Comparison

CRA vs DORA: which one applies to your product?

Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.

Short answer: DORA regulates the ICT risk management of EU financial entities and, by contract, their technology suppliers; the CRA regulates the cybersecurity of products with digital elements placed on the market. Neither excludes the other, and our verified CRA text does not mention DORA at all.

What each one regulates

The CRA applies to a product with digital elements: a software or hardware product and its remote data processing solutions, made available on the market with a data connection to a device or network. Its duties, vulnerability handling, an SBOM, secure defaults, a declared support period, attach to that product and to the economic operator who supplies it: the manufacturer, the authorised representative, the importer, the distributor, or another person subject to obligations under the Regulation.

“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”

“the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation”

Regulation (EU) 2022/2554 (DORA, the Digital Operational Resilience Act) requires banks, insurers, investment firms and other regulated financial entities to manage the ICT risk in their own operations, test their digital operational resilience, and extend oversight to their technology suppliers through contract, treating certain suppliers as their own critical ICT third-party providers. It is aimed at how the financial sector governs its use of technology, not directly at the products those suppliers build. Full text: Regulation (EU) 2022/2554, OJ L 333, 27.12.2022 (DORA).

Do they overlap, and which wins

The CRA names a short, closed list of other Union acts that take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.

“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”

DORA is not on that list, and no other quote in our verified corpus names DORA in either direction. The exclusion list above is a closed set of product-safety regimes; DORA regulates financial-sector operational resilience, a different subject matter entirely. Nothing in the CRA text we have verified suggests DORA displaces the CRA, or the reverse: a supplier can be pulled into DORA’s reach through a customer’s contract while independently owing CRA duties as a manufacturer, importer or distributor, described above.

What this means in practice

Check your product. Run the free Cybiq check: six questions, a definitive verdict, and every claim anchored word-for-word in the Official Journal. For the terms used here, see the glossary; for more scope questions, see the FAQ; for the dates that matter, see the CRA timeline.

Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.