Appoint us
Authorities enforcing the Cyber Resilience Act and NIS2

REP27 · CRA · Compared

Regulation 2024/2847 · Directive 2022/2555 · comparison

CRA and NIS2: one regulates the product, the other the operator.

Both are European cybersecurity law, both were written in the same period, and both have a 24-hour reporting duty. That is where the similarity ends. The Cyber Resilience Act is product legislation: it applies to what you place on the market, it ends in a CE mark, and its representative is optional. NIS2 is operator legislation: it applies to entities providing listed services, it ends in registration and supervision, and its representative is mandatory. A company that sells a device and runs the cloud behind it is caught by both, separately, for different things.

Product vs operatorCE markingRegistration24 hoursBoth

Request this service   Ask a question

The difference in one screen

The Cyber Resilience Act and NIS2 compared by subject, duties and representation
The Cyber Resilience Act and NIS2 compared by subject, duties and representation

The last line on each side is the one that trips companies up. Under the CRA the representative is optional and useful; under NIS2 it is mandatory and it assigns jurisdiction. Assuming the CRA works like NIS2, or the reverse, produces either an unnecessary purchase or a missing obligation.

The same company under both

How different company types fall under the CRA, NIS2, or both
How different company types fall under the CRA, NIS2, or both
Row three is the modern product company: a device, an app and a cloud backend. The device and its software are assessed under the CRA; the cloud service, if offered in the Union, makes you an Annex I entity under NIS2. Two regimes, two mandates, one company.

Nine differences worth knowing

PointCyber Resilience ActNIS2
InstrumentRegulation, directly applicableDirective, transposed nationally
SubjectProducts with digital elementsEntities providing listed services
Who is boundManufacturers, importers, distributorsEssential and important entities
OutcomeCE marking and a declaration of conformityRegistration and supervision
RepresentativeOptional, Article 18Mandatory, Article 26(3)
What the representative decidesThe CSIRT that receives your reportThe Member State with jurisdiction over you
Reporting triggerActively exploited vulnerability or severe incident affecting product securitySignificant incident affecting the service
RegistrationNoneArticle 27 entity registration with defined fields
Maximum penaltiesUp to €15 million or 2.5%At least €10 million or 2% for essential entities

Two reporting duties, one incident

  1. The event

    A vulnerability in your firmware is exploited against customers, and the same intrusion disrupts the cloud service you operate.

  2. The CRA report

    Early warning within 24 hours to the coordinating CSIRT through the ENISA platform, because an actively exploited vulnerability in your product is the trigger.

  3. The NIS2 report

    Early warning within 24 hours to your competent authority or CSIRT, because a significant incident affected the service you provide.

  4. The GDPR report

    If personal data was breached, 72 hours to the supervisory authority, on a different clock and to a different body.

  5. The lesson

    Three reports, three recipients, two clocks. Deciding who writes each one during the incident is how deadlines are missed.

The companies that handle this well have one page listing every reporting duty they are subject to, with the trigger, the deadline, the recipient and the named author. It takes an afternoon to write and it is the single most useful artefact in this whole area.

What each regime asks you to build

CRA, in engineering

Secure defaults, no known exploitable vulnerabilities at release, an update mechanism, an SBOM, a disclosure policy and a support period of at least five years.

CRA, in paperwork

Technical documentation, the declaration of conformity, CE marking and the assessment route for your class.

NIS2, in engineering

Risk management, incident handling, business continuity, supply chain security, cryptography, access control and multi-factor authentication.

NIS2, in paperwork

Entity registration with sector, Member States served and public IP ranges, plus management approval and training.

Both

An incident procedure with named people and pre-drafted templates, because both clocks are 24 hours and neither pauses for a weekend.

Neither

Can be delegated to a representative. Both mandates cover correspondence and documentation, not the work.

Deciding what you need, in five lines

AskIf yes
Do we place a product with digital elements on the Union market?CRA applies; the Article 18 mandate is optional and fixes your reporting route
Do we provide cloud, DNS, CDN, data centre, managed services, a marketplace or a search engine in the Union?NIS2 applies; the Article 26(3) mandate is mandatory
Both?Two mandates, ideally one provider and one renewal date
Is the entity doing these things established in a Member State?No representative needed for that entity under either regime
Do we also process personal data of people in the Union?Add the Article 27 GDPR designation

The short version

CRA is about the thing you sell and ends in a CE mark; NIS2 is about the service you run and ends in a registration. The CRA representative is optional and decides who receives your 24-hour report; the NIS2 representative is mandatory and decides which Member State supervises you. A company doing both needs both mandates, and the only sensible arrangement is one provider, one renewal date and one desk, so that when something happens nobody is arguing about which inbox it belongs to.

Four company shapes, four answers

Abstract comparisons are hard to apply. These four cover most of what reaches us, and the reasoning transfers to yours.

CompanyCRANIS2Mandates needed
US maker of smart home devices, no EU entityYes, for device and firmwareOnly if it offers a listed service in the UnionArticle 18 optional, plus GPSR and Article 27
Indian managed service provider, no productsNoYes, Annex IArticle 26(3) mandatory, plus Article 27
Chinese manufacturer with a cloud platform for its devicesYesYes, if the platform is a cloud service offered in the UnionBoth, plus GPSR and Article 27
EU-established software companyYes, as manufacturerDepends on servicesNone: established in the Union

Row four is worth noting, because it is where honest advice costs us a sale. A company genuinely established in a Member State carries the duties directly and needs no representative under either regime. What does not work is a letterbox subsidiary: both regimes borrow the idea of effective activity through stable arrangements, and an empty shell fails it.

One page every affected company should have

  1. Every reporting duty you are subject to

    CRA, NIS2, GDPR, GPSR, and any sector rules. One row each.

  2. The trigger for each

    Written in your own words, so that nobody has to read a regulation at 2am.

  3. The deadline and the clock type

    24 or 72 hours, calendar not working days, and when it starts.

  4. The recipient

    Named authority, named platform, and for the CRA the coordinating CSIRT your mandate fixes.

  5. The author

    A person, not a team. Two names where the deadline is 24 hours.

  6. The last rehearsal date

    If it is empty, that is the next thing to schedule.

What the two regimes have in common

A 24-hour first deadline

Both start with a short early warning rather than a full analysis, and both expect it to be updated. Calendar hours in each case, weekends included.

Supply chain focus

The CRA through the SBOM and vulnerability handling, NIS2 through supplier assessment. Both were written after the same decade of supply chain incidents.

Management accountability

NIS2 states it expressly; the CRA achieves it through the declaration of conformity, which somebody signs in their own name.

Representatives that do not do the work

Under both, the mandate covers correspondence and documentation. Neither regime allows a provider to take on the substantive duties, and Article 18(2) says so in terms.

The short version

The Cyber Resilience Act governs the product you place on the market and ends in a CE mark; NIS2 governs the service you operate and ends in a registration and supervision. The CRA representative is optional and fixes which CSIRT receives your 24-hour report; the NIS2 representative is mandatory and fixes which Member State supervises you. A company that sells a device and runs the platform behind it is caught by both, separately, and should hold both mandates with one provider on one renewal date so that when something happens the only question is technical rather than administrative.

Where the GDPR fits between them

Neither the CRA nor NIS2 replaces data protection law, and a single incident often engages all three. The clocks differ and so do the recipients, which is why the one-page table above matters more than any policy document.

RegimeFirst deadlineRecipientRepresentative
Cyber Resilience Act24 hoursCoordinating CSIRT via ENISA's platformOptional, Article 18
NIS224 hoursNational CSIRT or competent authorityMandatory, Article 26(3)
GDPR72 hoursSupervisory authorityMandatory, Article 27

The three questions that settle it

  1. Do we place a product on the Union market?

    If yes, the Cyber Resilience Act applies to that product, and the Article 18 mandate is optional but decides your reporting route.

  2. Do we operate one of the listed services in the Union?

    If yes, NIS2 applies to the entity, and the Article 26(3) mandate is mandatory and assigns jurisdiction.

  3. Is the entity doing either established in a Member State?

    If yes, no representative is needed under either regime, because the duties attach to that entity directly.

Infrastructure governed by NIS2 alongside products governed by the CRA
Infrastructure governed by NIS2 alongside products governed by the CRA
Product with digital elements assessed under the Cyber Resilience Act

Questions we are actually asked

Is the CRA the same as NIS2?

No. The CRA is product legislation applying to what you place on the market; NIS2 is operator legislation applying to entities providing listed services.

Can a company be caught by both?

Yes, commonly. A device maker that also runs a cloud platform is caught by the CRA for the product and by NIS2 for the service.

Which representative is mandatory?

The NIS2 one, under Article 26(3). The CRA one is optional under Article 18.

What does each representative decide?

The CRA representative determines which CSIRT receives your reports; the NIS2 representative determines which Member State has jurisdiction over you.

Do both have 24-hour reporting?

Yes, with different triggers: actively exploited vulnerabilities and severe incidents affecting product security under the CRA, significant incidents affecting the service under NIS2.

Does the CRA require registration?

No. NIS2 does, under its Article 27, with entity data including sector, Member States served and public IP ranges.

Which has higher penalties?

The CRA ceiling is up to €15 million or 2.5%; NIS2 sets at least €10 million or 2% for essential entities.

Does the CRA require CE marking?

Yes, from 11 December 2027, based on the conformity assessment route for the product class.

Does NIS2 require certification?

No. It requires appropriate risk management measures, which certification may help evidence.

If we only sell software, which applies?

The CRA, where the software is placed on the market commercially. NIS2 applies only if you also provide one of its listed services.

If we only run a cloud service, which applies?

NIS2, as an Annex I entity. The CRA may still reach remote data processing solutions integral to a product you sell.

Can one provider hold both mandates?

Yes, with two separate written designations, two certificates and one renewal date.

Do the reporting platforms differ?

Yes. The CRA uses the single reporting platform maintained by ENISA; NIS2 reporting goes through national channels.

Which starts first?

NIS2 is already in force through national transpositions. CRA reporting starts on 11 September 2026 and full application follows on 11 December 2027.

Does the GDPR overlap with either?

With both, whenever personal data is involved, on its own 72-hour clock and to a different authority.

Do we need an EU establishment?

No. Both regimes accept a representative instead, which is what these mandates are.

How much do both cost together?

€990 a year for CRA, NIS2 and the Article 27 GDPR designation, against €490, €490 and €290 taken separately.

What is excluded from both mandates?

Security engineering, conformity assessment, certification, incident reporting and legal advice on national measures.

Related: the CRA mandate · the NIS2 mandate

Two regimes, two mandates, one renewal

Europe Services, SE in Prague as your CRA authorised representative and your NIS2 representative, each with its own certificate and one desk that answers both.

Request this service