NIS2 vs Cyber Resilience Act: Which One Applies to You, and What Each Demands
NIS2 regulates operators of essential services; the CRA regulates products with digital elements. Who falls under which, duties, deadlines and penalties side by side.
Updated This page as Markdown
In short
NIS2 (Directive (EU) 2022/2555) is about operators: medium and large entities in sectors such as energy, health, transport, manufacturing and digital services must manage cyber risk, report incidents and make management accountable. The Cyber Resilience Act (Regulation (EU) 2024/2847) is about products: whoever places connected hardware or software on the EU market must build it securely, handle vulnerabilities for years and report exploited ones. A machine builder is both: a NIS2 entity for its operations and a CRA manufacturer for the machines it sells. Zyberum does gap analyses and testing for both and does not certify.
What is the difference?
NIS2 regulates organisations, the CRA regulates products. NIS2, Directive (EU) 2022/2555, tells essential and important entities in eighteen sectors how to run their own security: risk management, incident reporting, management accountability, supply chain. The Cyber Resilience Act, Regulation (EU) 2024/2847, tells manufacturers, importers and distributors what a product with digital elements has to look like before it carries a CE mark and how it has to be maintained afterwards: secure by default, no known exploitable vulnerabilities at release, security updates for the support period, a process to receive and handle vulnerability reports.
The legal form differs too. NIS2 is a directive: each member state transposes it into national law, in Germany through an amended BSI Act, and the details, the authority and the registration process are national. The CRA is a regulation: it applies directly and identically in every member state, with market surveillance authorities checking products the way they check machinery or radio equipment today.
Side by side
| NIS2 | Cyber Resilience Act | |
|---|---|---|
| What it covers | The organisation: governance, risk management, incident handling, business continuity, supply chain, access control, cryptography, training (Art. 21(2) lists ten minimum measures) | The product and its lifecycle: secure design and defaults, vulnerability handling, updates, SBOM, documentation, conformity assessment, CE marking (Art. 13, Annex I) |
| What it does not cover | The security of products the entity sells; small and micro enterprises outside the exceptions of Art. 2 | The operator’s IT and processes; pure services without a product, pure SaaS unless part of a product’s remote data processing; products already under sector rules such as medical devices or vehicles under UN R155 |
| Who is addressed | Essential and important entities: medium and large enterprises in Annex I and II sectors (energy, transport, health, water, digital infrastructure, manufacturing of machinery, vehicles, electronics and more), plus some regardless of size | Manufacturers above all, then importers and distributors, of any hardware or software with a network connection placed on the EU market, including open source in commercial activity |
| Timeline | Transposition deadline 17 October 2024; national law and registration follow per member state | In force since 10 December 2024; reporting duties apply from 11 September 2026; all obligations from 11 December 2027 (Art. 71) |
| Typical cost | Gap analysis for a mid-sized entity 8,000 to 25,000 euros; implementation depends on the gaps, often an ISMS project over a year; typical ranges for Germany and the EU, not an offer | Gap analysis per product family 8,000 to 20,000 euros; penetration test of an IoT product 15,000 to 30,000; ongoing vulnerability handling as a permanent team task; third-party assessment for important products Class II and critical products |
| Recurring duties | Continuous risk management, management training, incident reports as they happen, audits by the authority | Vulnerability handling and updates for the support period (at least five years unless the product’s lifetime is shorter, Art. 13(8)), reports of exploited vulnerabilities, re-assessment after substantial modification |
| Required by | Directive (EU) 2022/2555 and national transposition law | Regulation (EU) 2024/2847, directly applicable |
| Output and evidence | Documented ISMS, risk analysis, measures, registration with the authority, incident reports, management sign-off | Technical documentation (Annex VII), EU declaration of conformity, CE marking, SBOM, user information, coordinated disclosure policy, security.txt style contact |
| Penalties | Essential entities up to 10 million euros or 2 % of worldwide turnover, important entities up to 7 million or 1.4 % (Art. 34), plus personal liability of management (Art. 20) | Up to 15 million euros or 2.5 % of worldwide turnover for breaches of the essential requirements (Art. 64), product withdrawal by market surveillance |
Focus on NIS2 when
- You operate rather than build: a utility, a hospital, a logistics company, a food producer, a data centre, a managed service provider. The products you use are someone else’s CRA problem; your processes are yours.
- Your management needs to understand that NIS2 is a governance law. Art. 20 requires the management body to approve the measures, oversee them and be trained; the fines are the company’s, the liability is theirs.
- You have an incident-reporting gap. The 24 hour early warning only works with detection, an on-call rota and a prepared report template.
Focus on the CRA when
- You sell hardware or software with a network interface into the EU: devices, machines with connectivity, apps, firmware, embedded Linux boards, industrial controllers.
- You are small. NIS2 mostly exempts small and micro enterprises; the CRA does not, so a ten-person IoT start-up is a CRA manufacturer with full obligations.
- Your product has a long field life. The support period and the vulnerability-handling duties bind you for years after the sale, which affects architecture decisions now, from update mechanisms to SBOM tooling.
- You face the 11 September 2026 reporting date. Whoever sells today needs a process to detect, assess and report actively exploited vulnerabilities before the product requirements even apply.
For a product company, the CRA is the law with the harder technical requirements; for an operator, NIS2 is the one with teeth for management.
Both together
Many Zyberum customers are both: a machine builder, an appliance manufacturer, an automotive supplier with a connected product and a factory. The efficient approach treats the overlap once. One risk-management framework covers the NIS2 measures and the CRA’s risk assessment of the product. One vulnerability-handling process serves the CRA’s reporting and the NIS2 incident procedure. One supplier policy handles NIS2 supply chain and CRA due diligence on components, and penetration tests serve as evidence under both.
Zyberum does NIS2 and CRA gap analyses, builds the vulnerability-handling and reporting processes, and tests the products and the networks. We do not certify: the CRA conformity assessment is your self-assessment or a notified body’s, and the NIS2 audit is the authority’s or an auditor’s. Our role is to find the gaps before they do and to produce the evidence they will ask for.
FAQ
Frequently asked questions
My company builds connected machines. NIS2, CRA or both?
Probably both. The machines you sell are products with digital elements, so the CRA applies to them from 11 December 2027, with vulnerability reporting duties from 11 September 2026. If your company is a medium or large enterprise in the manufacturing sectors of Annex I or II of NIS2, your own operations fall under NIS2 as well. The two regimes look at different things: the CRA at the product, NIS2 at the company running its IT and plant.
Which one has the shorter reporting deadline?
Both start with 24 hours. Under NIS2 Art. 23 an essential or important entity sends an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours and a final report within one month. Under CRA Art. 14 a manufacturer sends an early warning about an actively exploited vulnerability within 24 hours, a notification within 72 hours and a final report within 14 days of a fix being available.
Does a CRA-compliant product make its buyer NIS2-compliant?
No. NIS2 Art. 21 requires the operator to manage its own risks, including supply chain security, access control, backups, incident handling and training. Buying products with CE marking under the CRA helps with the supply-chain measure and nothing else. Conversely, a NIS2-compliant operator can still sell an insecure product.
Sources
- Directive (EU) 2022/2555 (NIS2), Art. 2 and 3 scope, Art. 20 governance, Art. 21 measures, Art. 23 reporting, Art. 34 fines
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Art. 13 and 14 manufacturer obligations, Art. 32 conformity assessment, Art. 64 penalties, Art. 71 application, Annex I essential requirements
- BSI: NIS-2 information for affected entities (German)
Related pages
- GlossaryNIS2NIS2 (Directive (EU) 2022/2555) sets cybersecurity duties for essential and important entities in 18 sectors. Scope, ten measures, reporting deadlines, German law.
- GlossaryCyber Resilience Act (CRA)The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.
- InsightsNIS2 in Germany: Who Is Affected and What to Do NowThe German NIS2 law has applied since 6 December 2025. A practical checklist: scope, registration, the ten risk measures, reporting deadlines and first steps.
- InsightsCyber Resilience Act: What Manufacturers Must Do by 2027A practical guide to the EU Cyber Resilience Act: scope, product classes, deadlines, reporting duties and the concrete steps manufacturers should take now.
- InsightsThe CRA 24-Hour Reporting Duty: What Manufacturers Must DoThe Cyber Resilience Act reporting duty applies since 11 September 2026. The deadlines (24 hours, 72 hours, 14 days, one month), what triggers them, and how to be ready.
- ServicesDoes NIS2 apply to your company?Free NIS2 self-check: three questions on sector and size tell you whether your company is an important or especially important entity under NIS2.
- ServicesIs your product affected by the Cyber Resilience Act?Free Cyber Resilience Act self-check: four questions tell you whether your product is in scope, which class it falls into and which deadlines apply.
