← Back to Resource Center
Multi-regulation · Scope 9 min read

CRA, NIS2 and the EU AI Act: which one applies to you

Three EU rules, overlapping populations, different duties. One regulates your product, one regulates your organisation, one regulates what your software decides.


If you build and sell software in the EU, you have probably been told that three different rules apply to you, by three different people, with three different levels of alarm.

They are not alternatives, and working out which one applies is the wrong question. They can all apply at once, because they regulate different things.

Here is the distinction that makes the rest of it tractable.

RegulatesAsks
Cyber Resilience ActYour productIs what you ship secure, and can you show it?
NIS2Your organisationIs the company that runs the service managing its own risk?
EU AI ActWhat your software decidesDoes it use AI, and what happens to people when it is wrong?

A single company can be a manufacturer under the CRA, an important entity under NIS2, and a deployer under the AI Act — with three separate sets of obligations, three separate deadlines, and one engineering team.

The Cyber Resilience Act regulates the product

The CRA reaches products with digital elements made available on the EU market in the course of a commercial activity. Software, hardware, and the remote data processing solutions a product depends on to work.

Its questions are product questions. Does it meet the essential cybersecurity requirements? Is there a coordinated vulnerability disclosure policy? Is there a software bill of materials? Will security updates be available for the support period? Can a market surveillance authority see the technical documentation?

It does not care how big you are. There is no employee threshold and no turnover threshold. A two-person company shipping a password manager has the same product obligations as a large vendor shipping one — and the same product class, which for that example is Annex III, Class I.

Two dates. Reporting obligations from 11 September 2026. Everything else — essential requirements, conformity assessment, CE marking — from 11 December 2027.

NIS2 regulates the organisation

NIS2 is a directive, not a regulation, which is the first practical difference: it does not apply to you directly. It applies through your Member State’s implementing law, and those laws differ. Where you are established matters here in a way it does not for the CRA.

It reaches entities in named sectors above a size threshold — energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space, and for important entities also postal services, waste, chemicals, food, manufacturing, digital providers and research. Generally medium-sized and above, with exceptions that pull smaller entities in where they are sole providers or critical to a sector.

Its questions are governance questions. Who is accountable at management level? What is your risk-management policy? How do you handle incidents, business continuity, supply chain security, and access control? Can you report a significant incident within 24 hours?

NIS2 is already in force. Member States were required to transpose it by 17 October 2024, and enforcement follows national timetables from there.

The part that catches software vendors

You may not be a NIS2 entity yourself and still feel NIS2 every week, because your customers are — and Article 21 makes them responsible for the security of their supply chain, including you.

That is why vendor security questionnaires got longer. It is not that your buyer became suspicious. It is that their own regulator now asks them what they know about you.

The EU AI Act regulates what the software decides

The AI Act reaches AI systems, and it assigns duties by role and by risk tier, not by sector or size.

Your role is usually one of two. A provider develops an AI system and places it on the market under its own name. A deployer uses one under its own authority. Most companies integrating a third-party model into a product are deployers of that model and providers of the system they built around it — both at once.

The tiers run from prohibited practices, through high-risk systems with substantial obligations, to limited-risk systems that mainly owe transparency, to minimal risk.

Like the CRA, it has no size exemption. Being an SME changes some of the support you can ask for. It does not remove a duty.

How they overlap in practice

Take one plausible company: eleven people, selling a connected access control product to hospitals and logistics operators, with an anomaly-detection feature built on a third-party model.

  • CRA — identity and access management is Annex III, Class I. The product needs essential requirements, an SBOM, a disclosure policy, and a conformity assessment where the self-assessment door is only open if a harmonised standard exists and is applied in full. Reporting duty from September 2026.
  • NIS2 — they are almost certainly not an entity themselves at eleven people. But their hospital and logistics customers are, so the supply-chain article lands on them through contracts and questionnaires rather than through law.
  • AI Act — the anomaly detection is an AI system. They are a provider of it. Whether it is high-risk depends on what it decides and where it sits; at minimum they owe transparency.

Three regimes, one product, one team. None of them replaces another, and the deadlines do not line up.

What to actually do

Work out your role under each, separately. Manufacturer, importer, distributor or steward under the CRA. Essential entity, important entity, or neither under NIS2. Provider or deployer under the AI Act. The role decides the duties, and people routinely assume the wrong one.

Do the work once where the work is genuinely the same. An asset and dependency inventory serves the CRA’s SBOM requirement and NIS2’s supply-chain article. An incident process serves the CRA’s Article 14 clocks and NIS2’s 24-hour report. Logging and access control appear in all three. These are the same controls described by three regulators, and building them three times is a choice, not a requirement.

Do not merge the parts that are not the same. A NIS2 risk-management policy is not a CRA technical file, and neither is an AI Act risk assessment. Sharing evidence across frameworks is efficient; pretending one document satisfies three regimes is how an audit goes badly.

Sequence by deadline, not by anxiety. NIS2 is in force now. The CRA’s reporting duty is 11 September 2026. The CRA’s full application is 11 December 2027. The AI Act’s obligations phase in on their own schedule. Whichever arrives first for you is the one to build for first.

Where to start

If you are not sure whether the CRA reaches your product at all, start with scope — it is the question the other two get argued about on top of. If you already know it does, the free CRA readiness scan takes about two minutes and tells you where you stand against the September 2026 duty specifically.