Comparison
CRA vs Cybersecurity Act: the EU Cybersecurity Act (Regulation 2019/881) and the CRA
Reviewed September 2026 against Regulation (EU) 2024/2847, OJ L, 20.11.2024, and Regulation (EU) 2019/881, OJ L 151, 7.6.2019.
Short answer: the EU Cybersecurity Act, Regulation (EU) 2019/881, gives ENISA its mandate and sets up a framework for European cybersecurity certification of ICT products, ICT services, ICT processes and managed security services, and that certification is voluntary unless another law makes it mandatory. The Cyber Resilience Act sets mandatory essential cybersecurity requirements for every product with digital elements placed on the EU market. The two connect at one point: a certificate issued under a Cybersecurity Act scheme can count as evidence of CRA conformity, and for critical products the CRA can make such a certificate compulsory.
What the Cybersecurity Act is
Regulation (EU) 2019/881 of 17 April 2019 carries the official short title “Cybersecurity Act”. It does two things. First, it lays down the objectives, tasks and organisation of ENISA, the European Union Agency for Cybersecurity, and establishes ENISA for an indefinite period as of 27 June 2019, replacing a mandate that Regulation (EU) No 526/2013 had extended only until 19 June 2020. Second, it creates the European cybersecurity certification framework: a mechanism to adopt European cybersecurity certification schemes and to attest that ICT products, ICT services, ICT processes and managed security services evaluated under such a scheme meet specified security requirements.
- Voluntary by default. Article 56(2) of the Cybersecurity Act says certification is voluntary, unless otherwise specified by Union law or Member State law.
- Three assurance levels. For ICT products, ICT services, ICT processes and managed security services, a scheme may specify the levels ‘basic’, ‘substantial’ or ‘high’, commensurate with the risk of the intended use (Article 52(1), as amended by Regulation (EU) 2025/37).
- EUCC is an adopted scheme. Commission Implementing Regulation (EU) 2024/482 of 31 January 2024 adopted the European Common Criteria-based cybersecurity certification scheme (EUCC), built on the Common Criteria of ISO/IEC 15408. It applies from 27 February 2025.
- Amended by Regulation (EU) 2025/37. Regulation (EU) 2025/37 of 19 December 2024 amended the Cybersecurity Act as regards managed security services.
Full texts: Regulation (EU) 2019/881, OJ L 151, 7.6.2019 (Cybersecurity Act), Implementing Regulation (EU) 2024/482 (EUCC) and Regulation (EU) 2025/37.
What the CRA is
The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to a product with digital elements made available on the market where its intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It does not ask whether a product is certified. It asks whether the product meets the essential cybersecurity requirements in Annex I, and it makes the manufacturer demonstrate that through a conformity assessment before the CE marking goes on. The full picture is on the page what the CRA is.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
How the two connect
The CRA refers to the Cybersecurity Act in three places that matter for a manufacturer. The first is a presumption of conformity: a product for which a certificate or an EU statement of conformity has been issued under a Cybersecurity Act scheme is presumed to meet the CRA requirements that the certificate covers, and only those.
“Products with digital elements and processes put in place by the manufacturer for which an EU statement of conformity or certificate has been issued under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881 shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I in so far as the EU statement of conformity or European cybersecurity certificate, or parts thereof, cover those requirements.”
The second is Article 27(9). The Commission may specify, by delegated act, which Cybersecurity Act schemes can be used to demonstrate CRA conformity. A certificate under such a scheme at assurance level ‘substantial’ or higher then removes the need for a third-party conformity assessment for the requirements it covers, which matters for important products in Annex III.
“the issuance of a European cybersecurity certificate issued under such schemes, at least at assurance level ‘substantial’, eliminates the obligation of a manufacturer to carry out a third-party conformity assessment for the corresponding requirements”
The third is the one place where certification stops being voluntary. For critical products listed in Annex IV, the Commission may adopt delegated acts requiring a European cybersecurity certificate, provided a scheme covering those products has been adopted under the Cybersecurity Act and is available to manufacturers.
“to determine which products with digital elements that have the core functionality of a product category that is set out in Annex IV to this Regulation are to be required to obtain a European cybersecurity certificate at assurance level at least ‘substantial’ under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881”
Where no such delegated act exists, a critical product falls back to the procedures open to Class II important products.
“Critical products with digital elements listed in Annex IV shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the following procedures: (a) a European cybersecurity certification scheme in accordance with Article 8(1); or (b) where the conditions in Article 8(1) are not met, any of the procedures referred to in paragraph 3 of this Article.”
Voluntary certification against mandatory requirements
| Cybersecurity Act | Cyber Resilience Act | |
|---|---|---|
| Instrument | Regulation (EU) 2019/881 | Regulation (EU) 2024/2847 |
| What it covers | ICT products, ICT services, ICT processes and managed security services submitted for certification | Every product with digital elements placed on the EU market, unless excluded |
| Binding force | Certification is voluntary unless other Union or national law requires it | The essential requirements are mandatory for products in scope |
| Who acts | Whoever applies for a certificate | Manufacturers, importers and distributors |
| Proof | A European cybersecurity certificate or an EU statement of conformity under a scheme | A conformity assessment, the EU declaration of conformity and the CE marking |
The proposed Cybersecurity Act 2
On 20 January 2026 the Commission presented a cybersecurity package. It includes a proposal for a new regulation, COM(2026) 11, which would repeal Regulation (EU) 2019/881 and replace it with what the proposal calls “The Cybersecurity Act 2”, and a proposal for a directive amending NIS2 for alignment with it. A proposal is not law: until the European Parliament and the Council adopt a text, Regulation (EU) 2019/881 is the Cybersecurity Act in force. Text of the proposal: COM(2026) 11 on EUR-Lex.
The EU cybersecurity regulation map
“EU cybersecurity regulation” is not one law. Each act below regulates a different thing, and each comparison page sets out how it relates to the CRA.
- Cyber Resilience Act, Regulation (EU) 2024/2847: the cybersecurity of products with digital elements. See what the CRA is.
- Cybersecurity Act, Regulation (EU) 2019/881: ENISA and voluntary certification schemes. This page.
- NIS2 Directive, Directive (EU) 2022/2555: the cybersecurity risk management and incident reporting of essential and important entities. See CRA vs NIS2.
- DORA, Regulation (EU) 2022/2554: the ICT risk management of financial entities. See CRA vs DORA.
- AI Act, Regulation (EU) 2024/1689: rules for AI systems, including high-risk AI systems. See CRA vs AI Act.
- GDPR, Regulation (EU) 2016/679: the processing of personal data. See CRA vs GDPR.
- Radio Equipment Directive, Directive 2014/53/EU: radio equipment, including cybersecurity requirements for certain connected radio equipment until 11 December 2027. See CRA vs RED.
What this means in practice
- A product in CRA scope needs a CRA conformity assessment whether or not it holds a Cybersecurity Act certificate.
- A certificate helps only as far as it covers the Annex I requirements. Map what your certificate covers against Annex I before relying on it.
- For important products, the route that avoids a notified body under Article 27(9) depends on the Commission first specifying the scheme by delegated act. Check EUR-Lex for such an act before planning on it.
- For critical products in Annex IV, watch for delegated acts under Article 8(1). Until one exists, the Article 32(3) procedures apply.
- Cybiq checks the CRA only: it does not assess whether a product qualifies for, or holds, a certificate under a Cybersecurity Act scheme.
Cybiq checks the CRA only: it does not assess certification under the Cybersecurity Act or compliance with any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Statements about the Cybersecurity Act, the EUCC and the 2026 proposal were checked against their Official Journal and Commission texts and are not quoted. Verify before relying on any item; for a binding assessment consult a qualified lawyer.