NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
Cyber Resilience Act vs NIS2 vs DORA
Learn

Cyber Resilience Act vs NIS2 vs DORA

·Alexander Sverdlov

The Cyber Resilience Act regulates products. NIS2 regulates the organisations that run essential and important services. DORA regulates the financial sector's ICT risk, and for financial entities it applies instead of NIS2 rather than alongside it. That is the whole distinction, and everything else in this comparison follows from it: who is in scope, what has to be done, when the clock started, and who can fine you.

They are also different kinds of law. The CRA, Regulation (EU) 2024/2847, and DORA, Regulation (EU) 2022/2554, apply directly in every Member State with the same text. NIS2, Directive (EU) 2022/2555, only reaches a company through the national law that transposes it, which is why the NIS2 obligations you actually face depend on which Member State you are in.

Cyber Resilience ActNIS2DORA
Legal formRegulation, directly applicableDirective, transposed nationallyRegulation, directly applicable
Who it applies toManufacturers, importers and distributors of products with digital elements made available in the EU, Art. 2(1)Medium and large entities in the Annex I and II sectors, plus the size-independent cases in Art. 2(2)The financial entities listed in Art. 2(1)(a) to (t), and ICT third-party providers
What it regulatesThe product: Annex I essential requirements, vulnerability handling, conformity assessmentThe entity: the ten Art. 21(2) risk-management measures and Art. 23 reportingThe entity's ICT risk: framework, incidents, testing, third-party risk, information sharing
Key datesIn force 10 December 2024. Art. 14 reporting from 11 September 2026. Full application 11 December 2027, Art. 71Transposition by 17 October 2024, measures applied from 18 October 2024, Art. 41Applies from 17 January 2025, Art. 64
First report due24 hours, Art. 14(2)(a) and 14(4)(a)24 hours, Art. 23(4)(a)4 hours from classification, no later than 24 hours from awareness, Delegated Reg. 2025/301 Art. 5
Maximum fineEUR 15M or 2.5% of worldwide turnover, Art. 64(2)EUR 10M or 2% essential, EUR 7M or 1.4% important, Art. 34No EU-wide ceiling for financial entities. Member States set penalties, Art. 50(3)
EnforcerNational market surveillance authoritiesNational competent authorities under the transposing lawFinancial supervisors. Lead Overseers for critical ICT third-party providers
Maximum fines under the three regimes: 2.5% or EUR 15 million under CRA Article 64, 2% or EUR 10 million for NIS2 essential entities under Article 34, and no EU-wide ceiling under DORA Article 50

What is the difference between the Cyber Resilience Act and NIS2?

The CRA attaches to a thing. Article 2(1) brings in any product with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a data connection, and Article 3(1) defines that product as software or hardware and its remote data processing solutions. The obligations fall on whoever manufactures, imports or distributes it. The sector of the buyer is irrelevant, and so is the sector of the seller. A two-person software company selling a connected component is a manufacturer under the CRA in exactly the way a large electronics group is.

NIS2 attaches to an organisation. Article 2(1) covers public or private entities of a type listed in Annex I or II that are at least medium-sized, and Article 2(2) adds specific cases regardless of size, such as trust service providers, DNS providers and sole providers of a critical service. Article 3 then splits them into essential and important entities, which changes the supervision model and the fine ceiling but not the substantive duties. Those duties are the ten measures in Article 21(2), from risk analysis policies through supply chain security to multi-factor authentication, and the reporting duty in Article 23.

The two regimes touch at the supply chain. Article 21(2)(d) makes supply chain security one of the mandatory NIS2 measures, Article 21(2)(e) adds vulnerability handling and disclosure, and Article 21(3) requires entities to take into account the overall quality of products and the secure development procedures of their suppliers. Recital 67 of the CRA says in terms that the Regulation aims to facilitate compliance with those NIS2 supply chain requirements by making sure the products essential entities buy are built securely and receive timely updates. In practice that means a NIS2 entity's procurement questions and a CRA manufacturer's conformity evidence are the same documents viewed from opposite ends.

Where does DORA fit, and does it replace NIS2?

For financial entities, yes. Article 1(2) of DORA states that in relation to financial entities identified as essential or important under NIS2, DORA is a sector-specific Union legal act for the purposes of Article 4 of that Directive. Article 4(1) of NIS2 then provides that where a sector-specific act requires at least equivalent risk-management measures or incident notification, the relevant NIS2 provisions, including supervision and enforcement, do not apply. Recital 28 of NIS2 spells out the consequence: Member States should not apply the NIS2 provisions on risk management, reporting, supervision and enforcement to financial entities covered by DORA.

DORA's scope is a list, not a test. Article 2(1) names twenty categories of financial entity, from credit institutions and payment institutions through investment firms, insurers, crypto-asset service providers and crowdfunding platforms, and adds ICT third-party service providers as a twenty-first category with its own oversight regime. If you are on that list, DORA applies from 17 January 2025 and displaces NIS2 for the matters it covers. If you are not, DORA reaches you only through your contracts with financial entities under Article 28 and, for the largest providers, through designation as a critical ICT third-party provider.

What DORA does not displace is the CRA. A bank that develops and places on the market a product with digital elements is a manufacturer for that product. A bank's software supplier is a manufacturer under the CRA for the product and an ICT third-party service provider under DORA for the service. The two regimes address different things and both apply.

Where the three regimes meet: CRA Annex I Part II vulnerability handling, NIS2 Article 21(2)(d) supply chain security and Article 21(3) supplier quality, DORA Article 28 third-party risk, DORA Article 1(2) and NIS2 Article 4 on sector-specific acts

Can one organisation be in all three?

Yes, and the cleanest example is a software vendor selling to banks. Its product is a product with digital elements, so it is a CRA manufacturer with Annex I duties and Article 14 reporting from 11 September 2026. If it provides managed services and is at least medium-sized, it is an entity of a type in Annex I of NIS2 and faces Article 21 and Article 23. Its contracts with financial entity customers must carry the Article 30 provisions of DORA, and if it becomes critical to the sector it can be designated for direct oversight under Article 31, with periodic penalty payments of up to 1% of average daily worldwide turnover under Article 35(8).

A financial entity that also builds products sits in a different combination: DORA for its own ICT risk, CRA for the products it places on the market, and NIS2 not at all for the matters DORA covers. The mistake to avoid is treating those as three parallel programmes. The controls overlap substantially, and the evidence for one is usually the evidence for another, which our comparison of DORA and NIS2 for dual-scope organisations covers in more detail.

A decision path for which of the three regimes applies: whether you make a connected product, whether you are in a NIS2 sector at medium size, whether you are a DORA financial entity, and how DORA replaces NIS2 Articles 21 and 23

How do the reporting clocks compare?

All three use a staged model, but they start the clock on different events and send the report to different places.

Under the CRA, Article 14 requires a manufacturer to notify an actively exploited vulnerability, or a severe incident affecting product security, to the CSIRT designated as coordinator and to ENISA simultaneously, through the single reporting platform in Article 16. The early warning is due within 24 hours of becoming aware, the fuller notification within 72 hours, and for vulnerabilities a final report no later than 14 days after a corrective or mitigating measure is available. These duties apply from 11 September 2026 and, under Article 69(3), to products placed on the market before the Regulation fully applies.

Under NIS2, Article 23(4) requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of that notification, sent to the CSIRT or the competent authority. The trigger is a significant incident affecting the entity's own services, as defined in Article 23(3).

Under DORA, Article 19 requires an initial notification, an intermediate report and a final report for major ICT-related incidents, sent to the financial supervisor. The time limits are in Article 5 of Delegated Regulation (EU) 2025/301: the initial notification within four hours of classifying the incident as major and in any case within 24 hours of becoming aware, the intermediate report within 72 hours of the initial notification, and the final report within one month of the intermediate report. The four hour figure is the one that catches firms coming from NIS2, because it runs from the classification decision rather than from discovery. Our guide to incident reporting deadlines by regulation sets the three clocks next to GDPR and the AI Act.

Three first-report clocks: 24 hours under CRA Article 14, 24 hours under NIS2 Article 23(4), 4 hours from classification under DORA, and a 72 hour second-stage report under all three from different start points

How do the penalties compare?

The CRA and NIS2 both fix EU-wide ceilings. Article 64 of the CRA sets three tiers: EUR 15 000 000 or 2.5% of total worldwide annual turnover for breaches of the Annex I essential requirements and the Article 13 and 14 duties, EUR 10 000 000 or 2% for the other operator obligations, and EUR 5 000 000 or 1% for supplying misleading information to authorities, in each case whichever is higher. Article 34 of NIS2 requires Member States to provide maxima of at least EUR 10 000 000 or 2% of worldwide turnover for essential entities and EUR 7 000 000 or 1.4% for important ones, again whichever is higher, and Article 20 makes management bodies liable for the entity's Article 21 failures.

DORA takes a different route. Article 50(3) leaves the rules on administrative penalties for financial entities to Member States, requiring only that they be effective, proportionate and dissuasive, and Article 50(4) lists the minimum powers supervisors must have: cease orders, remedial measures including pecuniary ones, and public notices naming the firm. The one EU-wide figure in DORA applies not to financial entities but to critical ICT third-party providers, who face periodic penalty payments of up to 1% of average daily worldwide turnover, imposed daily for up to six months, under Article 35(7) and (8). The detail of each regime is in our guides to Cyber Resilience Act fines and penalties and NIS2 fines and penalties.

What the other results get wrong

Four errors recur across the comparison pages.

The first is dating NIS2 from 16 January 2023. That is when the Directive entered into force for Member States. Under Article 41, companies were reached only when national transposing law applied from 18 October 2024, and in Member States that transposed late, later still. Quoting the 2023 date makes NIS2 look two years older than the obligations actually are.

The second is treating DORA as NIS2 for finance, as though it added a layer on top. Article 1(2) of DORA and Article 4 of NIS2 make it a replacement for the matters it covers. A bank does not owe both an Article 23 NIS2 notification and an Article 19 DORA notification for the same incident.

The third is dating every CRA obligation to December 2027. Article 71 brings the Article 14 reporting duties in on 11 September 2026, and Article 69(3) applies them to products already on the market. The first CRA obligation any manufacturer can breach lands fifteen months before the rest.

The fourth is describing all three as applying to organisations of a certain size. Size matters for NIS2 and, for fine relief, in the CRA. It does not gate CRA scope at all, which turns on the Article 2 product test, and DORA scope turns on the list in Article 2, with only limited carve-outs for the smallest entities.

A readiness dashboard for a programme covering all three regimes: products in CRA scope classified, NIS2 Article 21 measures evidenced, DORA register of information current, and reporting clocks rehearsed

Which of the three applies to you?

Fill this in. Every row has a yes or no answer in the legal text, and the pattern of answers is your programme.

QuestionYour answerWhat it decides
Do you make, import or distribute software or hardware that can connect to a device or network?CRA, Art. 2(1). Reporting from 11 September 2026, the rest from 11 December 2027.
Are you of a type listed in NIS2 Annex I or II, and at least medium-sized or caught by Art. 2(2)?NIS2, unless a sector-specific act such as DORA displaces it under Art. 4.
Are you one of the entities listed in DORA Art. 2(1)(a) to (t)?DORA applies since 17 January 2025 and replaces NIS2 for what it covers.
Do you provide ICT services to any of those entities?DORA Art. 28 and 30 reach you through contract. Art. 31 designation is possible for the largest providers.
Are your products bought by NIS2 entities or DORA financial entities?Your CRA conformity evidence is their supply chain evidence under NIS2 Art. 21(3) and DORA Art. 28.
Which of the three first-report clocks could you meet today?24 hours, 24 hours, and 4 hours from classification. The DORA one is the hardest to rehearse.

If the answers put you in two or three regimes, the efficient move is one control set with three sets of evidence, mapped once. The framework pages for the Cyber Resilience Act, NIS2 and DORA set out each requirement area, and a free compliance check gives you a starting position across them.

The bottom line: the Cyber Resilience Act follows the product, NIS2 follows the entity, and DORA follows the financial sector

Frequently asked questions

Is the Cyber Resilience Act part of NIS2?

No. They are separate legal acts. The CRA is a Regulation on product cybersecurity; NIS2 is a Directive on the cybersecurity of entities. The CRA borrows NIS2 definitions of incident and near miss in Article 3 and routes its notifications to the CSIRTs designated under NIS2, but the obligations and the enforcers are different.

If we comply with DORA, do we also need to comply with NIS2?

For a financial entity in DORA's scope, not for the matters DORA covers. Article 1(2) of DORA and Article 4 of NIS2 make DORA the applicable regime for ICT risk management, incident reporting, supervision and enforcement. Article 2(10) of NIS2 also excludes entities that a Member State has exempted from DORA under Article 2(4) of that Regulation.

Does the CRA apply to a bank?

Only if the bank manufactures, imports or distributes a product with digital elements that it makes available on the market. Internal systems that are never placed on the market are not products in that sense. A bank's suppliers of such products are manufacturers regardless of who the customer is.

Which regime has the shortest reporting deadline?

DORA, for the initial notification: four hours from classifying an incident as major, and never later than 24 hours from awareness, under Article 5 of Delegated Regulation (EU) 2025/301. The CRA and NIS2 both give 24 hours from awareness for the early warning.

Which applies first in time?

NIS2 obligations applied through national law from 18 October 2024. DORA applied from 17 January 2025. The CRA's Article 14 reporting duties apply from 11 September 2026, and the rest of the CRA from 11 December 2027.

Primary sources

Scope, dates, reporting clocks and penalties are taken from Articles 2, 3, 13, 14, 16, 64, 69 and 71 of Regulation (EU) 2024/2847, the Cyber Resilience Act; Articles 2, 3, 4, 20, 21, 23, 34 and 41 and recital 28 of Directive (EU) 2022/2555, NIS2; Articles 1, 2, 19, 28, 30, 31, 35, 50 and 64 and recital 16 of Regulation (EU) 2022/2554, DORA; and Article 5 of Commission Delegated Regulation (EU) 2025/301 on DORA incident reporting time limits. National transposition of NIS2 varies by Member State. Confirm the current text before relying on a date or figure.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING