NIS 2, the Cyber Resilience Act and the Cybersecurity Act address different parts of EU cybersecurity. Understanding their separate scopes helps organisations assess which duties, products and certification schemes may be relevant.
Three related EU cybersecurity measures
NIS 2, the Cyber Resilience Act (CRA) and the Cybersecurity Act (CSA) are connected, but they do different jobs.
NIS 2 concerns the cybersecurity risk management and significant-incident reporting obligations that apply to essential and important entities within the directive's scope and national transposition. The CRA sets cybersecurity requirements for products with digital elements made available on the EU market, subject to its scope rules and exclusions. The CSA provides the framework for European cybersecurity certification schemes for ICT products, services and processes.
NIS 2 and organisational cybersecurity duties
It applies to essential and important entities in the sectors and entity types specified by the directive and relevant national rules. Inclusion in a named sector alone does not determine whether an organisation is in scope.
The directive requires appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risks. It also sets requirements for reporting significant incidents.
Article 24 gives Member States the option, in particular circumstances, to require essential and important entities to use particular ICT products, services or processes certified under European cybersecurity certification schemes to demonstrate compliance with particular Article 21 requirements. This is not a universal certification requirement, nor does certification by itself demonstrate complete NIS 2 compliance.
The Cyber Resilience Act and products with digital elements
The CRA is Regulation (EU) 2024/2847. It introduces horizontal cybersecurity requirements for covered products with digital elements made available on the Union market, subject to the regulation's scope rules and exclusions.
Manufacturers of covered products must ensure that products are designed, developed and produced in accordance with the CRA's essential cybersecurity requirements. Their duties include carrying out and documenting a cybersecurity risk assessment, as well as meeting vulnerability-handling and support-period requirements.
Article 27 provides routes to a presumption of conformity for the requirements covered. One route may involve an EU statement of conformity or a certificate issued under a European cybersecurity certification scheme, but only where it covers the relevant requirements. It is not a blanket finding that a product conforms to the CRA.
The Commission also has a delegated power, subject to the conditions in Article 8, to identify critical product categories that must obtain a European cybersecurity certificate at an assurance level of at least substantial. This is a conditional mechanism, not a universal certificate mandate for all products with digital elements.
The Cybersecurity Act and EU certification
The CSA gives the EU Agency for Cybersecurity, ENISA, a permanent mandate and establishes a European cybersecurity certification framework. The framework can apply to ICT products, services and processes.
Certification is voluntary unless EU or Member State law provides otherwise. European schemes can use assurance levels including basic, substantial and high. These levels and certificates need to be read in the context of the relevant scheme and the requirements it covers; they do not guarantee complete security.
How NIS 2, the CRA and the CSA differ
| Measure | Main focus | What it provides |
|---|---|---|
| NIS 2 | Cybersecurity risk management and incident reporting for in-scope essential and important entities | Organisational duties, with possible use of certified ICT products, services or processes in specified circumstances |
| CRA | Cybersecurity of covered products with digital elements made available on the EU market | Product and manufacturer requirements, conformity assessment routes and conditional certification mechanisms |
| CSA | European cybersecurity certification | A framework for certification schemes for ICT products, services and processes |
The measures therefore operate at different levels. NIS 2 addresses organisational risk management and reporting. The CRA addresses covered products and the obligations of relevant economic operators, including manufacturers. The CSA supplies a certification framework that NIS 2 and the CRA can draw on where their respective legal conditions are met.
A practical way to assess relevance
A useful starting point is to consider three questions separately:
- Does the entity fall within NIS 2 and the applicable national rules?
- Is a product with digital elements being made available on the EU market within the CRA's scope?
- Is there a relevant European cybersecurity certification scheme, and does a legal requirement make its use necessary?
Only then is it possible to judge whether evidence can be reused across the frameworks. Where requirements and certification scope genuinely overlap, shared evidence may help, but records should retain the relevant requirement, entity, product, scheme and assurance-level context.
Product, procurement and organisational security teams may also need to coordinate. NIS 2 can affect the use of ICT and supply-chain measures, while the CRA governs covered products placed on the market. Keeping these assessments distinct makes it easier to avoid treating certification as an automatic substitute for a separate legal obligation.