CRA guidance · Published 2026-06-23

CRA vs NIS2: two cybersecurity regimes, two different questions

The CRA follows products; NIS2 primarily follows covered entities and services.

What this guide covers

  • Assess CRA scope around the product and economic operator
  • Assess NIS2 under the relevant Member State's implementing law
  • Reuse factual evidence while preserving separate legal triggers and approvals

This article provides general information about the EU Cyber Resilience Act. It is not legal advice.

Take the CRA readiness assessment · Read all CRA guides