Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsCompliance

NIS2 vs Cyber Resilience Act: Which One Applies to You, and What Each Demands

NIS2 regulates operators of essential services; the CRA regulates products with digital elements. Who falls under which, duties, deadlines and penalties side by side.

Updated This page as Markdown

In short

NIS2 (Directive (EU) 2022/2555) is about operators: medium and large entities in sectors such as energy, health, transport, manufacturing and digital services must manage cyber risk, report incidents and make management accountable. The Cyber Resilience Act (Regulation (EU) 2024/2847) is about products: whoever places connected hardware or software on the EU market must build it securely, handle vulnerabilities for years and report exploited ones. A machine builder is both: a NIS2 entity for its operations and a CRA manufacturer for the machines it sells. Zyberum does gap analyses and testing for both and does not certify.

What is the difference?

NIS2 regulates organisations, the CRA regulates products. NIS2, Directive (EU) 2022/2555, tells essential and important entities in eighteen sectors how to run their own security: risk management, incident reporting, management accountability, supply chain. The Cyber Resilience Act, Regulation (EU) 2024/2847, tells manufacturers, importers and distributors what a product with digital elements has to look like before it carries a CE mark and how it has to be maintained afterwards: secure by default, no known exploitable vulnerabilities at release, security updates for the support period, a process to receive and handle vulnerability reports.

The legal form differs too. NIS2 is a directive: each member state transposes it into national law, in Germany through an amended BSI Act, and the details, the authority and the registration process are national. The CRA is a regulation: it applies directly and identically in every member state, with market surveillance authorities checking products the way they check machinery or radio equipment today.

Side by side

NIS2Cyber Resilience Act
What it coversThe organisation: governance, risk management, incident handling, business continuity, supply chain, access control, cryptography, training (Art. 21(2) lists ten minimum measures)The product and its lifecycle: secure design and defaults, vulnerability handling, updates, SBOM, documentation, conformity assessment, CE marking (Art. 13, Annex I)
What it does not coverThe security of products the entity sells; small and micro enterprises outside the exceptions of Art. 2The operator’s IT and processes; pure services without a product, pure SaaS unless part of a product’s remote data processing; products already under sector rules such as medical devices or vehicles under UN R155
Who is addressedEssential and important entities: medium and large enterprises in Annex I and II sectors (energy, transport, health, water, digital infrastructure, manufacturing of machinery, vehicles, electronics and more), plus some regardless of sizeManufacturers above all, then importers and distributors, of any hardware or software with a network connection placed on the EU market, including open source in commercial activity
TimelineTransposition deadline 17 October 2024; national law and registration follow per member stateIn force since 10 December 2024; reporting duties apply from 11 September 2026; all obligations from 11 December 2027 (Art. 71)
Typical costGap analysis for a mid-sized entity 8,000 to 25,000 euros; implementation depends on the gaps, often an ISMS project over a year; typical ranges for Germany and the EU, not an offerGap analysis per product family 8,000 to 20,000 euros; penetration test of an IoT product 15,000 to 30,000; ongoing vulnerability handling as a permanent team task; third-party assessment for important products Class II and critical products
Recurring dutiesContinuous risk management, management training, incident reports as they happen, audits by the authorityVulnerability handling and updates for the support period (at least five years unless the product’s lifetime is shorter, Art. 13(8)), reports of exploited vulnerabilities, re-assessment after substantial modification
Required byDirective (EU) 2022/2555 and national transposition lawRegulation (EU) 2024/2847, directly applicable
Output and evidenceDocumented ISMS, risk analysis, measures, registration with the authority, incident reports, management sign-offTechnical documentation (Annex VII), EU declaration of conformity, CE marking, SBOM, user information, coordinated disclosure policy, security.txt style contact
PenaltiesEssential entities up to 10 million euros or 2 % of worldwide turnover, important entities up to 7 million or 1.4 % (Art. 34), plus personal liability of management (Art. 20)Up to 15 million euros or 2.5 % of worldwide turnover for breaches of the essential requirements (Art. 64), product withdrawal by market surveillance

Focus on NIS2 when

  • You operate rather than build: a utility, a hospital, a logistics company, a food producer, a data centre, a managed service provider. The products you use are someone else’s CRA problem; your processes are yours.
  • Your management needs to understand that NIS2 is a governance law. Art. 20 requires the management body to approve the measures, oversee them and be trained; the fines are the company’s, the liability is theirs.
  • You have an incident-reporting gap. The 24 hour early warning only works with detection, an on-call rota and a prepared report template.

Focus on the CRA when

  • You sell hardware or software with a network interface into the EU: devices, machines with connectivity, apps, firmware, embedded Linux boards, industrial controllers.
  • You are small. NIS2 mostly exempts small and micro enterprises; the CRA does not, so a ten-person IoT start-up is a CRA manufacturer with full obligations.
  • Your product has a long field life. The support period and the vulnerability-handling duties bind you for years after the sale, which affects architecture decisions now, from update mechanisms to SBOM tooling.
  • You face the 11 September 2026 reporting date. Whoever sells today needs a process to detect, assess and report actively exploited vulnerabilities before the product requirements even apply.

For a product company, the CRA is the law with the harder technical requirements; for an operator, NIS2 is the one with teeth for management.

Both together

Many Zyberum customers are both: a machine builder, an appliance manufacturer, an automotive supplier with a connected product and a factory. The efficient approach treats the overlap once. One risk-management framework covers the NIS2 measures and the CRA’s risk assessment of the product. One vulnerability-handling process serves the CRA’s reporting and the NIS2 incident procedure. One supplier policy handles NIS2 supply chain and CRA due diligence on components, and penetration tests serve as evidence under both.

Zyberum does NIS2 and CRA gap analyses, builds the vulnerability-handling and reporting processes, and tests the products and the networks. We do not certify: the CRA conformity assessment is your self-assessment or a notified body’s, and the NIS2 audit is the authority’s or an auditor’s. Our role is to find the gaps before they do and to produce the evidence they will ask for.

FAQ

Frequently asked questions

My company builds connected machines. NIS2, CRA or both?

Probably both. The machines you sell are products with digital elements, so the CRA applies to them from 11 December 2027, with vulnerability reporting duties from 11 September 2026. If your company is a medium or large enterprise in the manufacturing sectors of Annex I or II of NIS2, your own operations fall under NIS2 as well. The two regimes look at different things: the CRA at the product, NIS2 at the company running its IT and plant.

Which one has the shorter reporting deadline?

Both start with 24 hours. Under NIS2 Art. 23 an essential or important entity sends an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours and a final report within one month. Under CRA Art. 14 a manufacturer sends an early warning about an actively exploited vulnerability within 24 hours, a notification within 72 hours and a final report within 14 days of a fix being available.

Does a CRA-compliant product make its buyer NIS2-compliant?

No. NIS2 Art. 21 requires the operator to manage its own risks, including supply chain security, access control, backups, incident handling and training. Buying products with CE marking under the CRA helps with the supply-chain measure and nothing else. Conversely, a NIS2-compliant operator can still sell an insecure product.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab