Ch.17 Identity, Data and Cybersecurity: eIDAS 2.0, Data Act, NIS2, CRA Trap
Question

How do you separate NIS2 from the Cyber Resilience Act in a test item?

Tap to reveal answer
Answer

NIS2 is about entity risk management and incident reporting; CRA is about product cybersecurity requirements.

If the question says hospital, energy company, or public administration, think NIS2. If it says connected product, think CRA.

EPSOHQ Digital Skills DB / EU digital acquis
Deep dive

NIS2 vs CRA: entity or product?

NIS2 governs entity risk management and incident reporting; CRA governs product cybersecurity requirements. The exam trap is misapplying one to the other when a scenario mixes an organisation and a device.

Learn more
Listen to this page (beta)

View all flashcards