CRA: products with digital elements, not services
The Cyber Resilience Act sets cybersecurity requirements for products with digital elements; the exam trap is confusing it with NIS2, which covers organisations and services.
Escuchar esta página (beta)
The Cyber Resilience Act (CRA) focuses on hardware and software products that have digital components, such as smart devices, operating systems, or IoT gadgets. It does not regulate services like cloud computing or online platforms. The key contrast is with NIS2, which targets the cybersecurity of organisations and their services, not the products themselves. If a question mentions a smart thermostat or a connected toy, think CRA; if it mentions a hospital or a bank, think NIS2.
To avoid mixing them up, remember that CRA covers things you can buy and install, while NIS2 covers entities that provide critical services. Another trick: CRA applies to products placed on the EU market, regardless of where the manufacturer is based. If a scenario describes a software update requirement for a router, that is CRA territory. For a quick elimination, ask yourself: is this about a tangible product or an organisation's operations? The answer points to the right regulation.
A compact way to test yourself: if a question lists a smart speaker, a connected car, and a cloud service, which one falls under CRA? The first two do, because they are products with digital elements; the cloud service is a service, so it falls under NIS2. Keep that product-versus-service split in mind, and you will not confuse the two.
What does the Cyber Resilience Act focus on?
Cybersecurity requirements for products with digital elements.