Cyber Resilience Act
CRA vs NIS2: products, organisations and where they meet
The Cyber Resilience Act regulates products with digital elements and their manufacturers; the NIS2 Directive regulates essential and important organisations and how they manage cybersecurity risk. A company can be subject to both, and the CRA is designed to make the supply-chain part of NIS2 easier to meet.
Free plan, no card required.
The core difference
The CRA is a regulation about products: it applies directly in every Member State and follows the product wherever it is sold in the EU. NIS2, Directive (EU) 2022/2555, is about entities: it had to be transposed into national law by 17 October 2024 and applies to medium-sized and larger organisations in 18 sectors, with some exceptions regardless of size.
The Commission summarises the split this way: the CRA sets cybersecurity requirements for products with digital elements, NIS2 sets requirements for essential and important entities, and software provided as a service is covered by NIS2 rather than the CRA.
Side by side
The two laws use similar reporting windows but different triggers, recipients and penalties.
| Cyber Resilience Act | NIS2 Directive | |
|---|---|---|
| Legal form | Regulation (EU) 2024/2847, directly applicable | Directive (EU) 2022/2555, transposed nationally |
| Who | Manufacturers, importers and distributors of products with digital elements | Essential and important entities in Annex I and II sectors |
| Applies from | Reporting 11 September 2026; everything else 11 December 2027 | 18 October 2024 (national laws) |
| What triggers a report | Actively exploited vulnerability or severe incident in a product | Significant incident affecting the entity's services |
| Deadlines | 24 h early warning, 72 h notification, final report | 24 h early warning, 72 h notification, final report within one month |
| Fines | Up to €15 million or 2.5% of worldwide turnover | At least €10 million or 2% (essential), €7 million or 1.4% (important), set nationally |
Where they meet: the supply chain
Article 21 of NIS2 requires entities to manage supply-chain security and to handle and disclose vulnerabilities when they acquire, develop and maintain systems. Entities must take into account the vulnerabilities of each direct supplier and the quality of its secure development practices.
The CRA's recitals say it aims to make that easier: if the products an entity buys come with SBOMs, security updates and a vulnerability disclosure process, the entity has much of what it needs to assess its suppliers. The two also share infrastructure: the CSIRTs designated as coordinators under NIS2 receive CRA reports, and ENISA's EU Vulnerability Database was set up under NIS2.
Can a company fall under both?
Yes, and it is common. A manufacturer of industrial equipment that is itself a medium-sized company in a NIS2 sector must secure its own operations under national NIS2 law and its products under the CRA. A software company that sells an on-premises product and also runs it as a hosted service can meet both regimes for different offerings.
In practice the same evidence serves both: an inventory of components, a record of vulnerabilities and decisions, and a tested reporting process. Keeping one record avoids answering the same question twice.
- Map which products fall under the CRA and which services under NIS2.
- Use one vulnerability register for products and for internal systems.
- Align incident procedures so a single event can feed both reporting tracks.
- Ask suppliers for SBOMs and security-update commitments in contracts.
Different names in each language
Searches often mix languages. In French the Directive is officially the directive SRI 2 and in Spanish the Directiva SRI 2, while German and Italian texts use NIS 2. The CRA's official short names are règlement sur la cyberrésilience, Cyberresilienz-Verordnung, Reglamento de Ciberresiliencia and regolamento sulla ciberresilienza.
Available in KROMSE today
KROMSE works on the product side, and its records help with the supply-chain questions NIS2 asks.
- SBOMs in CycloneDX and SPDX for repositories, container images and Linux-based firmware.
- Known vulnerabilities in your components, with KEV, EPSS, NVD and ENISA EUVD context.
- CRA response cases and, on paid plans, internal Article 14 drafts for a person to approve and submit.
- Recorded decisions and an evidence pack you can share with customers who ask.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q1 2027 (January)NIS2 module. A NIS2 module will bring risk-management measures, incident timelines and evidence into one place in the product.
- Coming · Q1 2027ISO/IEC 27001 control evidence. Scan results and recorded decisions will be mapped to ISO/IEC 27001 controls as evidence for your audits.
Frequently asked questions
What is the main difference between the CRA and NIS2?
The CRA sets requirements for products with digital elements and applies to their manufacturers, importers and distributors. NIS2 sets cybersecurity risk-management and reporting duties for essential and important organisations in 18 sectors. One is about what you sell, the other about how you run your organisation.
Is SaaS covered by the CRA or by NIS2?
Software provided purely as a service is covered by NIS2 where the provider is in scope, not by the CRA. The CRA can still apply to remote data processing solutions that belong to a product with digital elements, such as the cloud backend a device needs to work.
Do CRA and NIS2 have the same reporting deadlines?
They are similar: both start with a 24-hour early warning and a 72-hour notification. The triggers differ: the CRA is about actively exploited vulnerabilities and severe incidents in products, NIS2 about significant incidents affecting an entity's services. Final reports follow different timelines.
Which should a manufacturer tackle first?
For most manufacturers the CRA has the nearer hard date for products: Article 14 reporting has applied since 11 September 2026, including for products already on the market. If the company is also an essential or important entity, its national NIS2 obligations already apply and the two programmes should share one vulnerability and incident process.
Does NIS2 require an SBOM?
NIS2 does not use the term. It requires supply-chain security and vulnerability handling as part of risk management. The CRA requires manufacturers to draw up an SBOM, which is one way entities can assess the components in the products they buy.