NIS2 and CRA compliance obligations for product manufacturers — interconnected cybersecurity frameworks

NIS2 vs CRA: What Product Manufacturers Must Document Before December 2027 — and the Obligations That Apply Under Both Regimes

Most manufacturers treating NIS2 and the Cyber Resilience Act as two separate compliance projects are building a problem they won’t discover until a security incident forces them to act under both simultaneously.

The logic for separation seems sound: the CRA governs the products you place on the EU market; NIS2 governs your organisation as an operator of essential or important services. Different regulators, different scopes, different documentation. But a significant number of manufacturers — specifically those producing connected industrial equipment, electrical systems, computers, or machinery while also meeting NIS2’s Annex II sector and size thresholds — fall squarely inside both regimes at once.

When that happens, a single actively exploited vulnerability can trigger a 24-hour notification to ENISA under CRA Article 14 and a parallel 24-hour early warning to your national competent authority under NIS2 Article 23. Two clocks start simultaneously. Two final reports run on different deadlines. One organisation must manage both.

This article maps exactly who the dual-scope manufacturer is, where the two regimes’ obligations converge, and how to build one documented programme that satisfies both. Key dates: CRA reporting obligations start 11 September 2026. Full CRA applicability: 11 December 2027. NIS2 enforcement is already active.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Two Regulations, Two Layers of the Same Problem

The CRA and NIS2 address cybersecurity at different points in the same supply chain. NIS2 Directive (EU) 2022/2555 imposes risk management and incident reporting obligations on entities operating in critical sectors — the organisations providing services. The CRA, Regulation (EU) 2024/2847, imposes cybersecurity requirements on the manufacturers who produce and sell the digital products those organisations rely on.

Neither regulation treats the other as a complete substitute. The European Commission designed them as complementary layers: NIS2 secures the operational environment; the CRA secures the products deployed within it. A manufacturer who is also an essential or important entity must satisfy both independently.

CRA (Regulation 2024/2847) NIS2 (Directive 2022/2555)
What it regulates Products with digital elements Entities operating in critical sectors
Who it targets Manufacturers, importers, distributors Essential and important entities
Compliance trigger Placing a connected product on the EU market Operating in Annex I or II sector above size threshold
Enforcing body Market surveillance authorities + ENISA National competent authorities
Key deadline Full application: 11 December 2027; reporting: 11 September 2026 Enforcement: active since October 2024
Maximum penalty €15M or 2.5% global annual turnover €10M or 2% (essential); €7M or 1.4% (important)

The table shows two different enforcement bodies and triggers. Those differences disappear the moment a dual-scope manufacturer faces a security incident that touches both regimes simultaneously.

CRA Scope: Which Products and Which Manufacturers Fall Under the Regulation

The CRA applies to “products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network” (Article 2.1). In practice, this captures any hardware or software product that connects to anything — a local network, the internet, or another device via Bluetooth or USB.

The CRA covers connected industrial sensors and PLCs, network equipment (routers, switches, firewalls), consumer and industrial electronics, embedded firmware, standalone software, and remote data processing solutions including cloud services and mobile applications. If your product has an IP address, a firmware update mechanism, or a wireless radio, it almost certainly falls within Article 2’s scope.

Exclusions under CRA Article 2:

  • Medical devices regulated under the MDR (Regulation (EU) 2017/745) and IVDR (Regulation (EU) 2017/746)
  • Aircraft and aeronautical products under Regulation (EU) 2018/1139
  • Marine equipment under Directive 2014/90/EU
  • Products developed exclusively for national security or defence purposes

The MDR exclusion is product-specific. It removes those particular devices from CRA scope but does not exempt the manufacturer from NIS2 as an entity. A medical device manufacturer that also meets NIS2’s Annex II sector and size criteria remains an important entity for NIS2 purposes.

Product risk tiers: The CRA distinguishes three categories based on cybersecurity risk profile. Default-category products (the majority) may self-declare conformity. Important products listed in CRA Annex III — including industrial control systems, network security tools, operating systems, and identity management software — may require third-party conformity assessment if the manufacturer has not applied harmonised standards. Critical products in CRA Annex IV — hardware security modules, smart meter gateways, smart cards — require a notified body in all cases. Manufacturers of Annex III and Annex IV products face a more demanding conformity assessment path whose documentary requirements overlap directly with NIS2 Article 21(2)(e) obligations.

NIS2 Scope for Manufacturers: Annex II Sectors and Size Thresholds

NIS2 does not apply to all manufacturers. It applies to those that pass two independent gates: sector of operation and organisational size. Passing only one gate is not sufficient.

Gate 1 — Sector (NIS2 Annex II, Section 6): Manufacturing is classified as an Important Entity sector. The covered subsectors follow NACE Rev. 2 classification codes:

  • Computers, electronic and optical products (NACE C26) — semiconductors, telecom equipment, measuring instruments, consumer electronics
  • Electrical equipment (NACE C27) — motors, transformers, batteries, wiring and switching devices
  • Machinery and equipment (NACE C28) — industrial engines, compressors, agricultural machinery, machine tools
  • Motor vehicles, trailers and semi-trailers (NACE C29)
  • Other transport equipment (NACE C30) — aircraft, railway equipment, ships
  • Basic pharmaceuticals and pharmaceutical preparations (NACE C21)
  • Medical devices not already covered under NIS2 Annex I (Regulation (EU) 2017/745 and 2017/746)

Manufacturers of “products with digital elements” as defined by the CRA are not identified as a separate NIS2 category. NIS2 classifies by sector of operation, not by product type. A manufacturer of connected sensors is captured via NACE C26, not via any CRA cross-reference.

Gate 2 — Size: Only entities at or above the medium enterprise threshold are in scope. Applying Recommendation 2003/361/EC as referenced in NIS2, a medium enterprise has 50 or more employees, or annual turnover and balance sheet total both exceeding €10 million. Entities below both thresholds are micro or small enterprises and are generally excluded. Penalties for Important entities (the category covering most Annex II manufacturers) reach up to €7 million or 1.4% of global annual turnover. Large entities (250+ employees) in Annex I sectors qualify as Essential and face penalties up to €10 million or 2% of global annual turnover.

The Dual-Scope Manufacturer: A Three-Question Test

Three questions determine whether you face one regime or both. Work through them in order — the first question that produces a “no” removes that regime from your scope.

Question 1: Do you manufacture products with digital elements as defined in CRA Article 2.1 (hardware or software capable of electronic processing with a logical or physical connection to a device or network)? If yes, CRA applies.

Question 2: Does your primary business sector appear in NIS2 Annex I or Annex II? Use the NACE codes listed above. Computer and electronics manufacturers (C26) typically qualify; general food or textile manufacturers do not.

Question 3: Do you meet the medium enterprise size threshold (50+ employees or €10M+ annual revenue and balance sheet)? If yes to both Questions 2 and 3, NIS2 applies.

Manufacturer type CRA NIS2 Reason
45-employee IoT sensor OEM (NACE C26) Yes No Below size threshold (gate 2 fails)
300-employee industrial PLC manufacturer (NACE C28) Yes Yes Both gates passed — dual-scope
MDR-regulated medical device manufacturer No (Art 2.2 exclusion) Sector-dependent CRA product exclusion; NIS2 depends on NACE and size
80-employee software firm selling to energy operators Yes (if software qualifies) Possibly CRA applies to the product; NIS2 depends on own sector classification
2,000-employee automotive manufacturer (NACE C29) Yes (connected components) Yes Both gates passed; potentially Essential if also in Annex I sector

The dual-scope manufacturer in the third row of this table — a medium-to-large producer of connected industrial equipment in an Annex II sector — is the subject of everything that follows. For a full applicability assessment covering all Annex I and Annex II sectors and size thresholds, see the NIS2 scope and applicability guide.

Where the Obligations Converge: Supply Chain, Incident Reporting, and Secure Development

Three specific areas produce genuine obligation overlap between the two regimes. Each creates a compliance burden that can be reduced significantly by designing once for both.

Zone 1: Supply Chain — CRA SBOM Meets NIS2 Article 21(2)(d)

CRA Annex I, Part II requires manufacturers to identify and document the components integrated into their products, including by drawing up a software bill of materials (SBOM) in a commonly used, machine-readable format covering at least top-level dependencies. Acceptable formats include commonly used, machine-readable standards such as SPDX, CycloneDX, or SWID. The SBOM does not need to be published publicly but must be available to market surveillance authorities on request. As part of mandatory CRA technical documentation, manufacturers must retain it for at least ten years after the product is first placed on the market. This requirement applies from 11 December 2027.

NIS2 Article 21(2)(d) requires entities to address “security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.” An NIS2-covered customer buying connected industrial equipment from a dual-scope manufacturer needs documented evidence that the manufacturer manages software components responsibly.

A CRA-compliant SBOM is precisely the artefact that an NIS2 important entity’s Article 21(2)(d) supplier assessment would request from a digital product vendor. For a dual-scope manufacturer, maintaining a CRA-compliant SBOM simultaneously satisfies your own NIS2 supply chain documentation obligation and provides the transparency your customers need for their supply chain risk assessments. One document serves both directions in the same supply chain.

For guidance on structuring supplier assessments under Article 21(2)(d), see the NIS2 supply chain security requirements overview and the guide to classifying NIS2 suppliers.

Zone 2: Incident Reporting — The Dual-Trigger Scenario

This is the zone where treating the two regimes as separate programmes creates the most acute operational risk. A single security event can force simultaneous action under both frameworks, and internal teams that are not prepared for this will miss one or both notification deadlines.

CRA Article 14 requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting their products via the ENISA Single Reporting Platform, effective 11 September 2026. The timeline for vulnerabilities is: early warning within 24 hours of awareness, full notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For incidents, the final report is due within one month of the initial notification. Manufacturers must also notify impacted users.

NIS2 Article 23 requires essential and important entities to report significant incidents to their national CSIRT or competent authority: early warning within 24 hours, full notification within 72 hours, final report within one month.

CRA Article 14 NIS2 Article 23
What triggers it Actively exploited product vulnerability or severe product security incident Significant incident causing severe service disruption or capable of causing material or financial damage
Early warning 24 hours from awareness 24 hours from awareness
Full notification 72 hours from awareness 72 hours from awareness
Final report 14 days after corrective measure (vulnerabilities); 1 month (incidents) 1 month after initial notification
Recipient Designated CSIRT + ENISA (simultaneously, via Single Reporting Platform) National CSIRT or competent authority
Effective date 11 September 2026 Now (enforcement active)

The dual-trigger: an actively exploited vulnerability in your connected industrial firmware causes a significant operational disruption at a customer who is an NIS2 essential entity. You file under CRA Article 14 (product vulnerability — 24h early warning to ENISA). The affected customer files under NIS2 Article 23 (service incident — 24h early warning to national authority). Both clocks start the moment you become aware. Your 14-day vulnerability final report and their 1-month service final report then run independently.

A manufacturer who discovers a zero-day in their firmware on a Tuesday morning must have both early warnings filed by Wednesday morning. If CRA reporting and NIS2 reporting are handled by separate functions communicating via weekly status meetings, neither deadline will be met. The operational requirement is a single intake process with a routing rule that determines whether to file under CRA, NIS2, or both — at the moment of triage, not days later.

For detailed Article 23 notification requirements and timeline documentation, see the Article 23 incident notification guide and the NIS2 incident reporting overview.

Zone 3: Secure Development — CRA Annex I Part I Meets NIS2 Article 21(2)(e)

CRA Annex I, Part I requires that products are designed, developed, and produced with no known exploitable vulnerabilities at market entry, with secure default configurations, effective access controls, the ability to receive security updates, and encryption capabilities where appropriate. These are product engineering requirements that apply throughout the development lifecycle.

NIS2 Article 21(2)(e) requires entities to address “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.” This is an organisational governance requirement covering the systems you operate — and for manufacturers, it also applies to the development process for the products you build.

A dual-scope manufacturer’s engineering team is subject to both simultaneously. The practical solution is a unified secure development lifecycle (SDL) that covers both: one secure coding standard, one peer review process, one vulnerability disclosure policy. Running separate processes for CRA product requirements and NIS2 organisational requirements produces documentation inconsistency without any compliance benefit, and creates the risk that the two versions diverge at exactly the moment an auditor asks to see them together.

Compliance Deadlines: September 2026 and December 2027

For dual-scope manufacturers, September 2026 is the binding constraint — not December 2027. CRA reporting obligations begin 14 months earlier than full CRA applicability, and those reporting obligations require operational capabilities (real-time vulnerability detection, dual-channel reporting infrastructure, trained response teams) that cannot be assembled in the weeks before the deadline.

Deadline What it requires Who it applies to
Now (NIS2 active) Entity registration with national competent authority; Article 21 security measures implemented; incident response process capable of Article 23 timelines All NIS2 essential and important entities, including Annex II manufacturers meeting the size threshold
11 September 2026 CRA Article 14 reporting infrastructure live; ENISA Single Reporting Platform accessible; internal triage process routes vulnerability notifications within 24 hours; affected users notification process in place All manufacturers of products with digital elements
11 December 2027 Full CRA conformity; CE marking in place; SBOM in machine-readable format; CRA Annex I Part I and Part II essential requirements met; conformity assessment complete (notified body required for Annex III/IV products) All manufacturers of products with digital elements

Role allocation for dual-scope manufacturers:

Obligation CISO / IT Security Compliance / Legal Board
NIS2 Article 21 implementation Owns technical controls and evidence Documents, monitors, manages audit trail Approves; bears personal liability under Article 20
CRA Article 14 reporting Operates detection and files notifications Reviews and retains notification records Informed within 24h of any early warning
SBOM maintenance Generates and updates with each release Retains per 10-year obligation
CRA conformity assessment (Annex III/IV) Provides technical file and evidence Coordinates notified body engagement Signs declaration of conformity

Building One Compliance Programme, Not Two

The efficiency gain from treating NIS2 and the CRA as a single programme is meaningful. Most of the underlying data — asset inventory, vulnerability register, risk assessment, supplier list — serves both obligations. The structural question is how that shared data routes to two different regulatory channels, not whether to build it twice.

Step 1 — Scope assessment. Map your products against CRA Article 2.1 to confirm applicability, and against CRA Annex III and Annex IV to determine the conformity assessment route. Separately, map your entity against NIS2 Annex I or Annex II and verify the size threshold. Document both conclusions in a single gap matrix. The two assessments are independent — do not let a CRA finding about a product influence the NIS2 entity classification. For sector-specific NIS2 applicability, see the NIS2 for manufacturing sector page.

Step 2 — Unified vulnerability intake. Build one triage process with a routing rule: if the vulnerability is in a product placed on the EU market, route to the CRA Article 14 channel (ENISA Single Reporting Platform). If it causes or risks causing a significant service incident at an NIS2-covered customer, simultaneously route to the NIS2 Article 23 channel. Two endpoints, one triage decision, made at detection — not days later when both deadlines are already compromised.

Step 3 — Supply chain integration. Update your supplier assessment questionnaire to require CRA conformity evidence (CE declaration, SBOM availability on request) from digital product suppliers. This simultaneously satisfies your NIS2 Article 21(2)(d) documentation obligation for supply chain risk. For your own SBOM, maintain it as a living document updated with each product release — a one-time filing will be outdated before the ink is dry.

Step 4 — Documentation architecture. A CRA technical file and a NIS2 risk register share the same foundation: the same asset inventory, the same threat model, the same vulnerability disclosure policy. Build the shared layer once, then branch documentation only where the two regimes genuinely diverge: CE marking process and conformity declaration for CRA; national competent authority registration and Article 21 measure documentation for NIS2. One review cycle for the shared layer reduces the maintenance burden across both frameworks.

Frequently Asked Questions

Does the Cyber Resilience Act replace NIS2 for product manufacturers?

No. The two regimes operate in parallel at different points in the supply chain. The CRA governs what you sell (the product); NIS2 governs how you operate (the entity). A manufacturer that places connected equipment on the EU market and also qualifies as an important entity under NIS2 Annex II must satisfy both independently. No provision in either regulation allows one to substitute for the other.

Our medical devices are excluded from the CRA under Article 2.2. Does that also exclude us from NIS2?

No. The CRA Article 2.2 exclusion is product-specific — it removes those particular devices from CRA scope. It has no effect on your organisation’s NIS2 classification. If your entity operates in an Annex II sector and meets the size threshold, NIS2 applies to your operations regardless of the CRA status of your products. You would not file a CRA Article 14 notification for a medical device vulnerability, but you could still face a NIS2 Article 23 obligation if that vulnerability causes a significant operational incident at an essential or important entity customer.

Our products fall under CRA Annex IV (critical). Does Annex IV classification change our NIS2 entity category?

No. CRA product classification (default / important / critical) and NIS2 entity classification (essential / important) are independent assessments. Annex IV status means your products require mandatory third-party conformity assessment by a notified body before CE marking. It has no direct effect on whether you are an essential or important entity under NIS2, or on the scope of your Article 21 obligations.

What is the combined worst-case penalty exposure for a dual-scope manufacturer?

CRA penalties for non-compliance reach up to €15 million or 2.5% of global annual turnover, whichever is higher. NIS2 penalties for an important entity reach up to €7 million or 1.4% of global annual turnover. These are separate penalty regimes enforced by different authorities — they do not offset each other. A dual-scope manufacturer that fails to comply with both faces independent enforcement from market surveillance authorities (CRA) and the national competent authority (NIS2).

Sources

  1. European Union. Regulation (EU) 2024/2847 of the European Parliament and of the Council — Cyber Resilience Act. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
  2. CRA Article 2 — Scope. European Cyber Resilience Act Reference. Cyber_Resilience_Act_Article_2
  3. CRA Article 13 — Manufacturer Obligations. European Cyber Resilience Act Reference. Cyber_Resilience_Act_Article_13
  4. CRA Article 14 — Vulnerability and Incident Reporting. European Cyber Resilience Act Reference. Cyber_Resilience_Act_Article_14
  5. Directive (EU) 2022/2555 — NIS2 Directive, Article 21. NIS2 Directive Reference. NIS_2_Directive_Article_21
  6. Directive (EU) 2022/2555 — NIS2 Directive, Article 23. NIS2 Directive Reference. NIS_2_Directive_Article_23
  7. European Commission. CRA Reporting Obligations. Shaping Europe’s Digital Future. digital-strategy.ec.europa.eu/cra-reporting

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: