Skip to content
atlas

Don't confuse these

Cyber Resilience Act (CRA) vs NIS2 Directive

Why they differ

NIS2 sets duties for the organisations that run vital services; the CRA sets duties for the products and software they, and everyone else, buy.

Cyber Resilience Act (CRA)

Compliance & regulation

The EU law that makes makers of connected products and software build them secure and keep fixing their flaws.

Formal

Regulation (EU) 2024/2847, in force since 10 December 2024, setting basic security requirements for products with digital elements sold in the EU. Reporting of actively exploited flaws and severe incidents applies from 11 September 2026; all other duties, including the CE mark, from 11 December 2027.

In plain English

Like the safety rules for toys or kettles, but for the software inside things - a gadget that is easy to break into counts as unsafe to sell.

In practice

A Danish maker of smart door locks ships them without a default password, keeps a list of every software part inside, promises five years of free security updates and, on learning a flaw is being exploited, warns the authorities within 24 hours.

Why it matters

Buyers cannot judge the security of a camera, router or app, and makers used to pay little when it failed; the CRA shifts that cost to the maker, with fines of up to 15 million euro or 2.5% of global turnover.

NIS2 Directive

Compliance & regulation

The EU cybersecurity law that sets shared security duties for organisations in important and critical sectors.

Formal

Directive (EU) 2022/2555, to be written into national law by 17 October 2024, which obliges essential and important entities in 18 sectors to manage cyber risk, report significant incidents in stages and make their management body answerable.

In plain English

Like common building safety rules for the whole EU - every country must write them into its own law, and those who keep society running must build by them.

In practice

The board of a mid-sized Danish shipping company learns it falls under NIS2, so it approves a risk assessment, a routine for reporting incidents within 24 hours and security terms for its suppliers.

Why it matters

The first NIS rules covered too few sectors and were applied unevenly; NIS2 brings in thousands more organisations, fines of up to 10 million euro or 2% of turnover, and personal liability for leaders.

Shared connections

Atlas is in beta.