CRA guidance · Published 2026-06-23
CRA vs NIS2: two cybersecurity regimes, two different questions
The CRA follows products; NIS2 primarily follows covered entities and services.
What this guide covers
- Assess CRA scope around the product and economic operator
- Assess NIS2 under the relevant Member State's implementing law
- Reuse factual evidence while preserving separate legal triggers and approvals
This article provides general information about the EU Cyber Resilience Act. It is not legal advice.