Comparison
CRA vs DORA: which one applies to your product?
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Short answer: DORA regulates the ICT risk management of EU financial entities and, by contract, their technology suppliers; the CRA regulates the cybersecurity of products with digital elements placed on the market. Neither excludes the other, and our verified CRA text does not mention DORA at all.
What each one regulates
The CRA applies to a product with digital elements: a software or hardware product and its remote data processing solutions, made available on the market with a data connection to a device or network. Its duties, vulnerability handling, an SBOM, secure defaults, a declared support period, attach to that product and to the economic operator who supplies it: the manufacturer, the authorised representative, the importer, the distributor, or another person subject to obligations under the Regulation.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
“the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation”
Regulation (EU) 2022/2554 (DORA, the Digital Operational Resilience Act) requires banks, insurers, investment firms and other regulated financial entities to manage the ICT risk in their own operations, test their digital operational resilience, and extend oversight to their technology suppliers through contract, treating certain suppliers as their own critical ICT third-party providers. It is aimed at how the financial sector governs its use of technology, not directly at the products those suppliers build. Full text: Regulation (EU) 2022/2554, OJ L 333, 27.12.2022 (DORA).
Do they overlap, and which wins
The CRA names a short, closed list of other Union acts that take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
DORA is not on that list, and no other quote in our verified corpus names DORA in either direction. The exclusion list above is a closed set of product-safety regimes; DORA regulates financial-sector operational resilience, a different subject matter entirely. Nothing in the CRA text we have verified suggests DORA displaces the CRA, or the reverse: a supplier can be pulled into DORA’s reach through a customer’s contract while independently owing CRA duties as a manufacturer, importer or distributor, described above.
What this means in practice
- If your customer is an EU-regulated financial entity, DORA’s own rules can require them to push security and incident-reporting terms into your contract as their ICT third-party provider; that duty runs from their side of DORA, not from anything the CRA asks of you.
- Meeting your CRA obligations (vulnerability handling, an SBOM, secure defaults, a declared support period) can help satisfy a financial-sector customer’s DORA-driven due diligence, but the CRA itself makes no reference to DORA and imposes no DORA-specific duty.
- If your own product is a product with digital elements, you owe CRA manufacturer duties to your market surveillance authority regardless of whether any customer is a financial entity.
- Treat DORA compliance and CRA compliance as two separate work-streams with two separate advisers.
- Cybiq checks the CRA only: it does not assess whether you are a DORA financial entity or a critical ICT third-party provider, that determination sits entirely outside what we check.
Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.