Comparison

CRA vs Cybersecurity Act: the EU Cybersecurity Act (Regulation 2019/881) and the CRA

Reviewed September 2026 against Regulation (EU) 2024/2847, OJ L, 20.11.2024, and Regulation (EU) 2019/881, OJ L 151, 7.6.2019.

Short answer: the EU Cybersecurity Act, Regulation (EU) 2019/881, gives ENISA its mandate and sets up a framework for European cybersecurity certification of ICT products, ICT services, ICT processes and managed security services, and that certification is voluntary unless another law makes it mandatory. The Cyber Resilience Act sets mandatory essential cybersecurity requirements for every product with digital elements placed on the EU market. The two connect at one point: a certificate issued under a Cybersecurity Act scheme can count as evidence of CRA conformity, and for critical products the CRA can make such a certificate compulsory.

What the Cybersecurity Act is

Regulation (EU) 2019/881 of 17 April 2019 carries the official short title “Cybersecurity Act”. It does two things. First, it lays down the objectives, tasks and organisation of ENISA, the European Union Agency for Cybersecurity, and establishes ENISA for an indefinite period as of 27 June 2019, replacing a mandate that Regulation (EU) No 526/2013 had extended only until 19 June 2020. Second, it creates the European cybersecurity certification framework: a mechanism to adopt European cybersecurity certification schemes and to attest that ICT products, ICT services, ICT processes and managed security services evaluated under such a scheme meet specified security requirements.

Full texts: Regulation (EU) 2019/881, OJ L 151, 7.6.2019 (Cybersecurity Act), Implementing Regulation (EU) 2024/482 (EUCC) and Regulation (EU) 2025/37.

What the CRA is

The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to a product with digital elements made available on the market where its intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It does not ask whether a product is certified. It asks whether the product meets the essential cybersecurity requirements in Annex I, and it makes the manufacturer demonstrate that through a conformity assessment before the CE marking goes on. The full picture is on the page what the CRA is.

“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”

How the two connect

The CRA refers to the Cybersecurity Act in three places that matter for a manufacturer. The first is a presumption of conformity: a product for which a certificate or an EU statement of conformity has been issued under a Cybersecurity Act scheme is presumed to meet the CRA requirements that the certificate covers, and only those.

“Products with digital elements and processes put in place by the manufacturer for which an EU statement of conformity or certificate has been issued under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881 shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I in so far as the EU statement of conformity or European cybersecurity certificate, or parts thereof, cover those requirements.”

The second is Article 27(9). The Commission may specify, by delegated act, which Cybersecurity Act schemes can be used to demonstrate CRA conformity. A certificate under such a scheme at assurance level ‘substantial’ or higher then removes the need for a third-party conformity assessment for the requirements it covers, which matters for important products in Annex III.

“the issuance of a European cybersecurity certificate issued under such schemes, at least at assurance level ‘substantial’, eliminates the obligation of a manufacturer to carry out a third-party conformity assessment for the corresponding requirements”

The third is the one place where certification stops being voluntary. For critical products listed in Annex IV, the Commission may adopt delegated acts requiring a European cybersecurity certificate, provided a scheme covering those products has been adopted under the Cybersecurity Act and is available to manufacturers.

“to determine which products with digital elements that have the core functionality of a product category that is set out in Annex IV to this Regulation are to be required to obtain a European cybersecurity certificate at assurance level at least ‘substantial’ under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881”

Where no such delegated act exists, a critical product falls back to the procedures open to Class II important products.

“Critical products with digital elements listed in Annex IV shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the following procedures: (a) a European cybersecurity certification scheme in accordance with Article 8(1); or (b) where the conditions in Article 8(1) are not met, any of the procedures referred to in paragraph 3 of this Article.”

Voluntary certification against mandatory requirements

Cybersecurity ActCyber Resilience Act
InstrumentRegulation (EU) 2019/881Regulation (EU) 2024/2847
What it coversICT products, ICT services, ICT processes and managed security services submitted for certificationEvery product with digital elements placed on the EU market, unless excluded
Binding forceCertification is voluntary unless other Union or national law requires itThe essential requirements are mandatory for products in scope
Who actsWhoever applies for a certificateManufacturers, importers and distributors
ProofA European cybersecurity certificate or an EU statement of conformity under a schemeA conformity assessment, the EU declaration of conformity and the CE marking

The proposed Cybersecurity Act 2

On 20 January 2026 the Commission presented a cybersecurity package. It includes a proposal for a new regulation, COM(2026) 11, which would repeal Regulation (EU) 2019/881 and replace it with what the proposal calls “The Cybersecurity Act 2”, and a proposal for a directive amending NIS2 for alignment with it. A proposal is not law: until the European Parliament and the Council adopt a text, Regulation (EU) 2019/881 is the Cybersecurity Act in force. Text of the proposal: COM(2026) 11 on EUR-Lex.

The EU cybersecurity regulation map

“EU cybersecurity regulation” is not one law. Each act below regulates a different thing, and each comparison page sets out how it relates to the CRA.

What this means in practice

Check your product. Run the free Cybiq check: five or six questions, a definitive verdict, and every claim anchored word-for-word in the Official Journal. For the terms used here, see the glossary; for more scope questions, see the FAQ; for the dates that matter, see the CRA timeline.

Cybiq checks the CRA only: it does not assess certification under the Cybersecurity Act or compliance with any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Statements about the Cybersecurity Act, the EUCC and the 2026 proposal were checked against their Official Journal and Commission texts and are not quoted. Verify before relying on any item; for a binding assessment consult a qualified lawyer.