All posts

NIS2, DORA or the Cyber Resilience Act: Which One Reaches You

Three EU cyber laws with overlapping vocabulary and different scopes. How to tell which applies to your organisation, and where they stack.

Published 5 min readBy the Auditly teamDiesen Beitrag auf Deutsch lesenLire cet article en français

Between 2024 and 2027 the European Union brought three major cybersecurity laws into application. They share vocabulary, they reference one another, and they are routinely confused. A software company can be in scope of one, two or all three depending on what it sells and to whom, and the obligations do not merge; they stack.

Here is the shortest reliable way to tell them apart.

The one-line versions

NIS2 (Directive (EU) 2022/2555) regulates the cybersecurity of organisations that provide services society depends on. It applies by sector and size. It is a directive, so each Member State turned it into national law, with a deadline of 17 October 2024 that several missed.

DORA (Regulation (EU) 2022/2554) regulates the ICT resilience of the financial sector and the suppliers that sector depends on. It has applied directly across the EU since 17 January 2025.

The Cyber Resilience Act (Regulation (EU) 2024/2847) regulates the cybersecurity of products with digital elements placed on the EU market: hardware and software, from routers to mobile apps. It entered into force on 10 December 2024. Its reporting obligations apply from 11 September 2026 and the full set from 11 December 2027.

The distinction that resolves most confusion: NIS2 and DORA regulate organisations and how they run; the CRA regulates products and how they are built and maintained.

Which one reaches you

You operate in a listed sector and exceed the size threshold. NIS2. Its Annex I and II sectors include energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing of certain products, digital providers and research. The default threshold is medium-sized: at least 50 employees or 10 million euro turnover, with some entities in scope regardless of size. See our earlier guide on NIS2 scope for the full test.

You are a financial entity. DORA, in place of NIS2 for the ICT risk requirements. DORA is lex specialis: where a financial entity is covered by DORA, DORA's rules on ICT risk management, incident reporting and testing apply instead of NIS2's. The financial regulator supervises you, not the cybersecurity authority.

You supply ICT services to financial entities. DORA reaches you through your customers' contracts, and directly if you are designated a critical ICT third-party provider. You may also be in NIS2 in your own right if you are, say, a cloud provider or a managed service provider above the size threshold.

You make or sell software or connected hardware. The CRA. It applies to manufacturers, importers and distributors of products with digital elements, with exemptions for some products already covered by sectoral law (medical devices, vehicles, civil aviation) and for open-source software developed outside a commercial activity. SaaS is largely out of scope as a product, unless it forms part of a product's remote data processing, but the software you ship to customers is in.

You are a SaaS provider selling into all of these. Possibly NIS2 as a digital provider or ICT service manager, DORA through your financial customers, and the CRA for any client software or on-premise components you distribute. This is the common case for B2B technology companies and the reason the three laws need to be considered together.

What each one asks for

NIS2 asks for governance and risk management: a set of measures under Article 21 covering risk analysis, incident handling, business continuity, supply chain security, secure development and vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication. Management bodies must approve the measures, oversee them, and can be held personally liable. Significant incidents are reported to the CSIRT or authority with an early warning within 24 hours, a notification within 72 hours, and a final report within a month. Fines reach 10 million euro or 2 percent of turnover for essential entities, 7 million euro or 1.4 percent for important ones.

DORA asks for the same in more prescriptive form and adds two things NIS2 does not: a mandatory testing programme including threat-led penetration testing for significant entities, and a detailed third-party regime with a register of information and mandatory contract clauses. Incident reporting deadlines are tighter, with an initial notification within four hours of classification.

The CRA asks for secure-by-design products: essential cybersecurity requirements in Annex I covering the product's properties (no known exploitable vulnerabilities at release, secure default configuration, protection against unauthorised access, data minimisation, resilience, logging) and the manufacturer's vulnerability handling (an SBOM, coordinated disclosure, security updates for the support period, which is at least five years unless the product's life is shorter). Products are classified as default, important (class I or II) or critical, which decides whether self-assessment is enough or a third party must assess. CE marking, technical documentation and an EU declaration of conformity follow. From September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours of awareness.

Where they stack

A company can be an important entity under NIS2, a supplier to DORA entities, and a manufacturer under the CRA at the same time. The obligations do not cancel out, but the evidence overlaps heavily. One ISO 27001 information security management system can carry the NIS2 measures and most of the DORA risk framework. One secure development lifecycle can satisfy NIS2 Article 21's development requirement, DORA's testing expectations and the CRA's vulnerability handling. One incident process with the tightest deadline (DORA's four hours) will meet the others.

The practical approach is to map once. Build a control set, tag each control with the article of each law it serves, and maintain one body of evidence. Auditors engaged for any of the three will accept a well-mapped integrated system far more readily than three parallel ones, and the mapping is itself evidence of the governance all three laws demand.

What to do this quarter

Decide which laws apply, in writing, with the reasoning. Identify the competent authority for each. Check your national NIS2 law for the registration requirement, which many entities have missed. If you ship products, classify them under the CRA now; the September 2026 reporting date is the first hard deadline and the December 2027 date requires the product work to already be under way. And if you have financial customers, expect the DORA contract clauses and have your answers ready.

ShareLinkedInXEmail
Keep reading