NIS2 vs CRA: entity or product?
NIS2 governs entity risk management and incident reporting; CRA governs product cybersecurity requirements. The exam trap is misapplying one to the other when a scenario mixes an organisation and a device.
Listen to this page (beta)
NIS2 and the Cyber Resilience Act (CRA) target different layers of cybersecurity. NIS2 applies to entities—think hospitals, energy companies, and public administrations—and mandates risk management processes plus incident reporting. The CRA, by contrast, focuses on products with digital elements, such as smart thermostats, connected medical devices, or software. If a test item describes an organisation's security policies or a breach notification, it is NIS2 territory; if it describes a device's security features or vulnerabilities, it is CRA territory.
To avoid confusion, use a simple elimination trick: ask yourself whether the scenario centres on an entity or a product. For example, a question about a hospital's cybersecurity plan points to NIS2, while one about a smart meter's built-in security points to the CRA. Another hint: NIS2 deals with processes and reporting timelines, whereas the CRA deals with design, lifecycle security, and market surveillance. If the item mentions 'incident notification' or 'risk assessment', lean towards NIS2; if it mentions 'secure by default' or 'vulnerability disclosure', lean towards the CRA.
A compact memory aid: 'NIS2 = entity, CRA = thing'. For a quick test, imagine a scenario with a connected pacemaker: the hospital using it falls under NIS2, but the pacemaker itself falls under the CRA. If the item mixes both, check which aspect the question emphasises—organisation or device—and match accordingly.
How do you separate NIS2 from the Cyber Resilience Act in a test item?
NIS2 is about entity risk management and incident reporting; CRA is about product cybersecurity requirements.