Comparison

CRA vs NIS2: which one applies to your product?

Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.

Short answer: NIS2 regulates the cybersecurity risk management of certain organisations, not a product category, and the CRA’s own manufacturer reporting duty runs through the same national CSIRT network that NIS2 establishes. Both regimes can reach the same company for different reasons.

What each one regulates

The CRA applies to a product with digital elements made available on the market with a data connection to a device or network, and it points at NIS2 infrastructure for one specific thing: where a manufacturer must notify an actively exploited vulnerability, it goes simultaneously to the CSIRT designated as coordinator under NIS2, and to ENISA.

“a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555”

“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”

Directive (EU) 2022/2555 (the NIS2 Directive) requires designated “essential” and “important” entities across many sectors, energy, transport, banking, digital infrastructure, managed service providers and more, to run their own cybersecurity risk-management programme, report significant incidents to a national CSIRT, and in some sectors register with a national authority. It regulates organisations and how they run their own IT, not a category of product. Full text: Directive (EU) 2022/2555, OJ L 333, 27.12.2022 (NIS2).

Do they overlap, and which wins

NIS2 is not one of the CRA’s Article 2 exclusions, the closed list of medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval that displaces the CRA for certain product categories.

“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”

NIS2 and the CRA are not carve-outs of one another: they apply alongside each other. What genuinely links them is narrower than a scope exclusion: the CRA borrows NIS2’s CSIRT-designated-as-coordinator network as the recipient for its own Article 14 vulnerability and incident notifications, alongside ENISA, described above. That is a shared reporting channel between two different regimes, not one regime yielding to the other.

What this means in practice

“This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.”

Check your product. Run the free Cybiq check: six questions, a definitive verdict, and every claim anchored word-for-word in the Official Journal. For the terms used here, see the glossary; for more scope questions, see the FAQ; for the dates that matter, see the CRA timeline.

Cybiq checks the CRA only: it does not assess your organisation’s compliance with NIS2 or any other regime. Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.