CRA vs NIS2: differences, overlaps and how to manage them together

By the QuantumSec team

With the Cyber Resilience Act entering into force and NIS2 fully applicable since 2024, many companies face a logical question: do I have to comply with both? Are they redundant? Can I reuse the work I've already done for NIS2 in my CRA compliance effort? The answer to the first question is frequently yes, especially if you manufacture software or hardware and also operate a digital service. The answer to the third is also yes, partially. This guide helps you understand the boundaries and the intersections.

What the CRA regulates and who it applies to

The Cyber Resilience Act (Regulation EU 2024/2847) governs the security of products with digital elements before they are placed on the European market. Its logic is that of product regulation: it sets cybersecurity requirements that the manufacturer must build into the design and development of the product before selling it. It applies to manufacturers, importers and distributors of network-connected hardware and software marketed in the EU, regardless of where the manufacturer is based. It does not apply to the operation of services: it does not concern itself with how you manage your infrastructure in production, but with how you design and maintain the product you sell.

What NIS2 regulates and who it applies to

The NIS2 Directive (Directive EU 2022/2555) governs the cybersecurity of operators of essential and important services: the security of their networks, systems and infrastructure in operation. It requires companies operating critical services to implement risk management measures, report incidents and ensure service continuity. It applies to medium and large entities across 18 regulated sectors: energy, transport, banking, healthcare, digital infrastructure, ICT, manufacturing, food and others. It does not directly regulate the security of the products those companies manufacture, but the security of their operations.

The key differences between CRA and NIS2

Object of regulation: the CRA regulates the product (the software or hardware you sell); NIS2 regulates the operator (how you manage your infrastructure and services).

Legal instrument: the CRA is a European regulation, directly applicable in all member states without transposition; NIS2 is a directive, which requires transposition into each member state's national law.

Who is bound: the CRA binds manufacturers of digital products in any sector, of any size and location if they sell in the EU; NIS2 binds operators of services in specific sectors that exceed size thresholds.

What is assessed: the CRA assesses the product before it is placed on the market (ex ante conformity); NIS2 assesses the operator's risk management measures on an ongoing basis.

Marking and certification: the CRA introduces the CE cybersecurity marking; NIS2 has no equivalent company certification scheme.

Penalties: the CRA up to €15M or 2.5% of global turnover; NIS2 up to €10M or 2% for essential entities.

Who do both apply to at once?

The two regulations can apply simultaneously to the same company in very common situations. Examples: a company that manufactures critical-infrastructure management software (the CRA applies because it makes software with digital elements) and that also operates that software as a service for clients in the energy sector (NIS2 applies as a digital service provider). A manufacturer of industrial IoT devices (CRA for making connected hardware) that also provides the cloud management platform as a critical service for industrial facilities (NIS2). A developer of cybersecurity software —firewalls, intrusion detection systems, password managers— (CRA Class I or II) that also delivers managed security services to critical operators (NIS2).

What you can reuse between CRA and NIS2

Many of the controls NIS2 requires for operational risk management are directly reusable in your CRA compliance programme. The most directly applicable are the vulnerability management process —NIS2 requires you to identify and manage vulnerabilities in your infrastructure; the CRA requires the same for your product; the process documents both cases— and the incident management and reporting policy —both NIS2 (notification to the national supervisor) and the CRA (notification to ENISA) require formalised protocols with similar 24/72-hour deadlines. The risk analysis for NIS2 is a valuable source of information for identifying the priority technical requirements of Annex I of the CRA. Furthermore, if you already hold an ISO/IEC 27001 certification, the ISMS covers a significant part of the process controls required by both regulations.

How to design an integrated CRA + NIS2 plan

The key is not to treat CRA and NIS2 as two independent parallel projects. An integrated plan starts from a single inventory of assets and products, where each item is tagged with the regulations that apply to it. The gap analysis covers the requirements of Article 21 of NIS2 and those of Annex I of the CRA simultaneously, identifying the common controls that only need to be implemented once. The documentary deliverables —security policies, incident procedures, risk analyses— are designed to cover both regulations. This not only saves time and resources, but produces a more coherent and sustainable cybersecurity programme.

FAQ

If I comply with NIS2, am I automatically complying with the CRA?

No. NIS2 and the CRA regulate different things. NIS2 requires you to manage the security of your operations; the CRA requires you to ensure the security of the product you manufacture and sell. There are overlapping controls you can reuse, but they are two distinct projects with a different object and different assessment mechanisms.

Are SaaS providers bound by the CRA?

Pure SaaS services with no client-installable components are excluded from the CRA. However, if your SaaS includes a desktop agent, a plugin that installs in the browser, an SDK your clients embed in their applications or any component the user downloads and runs in their environment, that component does fall within the scope of the CRA.