Two European cybersecurity laws dominate compliance conversations right now, and they are constantly mixed up. The Cyber Resilience Act and the NIS2 Directive arrived within two years of each other, both carry heavy penalties, both talk about incident reporting and supply chains, and both are described as landmark EU cybersecurity legislation. It is easy to assume they are two versions of the same thing, or that complying with one covers the other.
They are not, and it does not. The cleanest way to understand the difference is to ask what each law is actually about. The CRA is about products. NIS2 is about organisations. The CRA asks whether a thing you build and sell is secure enough to be placed on the market. NIS2 asks whether your organisation manages cyber risk well enough to operate an essential or important service. One is a product law tied to a CE marking. The other is an operational governance law tied to how you run your business.
That single distinction is the spine of everything that follows. Get it wrong and you will either over-scope your compliance program or, far more dangerously, miss an entire law that applies to you. Because here is the part that catches organisations out: many companies are subject to both at the same time. This guide walks through exactly how the two laws differ, where they overlap, what each demands, the deadlines and penalties attached to each, and how to tell which one, or which combination, applies to you.
The Core Difference: Products vs Organisations
If you remember nothing else from this article, remember this table. Every other difference flows from it.
| CRA | NIS2 | |
|---|---|---|
| Regulates | Products with digital elements | Organisations and entities |
| Nature | A product-safety-style law tied to CE marking and market access | An operational cyber risk-management and governance law |
| Unit of compliance | A product | An organisation |
| Time character | A conformity gate when the product is placed on the market, plus a lifecycle duty to handle vulnerabilities and ship updates | A continuous operational duty that never finishes |
| What triggers scope | Placing a product on the EU market | Being an in-scope entity, in a covered sector, at or above the size threshold |
The CRA attaches to a thing. Each product a company makes has to be made compliant, assessed, CE-marked, and supported. If a firm sells ten different connected products, it has ten compliance objects, each with its own classification, documentation, and declaration of conformity. The obligation has a clear moment of truth, the point of placing on the market, and a tail that runs through the support period.
NIS2 attaches to an organisation. It does not care about any single product. It asks whether the entity runs a proper cybersecurity program: governance, risk management, incident handling, business continuity, supply-chain security, training, and so on. There is no CE mark, no product classification. There is a standing obligation to operate securely and to keep operating securely, audited and enforced over time.
Why this matters in practice: the two laws can both apply to one company, because they attach to different units of the same business. Consider an industrial automation vendor. The PLCs, HMIs, and gateways it manufactures are products, so those fall under the CRA. If that same vendor is also a medium or large enterprise operating in a covered sector, or it runs a managed service, then the organisation itself falls under NIS2. The product layer and the operator layer sit on top of each other. Complying with one says nothing about the other.
Legal Instrument: Regulation vs Directive
A difference that sounds like legal trivia but has real operational consequences: the CRA is a Regulation and NIS2 is a Directive. They apply in completely different ways.
The CRA, as a Regulation, is directly applicable in every member state. The text is the law, everywhere, identically. There is no national transposition, no country-specific version, and no variation in the deadlines or the fine ceilings. What the Regulation says is what applies to you, whether you are dealing with Germany, France, or any other member state.
NIS2, as a Directive, is different. A Directive sets objectives that each of the 27 member states must convert into its own national law. The legal obligations that actually bind you flow from each country's national statute, not directly from the Directive. That means the precise obligations, the competent authority, the registration process, and even the maximum fines can differ from country to country.
This created a messy reality that is central to understanding NIS2 today. The Directive entered into force on 16 January 2023, and member states were required to have national NIS2 laws in place by 17 October 2024, with the rules applying from 18 October 2024. In practice, the great majority of member states missed that deadline. Only a handful had transposed on time, and in late November 2024 the European Commission opened infringement proceedings against 23 member states for failing to transpose. Through 2025 and into 2026 the national laws came into force on a staggered timetable, country by country.
The consequence for organisations: you cannot wait for "your" country's law to feel the pressure, and you cannot assume the rules are identical to a neighbouring country's. The underlying obligations are legally due, national authorities are standing up their enforcement, and multinational organisations have to track transposition in each country where they operate. The CRA gives you one text to comply with. NIS2 gives you as many national variations as the member states you touch.
At a Glance: CRA and NIS2 Side by Side
Before going deeper, here is the full head-to-head. Each row is expanded in the sections that follow.
| Dimension | CRA (Regulation (EU) 2024/2847) | NIS2 (Directive (EU) 2022/2555) |
|---|---|---|
| Legal instrument | Regulation, directly applicable, uniform EU-wide | Directive, transposed into 27 national laws |
| Who is regulated | Manufacturers, importers, distributors of products | Essential and important entities in covered sectors |
| Unit of compliance | The product | The organisation |
| What is covered | Cybersecurity of hardware and software products | Cyber risk management and resilience of the entity |
| Core obligation | Meet essential requirements, SBOM, secure updates, conformity assessment, CE marking | Risk-management measures, management accountability, registration |
| Incident reporting | 24h early warning, 72h notification, 14-day final report, via ENISA platform | 24h early warning, 72h notification, 1-month final report, to national CSIRT |
| Maximum fines | Up to €15M or 2.5% of turnover | Essential: up to €10M or 2%, important: up to €7M or 1.4% |
| Non-financial consequences | Product withdrawal, recall, EU market ban | Management liability, suspension of authorisation, ban on individuals from management roles |
| Enforcement | National market surveillance authorities | National competent authorities and CSIRTs |
| Key dates | In force Dec 2024, reporting Sep 2026, full application Dec 2027 | In force Jan 2023, transposition due Oct 2024, applied Oct 2024 |
| CE marking | Central, the CE mark proves conformity | Not applicable |
Who Each Law Covers
The two laws draw their scope in fundamentally different ways: one by role in a product's supply chain, the other by sector and size.
CRA: Economic Operators in the Product Chain
The CRA covers manufacturers, importers, and distributors of products with digital elements, meaning any software or hardware product that connects to a device or network. Manufacturers hold the primary obligations, while importers and distributors carry verification and gatekeeping duties.
Within that, products are sorted into risk tiers that determine how conformity is assessed. Default products can be self-assessed. Important products, which split into Class I (such as password managers, VPNs, operating systems, and network management systems) and Class II (such as firewalls, intrusion detection systems, and hypervisors), face progressively stricter assessment. Critical products, such as smartcards, secure elements, and hardware security modules, face the strictest route of all. The tier decides whether the manufacturer can self-assess or must involve an independent notified body.
Crucially, the CRA reaches manufacturers anywhere in the world. The trigger is placing a product on the EU market, not where the maker sits. Any vendor selling connected products into Europe is bound, and must act through the EU distribution chain.
NIS2: Essential and Important Entities
NIS2 covers organisations, and it decides scope through a combination of sector and size.
The Directive names 18 sectors across two annexes. Annex I lists 11 sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Annex II lists 7 other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers, and research.
Size matters too. As a general baseline, NIS2 applies to medium and large enterprises, meaning those with at least 50 employees or more than €10 million in annual turnover or balance sheet, operating in those sectors. Some entity types are in scope regardless of size, for example DNS and top-level-domain providers, trust service providers, and providers of public electronic communications networks.
The combination of sector and size produces the classification, and this is where a common shorthand needs care. It is not simply "Annex I means essential and Annex II means important." The rule is size plus sector. Large entities in the high-criticality Annex I sectors are generally essential. Medium entities in Annex I, together with entities in the Annex II sectors, are generally important. Certain entity types are essential regardless of size. The classification matters, because it drives both how intensively you are supervised and how large a fine you can face.
What Each Law Requires
Because one governs products and the other governs organisations, their core obligations look entirely different in character.
CRA Obligations: Building a Secure Product
Under the CRA, a manufacturer must make each product meet the essential cybersecurity requirements. Those come in two parts. The product itself must have sound security properties: no known exploitable vulnerabilities at release, a secure-by-default configuration, access control, encryption for confidentiality, integrity protection, data minimisation, resilience against denial of service, a reduced attack surface, and security logging. Alongside the product, the manufacturer must run vulnerability-handling processes: producing a machine-readable software bill of materials, remediating vulnerabilities without delay, operating a coordinated vulnerability disclosure policy, and providing free security updates across a support period of at least five years.
The manufacturer then demonstrates all of this through a conformity assessment appropriate to the product's risk tier, draws up an EU declaration of conformity, and affixes the CE marking. That mark is the proof of conformity and the legal gate to the market.
NIS2 Obligations: Running a Secure Organisation
Under NIS2, an in-scope entity must implement a set of cyber risk-management measures and put governance around them. The Directive sets out ten minimum measures that an entity must have in place:
- Policies on risk analysis and information system security.
- Incident handling.
- Business continuity, including backup management, disaster recovery, and crisis management.
- Supply chain security, including the security of relationships with direct suppliers and service providers.
- Security in the acquisition, development, and maintenance of systems, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of the risk-management measures.
- Basic cyber hygiene practices and cybersecurity training.
- Policies on the use of cryptography and, where appropriate, encryption.
- Human-resources security, access-control policies, and asset management.
- Multi-factor authentication or continuous authentication, and secured voice, video, and text communications.
NIS2 then adds a governance dimension that the CRA does not have in the same form. Management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for infringements. Senior managers are required to undergo cybersecurity training. This puts leadership personally on the hook, and it is one of the most important differences in the whole comparison. NIS2 is not a responsibility that a security team can hold quietly on its own. It is a board-level accountability.
In-scope entities must also register with their national competent authority, so that regulators know who falls within the regime.
Incident Reporting Compared
Both laws require staged incident reporting, and at the front end they look almost identical, which is part of why they get confused. The differences are in the trigger, the final deadline, and where the report goes.
NIS2 reporting is triggered by a significant incident, one that has caused or could cause severe operational disruption or financial loss, or that has affected others through considerable damage. The reporting entity must send an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours, and a final report within one month. Reports go to the national CSIRT or competent authority.
CRA reporting is triggered by a product-level event: an actively exploited vulnerability in the product, or a severe incident affecting the product's security. The manufacturer must file an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a corrective measure becoming available, for a vulnerability. Reports go through a single ENISA reporting platform to the national CSIRT and ENISA at once.
| NIS2 | CRA | |
|---|---|---|
| Who reports | The in-scope entity (operator) | The manufacturer |
| What triggers it | A significant operational incident | An actively exploited vulnerability or severe product incident |
| Early warning | 24 hours | 24 hours |
| Notification | 72 hours | 72 hours |
| Final report | 1 month | 14 days after a fix is available |
| Reported to | National CSIRT / competent authority | ENISA single platform, then CSIRT and ENISA |
The shared 24-hour and 72-hour cadence is not a coincidence. The EU deliberately aligned the front end so that organisations face a consistent rhythm. But the triggers are different worlds. NIS2 reporting is about disruption to an operator's service. CRA reporting is about a vulnerability or incident in a product the manufacturer sold. A single company subject to both could, in principle, have to file under both regimes for related events, once as an operator whose service was disrupted, and once as the manufacturer of the affected product.
Penalties and Consequences Compared
Both laws carry serious penalties, and in both cases the financial fine is only part of the story. The non-financial consequences are often what should focus the mind.
CRA Penalties
The CRA's fines run in three tiers, based on whichever figure is higher. The top tier is up to €15 million or 2.5% of total worldwide annual turnover for breaching the essential requirements and core obligations. The middle tier is up to €10 million or 2% for most other obligations. The lowest tier is up to €5 million or 1% for supplying incorrect or misleading information.
But the CRA's real stick is market access. Without a valid CE marking and declaration of conformity, a product cannot legally be placed on the EU market at all. Market surveillance authorities can order the withdrawal or recall of non-compliant products already on sale, and can ban a product across the entire Union where it presents a significant risk. For a product business, that is existential in a way a fine is not.
NIS2 Penalties
NIS2's fines are set at EU-level minimum ceilings that national laws can exceed. For essential entities, up to €10 million or 2% of total worldwide annual turnover. For important entities, up to €7 million or 1.4%. The lower ceiling for important entities is a direct consequence of the essential-versus-important classification discussed earlier.
The non-financial consequences under NIS2 are, if anything, more striking, because they reach individuals:
- Personal management liability. Management bodies are accountable and can be held personally liable for infringements.
- Suspension of authorisation. For essential entities, authorities can order the temporary suspension of a certification or authorisation covering the services the entity provides. In other words, a regulator can temporarily stop the organisation from operating part of its business.
- Temporary ban on individuals. Authorities can request a temporary ban on a named person at chief-executive or legal-representative level from exercising management functions in the entity until the breach is remedied.
Few consequences concentrate executive attention like the prospect of being personally barred from running the company. This is why NIS2 compliance belongs on the board agenda, not just in the security function.
Enforcement and Supervision
The two laws are policed by different authorities in different ways.
The CRA is enforced by national market surveillance authorities, the same kind of bodies that police product conformity for CE-marked goods generally. They verify conformity and hold the power to restrict, withdraw, recall, or ban products, and to impose fines. ENISA operates the reporting platform.
NIS2 is enforced by each member state's national competent authorities, supported by national CSIRTs for incident response, with ENISA supporting cross-border cooperation. NIS2 also applies different levels of scrutiny depending on classification. Essential entities face proactive, ex-ante supervision: authorities can conduct routine audits, inspections, and security scans without any prior evidence of a problem. Important entities face reactive, ex-post supervision: authorities generally act only when they have some indication of non-compliance. The classification you fall into therefore changes not just your maximum fine but how closely you are watched.
How CRA and NIS2 Interlock
For all their differences, the CRA and NIS2 are designed to work together. They are best understood as layers, not alternatives: the CRA secures the product layer, and NIS2 secures the operator layer. The clearest place they meet is supply-chain security.
NIS2 makes supply-chain security a mandatory obligation for in-scope entities. Those entities have to manage the security of their suppliers and the products they buy. The CRA, meanwhile, raises the baseline security of the products entering that supply chain. The result is a kind of compliance handshake: when an NIS2 operator procures CRA-compliant, CE-marked products with SBOMs and guaranteed security updates, it becomes far easier for that operator to demonstrate it is meeting its own supply-chain obligations. A secure product ecosystem makes secure operators achievable, and vice versa.
The two also feed a shared intelligence picture. CRA vulnerability and incident reports flow to ENISA's reporting platform, while NIS2 significant-incident data flows through national CSIRTs into the EU cooperation structures. Between them, the authorities gain visibility across both the products being sold and the organisations operating critical services.
The OT and Industrial Angle
Nowhere do the two laws stack more visibly than in operational technology and critical infrastructure, where a single ecosystem contains both regulated products and regulated operators.
On one side sits the industrial vendor, the maker of PLCs, RTUs, HMIs, industrial network gear, and industrial firewalls. Those products fall under the CRA, and some of them, industrial firewalls and intrusion detection systems for example, land in the higher CRA risk classes that require independent assessment.
On the other side sits the critical-infrastructure operator, the energy utility, the water company, the chemical plant, the manufacturer. That organisation falls under NIS2, in Annex I or Annex II depending on its sector and size.
The practical mechanism that links them is procurement. Because the NIS2 operator is legally responsible for supply-chain security, it can and will use the CRA as procurement leverage, demanding CRA-conformant, CE-marked, SBOM-backed equipment from its vendors, and increasingly asking for IEC 62443 evidence on top. IEC 62443, the international standard for the security of industrial automation and control systems, is the shared technical backbone both regimes lean on: its product-focused parts map onto CRA obligations, and its asset-owner and system parts map onto NIS2 obligations. IEC 62443 answers the "how" that both of these "what" laws leave open. Operators that build these requirements into contracts now will find their NIS2 supply-chain compliance far easier to evidence, and vendors that meet them will win the business.
Common Findings from Beacon Security's Work
In assessments across industrial and critical-infrastructure organisations, a few recurring patterns show how unprepared many are for the reality of these two laws sitting side by side:
- Treating the two laws as one project. Organisations often assume a single "EU compliance" initiative will cover both, then discover the product and organisational obligations require completely different owners, evidence, and timelines.
- Missing the "both apply" case. Industrial vendors that also operate services, and operators that also build products, frequently scope only one law and are blindsided by the other.
- Supply-chain security in name only. NIS2's supply-chain obligation is often a policy statement with no mechanism behind it. There are no security requirements in vendor contracts and no way to verify supplier claims, which the CRA's product obligations are designed to help fix.
- No SBOM anywhere in the chain. Neither vendors nor operators can produce or obtain a software bill of materials, undermining both CRA product duties and NIS2 vulnerability management.
- Governance gap on NIS2. Management bodies are unaware that the law makes them personally accountable, so the board-level approval and oversight NIS2 requires simply is not happening.
- Reporting capability assumed, not built. Very few organisations could actually meet a 24-hour reporting deadline under either regime today.
What to Do If You Are in Scope of Both
For organisations that fall under both laws, the two programs are related but distinct, and both need to be running:
- Map your exposure to each law separately. For the CRA, inventory every product you place on the EU market and classify it. For NIS2, confirm whether your organisation is an essential or important entity based on sector and size, in every country where you operate.
- Assign the right owners. CRA compliance belongs with product and engineering leadership. NIS2 compliance is an organisational governance program that the management body must own and approve. They are not the same team.
- Build the shared foundations once. SBOM generation, vulnerability management, coordinated disclosure, and supply-chain security serve both laws. Build them once and use them on both sides of the handshake.
- Use IEC 62443 as the common technical language, mapping its product parts to CRA duties and its operator parts to NIS2 measures.
- Track the deadlines that apply to you. For the CRA, the fixed EU-wide dates: reporting from September 2026, full application December 2027. For NIS2, the national transposition law in each country you operate in, which is already in force in most member states.
- Get incident reporting operational now, for both regimes, before either deadline forces the issue.
The Cyber Resilience Act and NIS2 are not competing frameworks or duplicate paperwork. They are two halves of a deliberate European strategy: make the products secure, and make the organisations that operate them secure. Understanding which one applies to which part of your business, and acting on both where both apply, is the difference between a coherent compliance posture and an expensive, personally risky gap.
Beacon Security helps industrial vendors and critical-infrastructure operators navigate overlapping cybersecurity regulation, from CRA product readiness and IEC 62443 alignment to NIS2 risk-management programs and supply-chain security. Contact us to map exactly which obligations apply to your business and build a plan for both.

