CRA vs NIS2: Product Duties or Operator Duties?

The Cyber Resilience Act regulates the product; NIS2 regulates the entity. The comparison covers who is addressed, protection objectives, conformity evidence, the two separate reporting routes, and the case where a manufacturer is also caught as an operator.

Cyber Resilience Act vs. NIS2Cyber Resilience ActLast reviewed:

The Cyber Resilience Act and NIS2 are frequently named in one breath, because both sit under the heading of EU cybersecurity and because both speak of risk management, vulnerabilities and reporting duties. In what they attach to, however, they lie far apart, and confusing them regularly produces projects cut to the wrong shape.

The decisive difference is the question of what the law hooks onto. The Cyber Resilience Act is product safety law: what is regulated is the product with digital elements made available on the Union market, and those placed under duties are manufacturers, importers and distributors. NIS2 is operator law: what is regulated is the entity that operates its own network and information systems, and in Germany the classification runs through sector and company size under the BSI Act.

Two different worlds of evidence follow from that. The Cyber Resilience Act ends in technical documentation, an EU declaration of conformity and CE marking. Without those, a product in scope may not be placed on the market. NIS2 ends in a demonstrably effective management system towards the supervisory authority; there is no marking there.

It becomes difficult for organisations that are both. A machine builder with networked controllers, a supplier of network technology, or a software house that also operates its application as a service can fall under the Cyber Resilience Act as a manufacturer and under the BSIG as an entity.

Side by side

CriterionCyber Resilience ActNIS2
Legal act and legal formRegulation (EU) 2024/2847. As a regulation it applies directly in every member state and in identical wording. It entered into force in December 2024 and takes effect in stages.Directive (EU) 2022/2555. As a directive it takes effect only through national law. What governs in Germany is the BSI Act in the version given to it by the NIS-2-Umsetzungsgesetz (the German NIS2 transposition act), which entered into force on 6 December 2025.
Subject of regulationThe product. What is regulated are products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.The organisation. The entity in scope is the one that operates its own network and information systems and delivers services whose failure would have noticeable consequences for supply, the economy or public administration.
AddresseeManufacturers, importers and distributors. The main burden lies with the manufacturer. Anyone marketing a product under their own name or brand, or substantially modifying a product already placed on the market, counts as a manufacturer themselves.Essential and important entities in the sectors listed in the annexes to the BSIG, together with operators of critical installations. What governs are sector and company size under § 28 BSIG; operators of critical installations are covered irrespective of size.
Protection objectiveThe cybersecurity properties of products on the Union market across their whole lifecycle — from a secure default configuration through to the provision of security updates.The security and continuity of the entity's own systems and of the services resting on them. At the centre are risk management, incident handling and the resilience of operations.
Application and timetableStaged: the reporting duties for manufacturers apply from 11 September 2026. The regulation is fully applicable from 11 December 2027; from then on, products in scope may be placed on the market only where conformity has been established.The duties under the BSIG already exist. The BSI registration portal has been in operation since January 2026 and the first registration deadline fell in March 2026.
Core dutiesAnnex I Part I governs product properties such as secure default configuration, protection against unauthorised access, data minimisation and secure updateability. Part II governs vulnerability handling across the lifecycle, including a bill of materials for the software components (SBOM), coordinated disclosure and security updates. A support period has to be determined on top of that.§ 30(2) BSIG lists a binding catalogue, among it risk analysis and security policies, the handling of security incidents, the maintenance of operations with backup and crisis management, supply chain security, cryptography, access control and multi-factor authentication. Registration and reporting duties come on top.
Conformity and evidenceTechnical documentation, an EU declaration of conformity and CE marking. The route there depends on the risk class: self-assessment for the majority of products, stricter procedures for important products, frequently involving a notified body.No marking and no declaration of conformity. What has to be evidenced towards the BSI is the implementation and effectiveness of the measures. A certificate to ISO/IEC 27001 is a good starting position for that, but it is not statutory evidence.
Reporting dutiesWhat is reported are actively exploited vulnerabilities and severe security incidents: an early warning within 24 hours and a substantively fuller notification within 72 hours. The final report follows two separate tracks: for an actively exploited vulnerability it has to be submitted no later than 14 days after a corrective or mitigating measure is available; for a severe security incident, within one month of the 72-hour notification. An interim report is to be submitted only on request. The recipients are the CSIRT designated as coordinator and ENISA, through the single reporting platform.What is reported are significant security incidents under § 32 BSIG, in three stages: an early initial notification within 24 hours, a fuller notification within 72 hours, and a final notification one month after that notification. The addressee is the reporting office set up jointly by the BSI and the BBK.
SupervisionThe market surveillance authorities of the member states, on the pattern of the rest of product safety law. The instruments range from requesting documents through to measures against a product's availability on the market.The BSI. Essential entities can be examined proactively; important entities as a rule only once the BSI has indications of an infringement.
SanctionsThe regulation provides for tiered fine ranges that alternatively attach to worldwide annual turnover. In practice the product-law consequences often weigh more heavily, where a product may no longer be placed on the market.The directive sets tiered maximum amounts: up to 10 million euros or 2 per cent for the higher entity category, up to 7 million euros or 1.4 per cent for the lower one. What governs the assessment is the fine catalogue of the BSIG. § 38 BSIG additionally establishes duties and liability for the management body.
How the two meshProduces exactly the material operators need for their supply chain risk management: a bill of the components, the support period, information on vulnerabilities resolved, and dependable security updates.Requires supply chain security and uses the manufacturers' product information for it. The two legal acts mesh: one sees to secure products on the market, the other to their secure operation.
Who is caughtEvery company that makes hardware or software with digital elements available on the Union market in the course of a commercial activity, irrespective of sector and size. Excluded are product groups with their own sector-specific Union law, and products solely for national security and defence.Only entities in the sectors covered, from the size thresholds upwards, together with operators of critical installations. Every organisation has to determine for itself whether it is in scope; there is no notification from an authority.

Our verdict

The classification is simpler than the debate suggests: ask first what you do, not who you are. If you place a product with digital elements on the Union market, the Cyber Resilience Act applies. If you operate systems in a sector covered and above the size thresholds, the BSIG applies. These are two independent assessments with two independent outcomes.

The double case is more common than expected. A machine builder whose networked controllers fall under the Cyber Resilience Act and which, as a manufacturing company, also crosses the BSIG thresholds is an addressee of both regimes, for different subjects. The same holds for providers that both ship a piece of software and operate it themselves as a service, and for manufacturers of network or security technology that also count as digital infrastructure.

What matters is keeping the subjects cleanly apart. The product duties hang on the artefact shipped and accompany it through the support period. The operator duties hang on your own IT and your own services. A vulnerability in your own product that you also run yourself can therefore trigger both sets of duties, with different triggers, different recipients and different content. These cases belong to be settled before the real thing, not after.

What can be brought together. Vulnerability management, the ability to report within 24 hours, supplier management, cryptography and access control carry in both regimes. Anyone who builds those capabilities once so that they hold, and keeps the evidence for them in one place, can use them more than once.

What has to stay separate. Conformity assessment with technical documentation, an EU declaration of conformity and CE marking has no equivalent under NIS2. Conversely, registration with the BSI has no counterpart in product law. And the reporting routes differ: the manufacturer reports to the CSIRT designated as coordinator and to ENISA through the single reporting platform; for manufacturers whose main establishment is in Germany, the BSI is that coordinator CSIRT (§ 5(1) sentence 2 BSIG). The entity reports under § 32 BSIG to the reporting office set up jointly by the BSI and the BBK.

For scheduling: the operator duties under the BSIG already exist, while the product duties phase in. The reporting duties for manufacturers apply from 11 September 2026, and full applicability follows from 11 December 2027. Anyone developing a product today that will still be sold beyond that point is deciding its conformity now.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework