) but not a discharge; the entity still has to assess the supplier relationship and its own use of the product.
Where this leaves you
Read CRA vs NIS2 as two regimes with one vocabulary: NIS2 for what your organisation runs, the CRA for what you sell. Register both scopes, keep two reporting procedures with different triggers and recipients, build vulnerability handling once to the CRA’s standard, and put the dates on the calendar — NIS2 is already live, CRA reporting arrives on 11 September 2026, and the CE-marking obligations follow in December 2027.
References
- Regulation (EU) 2024/2847 — Cyber Resilience Act — Articles 2, 13, 14, 16, 17, 32, 64, 69 and 71; Annex I.
- Directive (EU) 2022/2555 — NIS2 — Articles 3, 20, 21, 23, 24, 32 to 34 and 41.
More on the EU CRA
- CRA vs NIS2 — you are here
- EU CRA: the Cyber Resilience Act explained
- The CRA reporting deadline: 11 September 2026
- CRA penalties: the three fine tiers
- CRA conformity assessment
- NIS2 requirements
The Reporting Obligations Procedure, the Actively Exploited Vulnerability and Severe Incident Reporting Workflows, the Vulnerability Handling Procedure and the Coordinated Vulnerability Disclosure Policy are in the EU CRA Toolkit, or start with the free templates.