
Regulation 2024/2847 · Directive 2022/2555 · comparison
Both are European cybersecurity law, both were written in the same period, and both have a 24-hour reporting duty. That is where the similarity ends. The Cyber Resilience Act is product legislation: it applies to what you place on the market, it ends in a CE mark, and its representative is optional. NIS2 is operator legislation: it applies to entities providing listed services, it ends in registration and supervision, and its representative is mandatory. A company that sells a device and runs the cloud behind it is caught by both, separately, for different things.
Product vs operatorCE markingRegistration24 hoursBoth

The last line on each side is the one that trips companies up. Under the CRA the representative is optional and useful; under NIS2 it is mandatory and it assigns jurisdiction. Assuming the CRA works like NIS2, or the reverse, produces either an unnecessary purchase or a missing obligation.

| Point | Cyber Resilience Act | NIS2 |
|---|---|---|
| Instrument | Regulation, directly applicable | Directive, transposed nationally |
| Subject | Products with digital elements | Entities providing listed services |
| Who is bound | Manufacturers, importers, distributors | Essential and important entities |
| Outcome | CE marking and a declaration of conformity | Registration and supervision |
| Representative | Optional, Article 18 | Mandatory, Article 26(3) |
| What the representative decides | The CSIRT that receives your report | The Member State with jurisdiction over you |
| Reporting trigger | Actively exploited vulnerability or severe incident affecting product security | Significant incident affecting the service |
| Registration | None | Article 27 entity registration with defined fields |
| Maximum penalties | Up to €15 million or 2.5% | At least €10 million or 2% for essential entities |
A vulnerability in your firmware is exploited against customers, and the same intrusion disrupts the cloud service you operate.
Early warning within 24 hours to the coordinating CSIRT through the ENISA platform, because an actively exploited vulnerability in your product is the trigger.
Early warning within 24 hours to your competent authority or CSIRT, because a significant incident affected the service you provide.
If personal data was breached, 72 hours to the supervisory authority, on a different clock and to a different body.
Three reports, three recipients, two clocks. Deciding who writes each one during the incident is how deadlines are missed.
The companies that handle this well have one page listing every reporting duty they are subject to, with the trigger, the deadline, the recipient and the named author. It takes an afternoon to write and it is the single most useful artefact in this whole area.
Secure defaults, no known exploitable vulnerabilities at release, an update mechanism, an SBOM, a disclosure policy and a support period of at least five years.
Technical documentation, the declaration of conformity, CE marking and the assessment route for your class.
Risk management, incident handling, business continuity, supply chain security, cryptography, access control and multi-factor authentication.
Entity registration with sector, Member States served and public IP ranges, plus management approval and training.
An incident procedure with named people and pre-drafted templates, because both clocks are 24 hours and neither pauses for a weekend.
Can be delegated to a representative. Both mandates cover correspondence and documentation, not the work.
| Ask | If yes |
|---|---|
| Do we place a product with digital elements on the Union market? | CRA applies; the Article 18 mandate is optional and fixes your reporting route |
| Do we provide cloud, DNS, CDN, data centre, managed services, a marketplace or a search engine in the Union? | NIS2 applies; the Article 26(3) mandate is mandatory |
| Both? | Two mandates, ideally one provider and one renewal date |
| Is the entity doing these things established in a Member State? | No representative needed for that entity under either regime |
| Do we also process personal data of people in the Union? | Add the Article 27 GDPR designation |
CRA is about the thing you sell and ends in a CE mark; NIS2 is about the service you run and ends in a registration. The CRA representative is optional and decides who receives your 24-hour report; the NIS2 representative is mandatory and decides which Member State supervises you. A company doing both needs both mandates, and the only sensible arrangement is one provider, one renewal date and one desk, so that when something happens nobody is arguing about which inbox it belongs to.
Abstract comparisons are hard to apply. These four cover most of what reaches us, and the reasoning transfers to yours.
| Company | CRA | NIS2 | Mandates needed |
|---|---|---|---|
| US maker of smart home devices, no EU entity | Yes, for device and firmware | Only if it offers a listed service in the Union | Article 18 optional, plus GPSR and Article 27 |
| Indian managed service provider, no products | No | Yes, Annex I | Article 26(3) mandatory, plus Article 27 |
| Chinese manufacturer with a cloud platform for its devices | Yes | Yes, if the platform is a cloud service offered in the Union | Both, plus GPSR and Article 27 |
| EU-established software company | Yes, as manufacturer | Depends on services | None: established in the Union |
Row four is worth noting, because it is where honest advice costs us a sale. A company genuinely established in a Member State carries the duties directly and needs no representative under either regime. What does not work is a letterbox subsidiary: both regimes borrow the idea of effective activity through stable arrangements, and an empty shell fails it.
CRA, NIS2, GDPR, GPSR, and any sector rules. One row each.
Written in your own words, so that nobody has to read a regulation at 2am.
24 or 72 hours, calendar not working days, and when it starts.
Named authority, named platform, and for the CRA the coordinating CSIRT your mandate fixes.
A person, not a team. Two names where the deadline is 24 hours.
If it is empty, that is the next thing to schedule.
Both start with a short early warning rather than a full analysis, and both expect it to be updated. Calendar hours in each case, weekends included.
The CRA through the SBOM and vulnerability handling, NIS2 through supplier assessment. Both were written after the same decade of supply chain incidents.
NIS2 states it expressly; the CRA achieves it through the declaration of conformity, which somebody signs in their own name.
Under both, the mandate covers correspondence and documentation. Neither regime allows a provider to take on the substantive duties, and Article 18(2) says so in terms.
The Cyber Resilience Act governs the product you place on the market and ends in a CE mark; NIS2 governs the service you operate and ends in a registration and supervision. The CRA representative is optional and fixes which CSIRT receives your 24-hour report; the NIS2 representative is mandatory and fixes which Member State supervises you. A company that sells a device and runs the platform behind it is caught by both, separately, and should hold both mandates with one provider on one renewal date so that when something happens the only question is technical rather than administrative.
Neither the CRA nor NIS2 replaces data protection law, and a single incident often engages all three. The clocks differ and so do the recipients, which is why the one-page table above matters more than any policy document.
| Regime | First deadline | Recipient | Representative |
|---|---|---|---|
| Cyber Resilience Act | 24 hours | Coordinating CSIRT via ENISA's platform | Optional, Article 18 |
| NIS2 | 24 hours | National CSIRT or competent authority | Mandatory, Article 26(3) |
| GDPR | 72 hours | Supervisory authority | Mandatory, Article 27 |
If yes, the Cyber Resilience Act applies to that product, and the Article 18 mandate is optional but decides your reporting route.
If yes, NIS2 applies to the entity, and the Article 26(3) mandate is mandatory and assigns jurisdiction.
If yes, no representative is needed under either regime, because the duties attach to that entity directly.


No. The CRA is product legislation applying to what you place on the market; NIS2 is operator legislation applying to entities providing listed services.
Yes, commonly. A device maker that also runs a cloud platform is caught by the CRA for the product and by NIS2 for the service.
The NIS2 one, under Article 26(3). The CRA one is optional under Article 18.
The CRA representative determines which CSIRT receives your reports; the NIS2 representative determines which Member State has jurisdiction over you.
Yes, with different triggers: actively exploited vulnerabilities and severe incidents affecting product security under the CRA, significant incidents affecting the service under NIS2.
No. NIS2 does, under its Article 27, with entity data including sector, Member States served and public IP ranges.
The CRA ceiling is up to €15 million or 2.5%; NIS2 sets at least €10 million or 2% for essential entities.
Yes, from 11 December 2027, based on the conformity assessment route for the product class.
No. It requires appropriate risk management measures, which certification may help evidence.
The CRA, where the software is placed on the market commercially. NIS2 applies only if you also provide one of its listed services.
NIS2, as an Annex I entity. The CRA may still reach remote data processing solutions integral to a product you sell.
Yes, with two separate written designations, two certificates and one renewal date.
Yes. The CRA uses the single reporting platform maintained by ENISA; NIS2 reporting goes through national channels.
NIS2 is already in force through national transpositions. CRA reporting starts on 11 September 2026 and full application follows on 11 December 2027.
With both, whenever personal data is involved, on its own 72-hour clock and to a different authority.
No. Both regimes accept a representative instead, which is what these mandates are.
€990 a year for CRA, NIS2 and the Article 27 GDPR designation, against €490, €490 and €290 taken separately.
Security engineering, conformity assessment, certification, incident reporting and legal advice on national measures.
Related: the CRA mandate · the NIS2 mandate
Europe Services, SE in Prague as your CRA authorised representative and your NIS2 representative, each with its own certificate and one desk that answers both.
Request this service