NIS2 focuses on organisations and services; CRA focuses on products placed on the market.
The Cyber Resilience Act sets cybersecurity requirements for products with digital elements; the exam trap is confusing it with NIS2, which covers organisations and services.