Two EU cybersecurity laws land on software companies within fifteen months of each other, and most explainers treat them as competitors or as a single blur. They are neither. The Cyber Resilience Act, Regulation (EU) 2024/2847, regulates products. The NIS2 Directive, Directive (EU) 2022/2555, regulates entities. Which one reaches you depends on what you sell and how big you are, and a company can be under both.
Here is the distinction, the two tests, and the practical differences that matter when both apply.
The one-sentence version
- CRA: you place a product with digital elements on the EU market (installed or downloadable software, an app, a library, firmware, a device, and the remote processing a product cannot work without). Applies to the product and its manufacturer regardless of size.
- NIS2: you are a medium-sized or larger entity providing a service in one of the listed sectors (cloud computing, data centres, managed services, online marketplaces, search engines, social networks, DNS, and the rest of Annexes I and II), or a smaller one a member state has specifically identified. Applies to the organisation, not to any product.
Pure software as a service is the case that decides most software companies: it is a service, so it is outside the CRA by Recital 12, and it is inside NIS2 if the provider is medium-sized or larger and in a listed sector, cloud computing being the obvious one.
The decision table
| You | CRA | NIS2 |
|---|---|---|
| Sell installed or downloadable software, any size | Yes, as manufacturer | Only if you are also a medium-sized or larger entity in a listed sector |
| Sell a device with software in it, any size | Yes, as manufacturer | Same as above |
| Run a SaaS platform, under 50 staff and under EUR 10 million turnover | No, unless a product you place on the market depends on it | No, unless a member state has identified you |
| Run a SaaS platform, 50 or more staff or EUR 10 million or more turnover, cloud or listed sector | No, unless a product depends on it | Yes, as an important or essential entity |
| Sell installed software and run the cloud back end it cannot work without, medium-sized or larger | Yes, product and its remote processing | Yes, as an entity, if in a listed sector |
| Build custom software for one customer and hand it over | Yes, as manufacturer of that product | Only if you are also a listed entity |
The size line is the NIS2 one: Article 2(1) applies the Directive to entities that qualify as medium-sized under Commission Recommendation 2003/361/EC or exceed its ceilings, which means 50 or more staff or more than EUR 10 million in turnover, with the Directive's own exceptions for certain entities regardless of size. The CRA has no size line at all.
What each one asks for
CRA: the 22 essential requirements of Annex I built into the product and its vulnerability handling, a technical file, a conformity assessment whose route depends on the product's tier, CE marking, a support period of at least five years, and Article 14 reporting of actively exploited vulnerabilities and severe incidents.
NIS2: the ten risk-management measures of Article 21(2), which for the digital sectors are spelled out in Implementing Regulation (EU) 2024/2690 and map onto an ISO 27001 management system section by section; registration with the national authority; management-body accountability and training; and Article 23 reporting of significant incidents.
The shape is different. The CRA asks what your product is like and what you do about its vulnerabilities. NIS2 asks how your organisation manages risk and what you do about incidents in your services.
The reporting clocks look the same and are not
Both use 24 hours, 72 hours and a final report, and that is where the resemblance ends.
| CRA Article 14 | NIS2 Article 23 | |
|---|---|---|
| What triggers it | An actively exploited vulnerability in the product, or a severe incident affecting the product's security | A significant incident affecting the entity's service |
| Early warning | 24 hours from awareness | 24 hours from awareness |
| Notification | 72 hours from awareness | 72 hours from awareness |
| Final report | Vulnerability: 14 days after a corrective or mitigating measure is available. Incident: one month after the 72-hour notification | One month after the 72-hour notification |
| Sent to | The CSIRT designated as coordinator for the manufacturer's member state, and ENISA, through the single reporting platform | The CSIRT or competent authority of the entity's member state, under national rules |
| In force | 11 September 2026, including products already on the market | Since national transposition, due 17 October 2024 |
A company under both can have two duties from one event: a vulnerability in its product being exploited (CRA) and the resulting incident in its own service (NIS2), with two recipients and two final-report anchors. The CRA's vulnerability final report does not run from awareness, which is the single most common mistake in write-ups that merge the two. The two clocks side by side, with the NIS2 thresholds that make an incident significant, is its own article.
The fines
CRA, Article 64: up to EUR 15 000 000 or 2.5% of worldwide annual turnover for Annex I and Articles 13 and 14; up to EUR 10 000 000 or 2% for the other operator obligations; up to EUR 5 000 000 or 1% for misleading an authority. Size is a mandatory factor under Article 64(5)(c). Written out here.
NIS2, Article 34: member states must provide for maximums of at least EUR 10 000 000 or 2% of worldwide annual turnover for essential entities, and at least EUR 7 000 000 or 1.4% for important entities, for breaches of Articles 21 or 23. "At least" because it is a Directive: national law sets the actual ceiling.
Who enforces
Both are enforced nationally. Under the CRA it is the market surveillance authority each member state designates and registers with the Commission, and on the day Article 14 applied, seven of 27 had registered one. Under NIS2 it is the competent authority each member state designates in its transposition, which in most states existed before the Directive and was extended to it.
What to decide, and write down
Two determinations, each one page. First, the CRA scope determination, which six questions on this site produce as text: what you place on the market, whether it has essential remote processing, which exclusion if any, which tier. Second, the NIS2 one: your size under Recommendation 2003/361/EC, which Annex I or II sector you fall in if any, and whether your member state's transposition adds you regardless of size. Date both and keep them together, because the answer to "which law applies" is the first thing either authority reads, and a company that has it written down has already answered the second question, which is who is responsible.
Sources
- Regulation (EU) 2024/2847 (CRA): Articles 2, 3, 13(8), 14, 32, 52, 64, 69, 71(2); Recital 12; Annexes I, III, IV, VII. Read from the Official Journal text on EUR-Lex on 11 September 2026.
- Directive (EU) 2022/2555 (NIS2): Article 2(1) (size threshold by reference to Recommendation 2003/361/EC), Article 21(2), Article 23(4) points (a), (b) and (d) (quoted timings), Article 34(4) and (5) (quoted fines), Annexes I and II. Read from EUR-Lex on 11 September 2026.
- Commission Implementing Regulation (EU) 2024/2690, for the digital sectors' measures.
This is not legal advice. Both texts are on EUR-Lex; the article numbers are there so you can check the two tests against your own company.