Comparison
CRA vs NIS2: which one applies to your product?
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Short answer: NIS2 regulates the cybersecurity risk management of certain organisations, not a product category, and the CRA’s own manufacturer reporting duty runs through the same national CSIRT network that NIS2 establishes. Both regimes can reach the same company for different reasons.
What each one regulates
The CRA applies to a product with digital elements made available on the market with a data connection to a device or network, and it points at NIS2 infrastructure for one specific thing: where a manufacturer must notify an actively exploited vulnerability, it goes simultaneously to the CSIRT designated as coordinator under NIS2, and to ENISA.
“a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555”
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”
Directive (EU) 2022/2555 (the NIS2 Directive) requires designated “essential” and “important” entities across many sectors, energy, transport, banking, digital infrastructure, managed service providers and more, to run their own cybersecurity risk-management programme, report significant incidents to a national CSIRT, and in some sectors register with a national authority. It regulates organisations and how they run their own IT, not a category of product. Full text: Directive (EU) 2022/2555, OJ L 333, 27.12.2022 (NIS2).
Do they overlap, and which wins
NIS2 is not one of the CRA’s Article 2 exclusions, the closed list of medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval that displaces the CRA for certain product categories.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
NIS2 and the CRA are not carve-outs of one another: they apply alongside each other. What genuinely links them is narrower than a scope exclusion: the CRA borrows NIS2’s CSIRT-designated-as-coordinator network as the recipient for its own Article 14 vulnerability and incident notifications, alongside ENISA, described above. That is a shared reporting channel between two different regimes, not one regime yielding to the other.
What this means in practice
- If your company also qualifies as an NIS2 “essential” or “important” entity, you carry NIS2’s own risk-management and incident-reporting duties for your organisation, in addition to, not instead of, any CRA duties for products you place on the market.
- The CRA’s Article 14 vulnerability and incident reporting (early warning, then notification, then a final report) reaches the same national CSIRT-designated-as-coordinator network NIS2 sets up, plus ENISA, even though the two regimes regulate different things.
- NIS2’s Member State transposition deadline was 17 October 2024, a widely reported NIS2 date, well before any CRA date; the CRA’s Article 14 reporting starts from 11 September 2026 and the rest applies from 11 December 2027. Nothing links the two calendars.
- Being covered by NIS2 does not create or remove CRA scope, and the reverse holds too; check each independently.
- Cybiq checks the CRA only: it does not assess whether your organisation is an NIS2 essential or important entity.
“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”
Cybiq checks the CRA only: it does not assess your organisation’s compliance with NIS2 or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.