Skip to main content
🎀 Speaking at KubeCon EU 2026 Lessons Learned Orchestrating Multi-Tenant GPUs on OpenShift AI View Session
🎀 Speaking at Red Hat Summit 2026 GPUs take flight: Safety-first multi-tenant Platform Engineering with NVIDIA and OpenShift AI Learn More
DevOps

CRA vs NIS2: Understanding the EU Cybersecurity Regulation Landscape

Luca Berton β€’ β€’ 2 min read
#cra#nis2#eu-regulation#cybersecurity#compliance

πŸ”„ CRA vs NIS2: Two Sides of EU Cybersecurity

The CRA and NIS2 Directive are complementary but different. Organizations may be subject to both. Understanding where they overlap and where they diverge is essential.

Key Differences

AspectCRANIS2
FocusProducts with digital elementsOrganizations and services
WhoManufacturers, importers, distributorsEssential and important entities
WhatProduct security requirementsOrganizational security measures
EnforcementMarket surveillance authoritiesNational cybersecurity authorities
PenaltiesUp to €15M / 2.5% turnoverUp to €10M / 2% turnover
TimelineFull enforcement Dec 2027Transposition Oct 2024

Where They Overlap

Incident Reporting

  • CRA: Report exploited vulnerabilities to ENISA (24h)
  • NIS2: Report significant incidents to CSIRT (24h)
  • Both apply? Report to both if you’re a manufacturer AND an essential entity

Supply Chain Security

  • CRA: SBOM, vulnerability management for products
  • NIS2: Supply chain risk management for the organization
  • Both apply? Your SBOM fulfills part of your NIS2 supply chain obligations

Security by Design

  • CRA: Mandatory for all products
  • NIS2: Required as part of organizational measures
  • Both apply? Security by design in your products helps meet NIS2 organizational requirements

Who Is Subject to Both?

Organizations that:

  1. Manufacture software products (CRA) AND
  2. Operate essential/important services (NIS2)

Examples:

  • Cloud service providers who also sell software products
  • Telecom operators who manufacture network equipment
  • Healthcare technology companies (device manufacturer + service provider)

Compliance Synergies

If you’re subject to both, many activities serve dual purpose:

CRA Requirement          β†’  NIS2 Benefit
─────────────────────────────────────────
SBOM generation         β†’  Supply chain risk assessment
Vulnerability handling  β†’  Incident management
Security by design      β†’  Risk management measures
Security testing        β†’  Security audit requirements
Technical documentation β†’  Governance documentation

Action Plan for Dual Compliance

  1. Single security team β€” don’t create separate CRA and NIS2 teams
  2. Unified incident reporting β€” one process, two notification channels
  3. Shared risk assessment β€” product risks and organizational risks overlap
  4. Combined documentation β€” technical docs serve both regulatory requirements
  5. Integrated audit β€” one audit program covering both regulations

Subject to both CRA and NIS2? I help organizations build unified compliance programs. Get in touch.

Share:

Luca Berton

AI & Cloud Advisor with 18+ years experience. Author of 8 technical books, creator of Ansible Pilot, and instructor at CopyPasteLearn Academy. Speaker at KubeCon EU & Red Hat Summit 2026.

Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens TechMeOut