Two EU cybersecurity laws land on software companies within fifteen months of each other, and most explainers treat them as competitors or as a single blur. They are neither. The Cyber Resilience Act, Regulation (EU) 2024/2847, regulates products. The NIS2 Directive, Directive (EU) 2022/2555, regulates entities. Which one reaches you depends on what you sell and how big you are, and a company can be under both.

Here is the distinction, the two tests, and the practical differences that matter when both apply.

The one-sentence version

  • CRA: you place a product with digital elements on the EU market (installed or downloadable software, an app, a library, firmware, a device, and the remote processing a product cannot work without). Applies to the product and its manufacturer regardless of size.
  • NIS2: you are a medium-sized or larger entity providing a service in one of the listed sectors (cloud computing, data centres, managed services, online marketplaces, search engines, social networks, DNS, and the rest of Annexes I and II), or a smaller one a member state has specifically identified. Applies to the organisation, not to any product.

Pure software as a service is the case that decides most software companies: it is a service, so it is outside the CRA by Recital 12, and it is inside NIS2 if the provider is medium-sized or larger and in a listed sector, cloud computing being the obvious one.

The decision table

You CRA NIS2
Sell installed or downloadable software, any size Yes, as manufacturer Only if you are also a medium-sized or larger entity in a listed sector
Sell a device with software in it, any size Yes, as manufacturer Same as above
Run a SaaS platform, under 50 staff and under EUR 10 million turnover No, unless a product you place on the market depends on it No, unless a member state has identified you
Run a SaaS platform, 50 or more staff or EUR 10 million or more turnover, cloud or listed sector No, unless a product depends on it Yes, as an important or essential entity
Sell installed software and run the cloud back end it cannot work without, medium-sized or larger Yes, product and its remote processing Yes, as an entity, if in a listed sector
Build custom software for one customer and hand it over Yes, as manufacturer of that product Only if you are also a listed entity

The size line is the NIS2 one: Article 2(1) applies the Directive to entities that qualify as medium-sized under Commission Recommendation 2003/361/EC or exceed its ceilings, which means 50 or more staff or more than EUR 10 million in turnover, with the Directive's own exceptions for certain entities regardless of size. The CRA has no size line at all.

What each one asks for

CRA: the 22 essential requirements of Annex I built into the product and its vulnerability handling, a technical file, a conformity assessment whose route depends on the product's tier, CE marking, a support period of at least five years, and Article 14 reporting of actively exploited vulnerabilities and severe incidents.

NIS2: the ten risk-management measures of Article 21(2), which for the digital sectors are spelled out in Implementing Regulation (EU) 2024/2690 and map onto an ISO 27001 management system section by section; registration with the national authority; management-body accountability and training; and Article 23 reporting of significant incidents.

The shape is different. The CRA asks what your product is like and what you do about its vulnerabilities. NIS2 asks how your organisation manages risk and what you do about incidents in your services.

The reporting clocks look the same and are not

Both use 24 hours, 72 hours and a final report, and that is where the resemblance ends.

CRA Article 14 NIS2 Article 23
What triggers it An actively exploited vulnerability in the product, or a severe incident affecting the product's security A significant incident affecting the entity's service
Early warning 24 hours from awareness 24 hours from awareness
Notification 72 hours from awareness 72 hours from awareness
Final report Vulnerability: 14 days after a corrective or mitigating measure is available. Incident: one month after the 72-hour notification One month after the 72-hour notification
Sent to The CSIRT designated as coordinator for the manufacturer's member state, and ENISA, through the single reporting platform The CSIRT or competent authority of the entity's member state, under national rules
In force 11 September 2026, including products already on the market Since national transposition, due 17 October 2024

A company under both can have two duties from one event: a vulnerability in its product being exploited (CRA) and the resulting incident in its own service (NIS2), with two recipients and two final-report anchors. The CRA's vulnerability final report does not run from awareness, which is the single most common mistake in write-ups that merge the two. The two clocks side by side, with the NIS2 thresholds that make an incident significant, is its own article.

The fines

CRA, Article 64: up to EUR 15 000 000 or 2.5% of worldwide annual turnover for Annex I and Articles 13 and 14; up to EUR 10 000 000 or 2% for the other operator obligations; up to EUR 5 000 000 or 1% for misleading an authority. Size is a mandatory factor under Article 64(5)(c). Written out here.

NIS2, Article 34: member states must provide for maximums of at least EUR 10 000 000 or 2% of worldwide annual turnover for essential entities, and at least EUR 7 000 000 or 1.4% for important entities, for breaches of Articles 21 or 23. "At least" because it is a Directive: national law sets the actual ceiling.

Who enforces

Both are enforced nationally. Under the CRA it is the market surveillance authority each member state designates and registers with the Commission, and on the day Article 14 applied, seven of 27 had registered one. Under NIS2 it is the competent authority each member state designates in its transposition, which in most states existed before the Directive and was extended to it.

What to decide, and write down

Two determinations, each one page. First, the CRA scope determination, which six questions on this site produce as text: what you place on the market, whether it has essential remote processing, which exclusion if any, which tier. Second, the NIS2 one: your size under Recommendation 2003/361/EC, which Annex I or II sector you fall in if any, and whether your member state's transposition adds you regardless of size. Date both and keep them together, because the answer to "which law applies" is the first thing either authority reads, and a company that has it written down has already answered the second question, which is who is responsible.

Sources

  • Regulation (EU) 2024/2847 (CRA): Articles 2, 3, 13(8), 14, 32, 52, 64, 69, 71(2); Recital 12; Annexes I, III, IV, VII. Read from the Official Journal text on EUR-Lex on 11 September 2026.
  • Directive (EU) 2022/2555 (NIS2): Article 2(1) (size threshold by reference to Recommendation 2003/361/EC), Article 21(2), Article 23(4) points (a), (b) and (d) (quoted timings), Article 34(4) and (5) (quoted fines), Annexes I and II. Read from EUR-Lex on 11 September 2026.
  • Commission Implementing Regulation (EU) 2024/2690, for the digital sectors' measures.

This is not legal advice. Both texts are on EUR-Lex; the article numbers are there so you can check the two tests against your own company.