Cyber Resilience Act and NIS2: Do Both Apply to You?

Since 11 September 2026, manufacturers must report exploited vulnerabilities under the CRA. What this means for NIS2 entities, and why most IT managers are only indirectly affected.
Written by the NIS2Compass editorial team | As of: October 2026
Since 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents within 24 hours. It only applies to you if you make connected products, or have them made, and market them under your own name; as a mere operator, you are usually affected only indirectly. To clarify your NIS2 obligations, use the NIS2 applicability check from NIS2Compass.
Who Does the Cyber Resilience Act Cover Since 11 September 2026?
Since 11 September 2026, the reporting obligation under Art. 14 CRA has applied to manufacturers of products with digital elements. Separate CRA obligations for importers and distributors only apply from 11 December 2027. A NIS2-regulated company is only a CRA manufacturer if it develops such products, or has them developed, and markets them under its own name.
Regulation (EU) 2024/2847 covers software and hardware whose intended purpose includes a data or network connection (Art. 2(1), Art. 3(1)). Exemptions include medical devices, in vitro diagnostics and type-approved vehicles (Art. 2(2)). The obligations apply in stages: Chapter IV on conformity assessment bodies since 11 June 2026, Art. 14 since 11 September 2026, everything else from 11 December 2027 (Art. 71(2)).
Under Art. 3(13), a manufacturer is anyone who develops a product, or has it developed, and markets it under their own name, even free of charge. The manufacturer reports under Art. 14, including for legacy products (Art. 69(3)).
Goods you sell under your own brand are a borderline case. Under Art. 3(13), there are good arguments that you are already a manufacturer today; this has not been conclusively settled. From 11 December 2027, Art. 21 and 22 address the case explicitly: anyone who distributes under their own brand or substantially modifies a product then counts as the manufacturer. From the same date, open-source software stewards report as well.
Two examples: in mechanical engineering, the obligation applies to manufacturers of connected controllers, HMIs and edge gateways. Smart meter gateways are listed as critical products in Annex IV; the reporting obligation lies with their manufacturer, not with the municipal utility that deploys them. Whether a product counts as "important" under Annex III, such as routers or firewalls, makes no difference to the reporting obligation.
Whether your company falls under NIS2 is explained in the NIS2Compass article Am I affected by NIS2?; a CRA obligation does not automatically follow from it.
Is Your In-House Software a CRA Product?
The CRA ties its obligations to making available on the market in the course of a commercial activity (Art. 3(22)). By this wording, a purely internal application is not a market product. Software for group companies, customer portals or customer apps remain borderline cases to assess individually.
How Does the Cyber Resilience Act Differ from NIS2?
NIS2 governs how securely an organization runs its IT and services. The Cyber Resilience Act governs the security of the products a company makes and sells. As an EU regulation, the CRA applies directly, without a national implementation act; NIS2, as a directive, only became binding through the NIS2UmsuCG in the BSIG.
- Legal form: NIS2: Directive (EU) 2022/2555, transposed into the BSIG since 6 December 2025. CRA: Regulation (EU) 2024/2847.
- Obligated parties: NIS2: essential and important entities. CRA: manufacturers; importers and distributors only from 11 December 2027.
- Requirements: NIS2: risk management of your own IT (§ 30 BSIG). CRA: product security across the lifecycle, such as security by design and a software bill of materials (SBOM), for new products from 11 December 2027 (Art. 13).
- Reporting: NIS2: the entity's incidents to the BSI portal. CRA: product vulnerabilities and incidents to the ENISA platform.
- Supervision: the BSI in both cases; for the CRA, according to the BSI, the federal government has notified it to the European Commission as market surveillance authority; the German implementing act is still pending.
BSI President Claudia Plattner in the press release of 7 October 2025: „Der CRA ist ein Gamechanger für die Sicherheit digitaler Produkte!“ (our translation: "The CRA is a game changer for the security of digital products!")
According to the European Commission, the CRA complements the NIS2 Directive. As with the KRITIS Umbrella Act, another regime sits alongside it. A mechanical engineering company with 50 or more employees, or with annual turnover and balance sheet total above EUR 10 million, is an important entity (§ 28 Abs. 2 Nr. 3 BSIG). If it also places connected controllers on the market under its own name, both regimes apply.
What Does the CRA Change for IT Managers Who Only Buy and Operate Products?
If you only buy and operate connected products, you have no CRA reporting obligation of your own. Since 11 September 2026, however, manufacturers must inform you about actively exploited vulnerabilities and possible countermeasures (Art. 14(8) CRA). These notices belong in your NIS2 risk management under § 30 BSIG.
In B2B purchasing, the cybersecurity of connected products used to be mainly a contractual matter, such as how long and how extensively security updates were provided. With the CRA, a horizontal EU framework applies to all products with digital elements for the first time: the information obligation under Art. 14(8) also covers older products (Art. 69(3)).
For products placed on the market from 11 December 2027, CE marking includes cybersecurity. The support period for security updates is then generally at least five years, unless the product's expected use time is shorter (Art. 13(8)).
For operators, the CRA thus lands in § 30 Abs. 2 BSIG: supply chain security (no. 4) and vulnerability management (no. 5).
- Define who receives notices: Decide who receives and assesses manufacturer notices on vulnerabilities.
- Extend your procurement: For new purchases, ask about CRA conformity and the committed support period.
For many IT managers, CRA exposure ends at this point. The Implementation Guide from NIS2Compass covers supply chain security under § 30 Abs. 2 Nr. 4 BSIG as a NIS2 obligation in Chapter 6, "Supply Chain Security".
How Does CRA Reporting Work, and Is the ENISA Reporting Platform Live?
Manufacturers report via ENISA's Single Reporting Platform (SRP), which has been in operation since 11 September 2026. The early warning notification is due within 24 hours, the more detailed notification within 72 hours. The final report follows 14 days after a corrective measure is available (vulnerability) or one month after the notification (incident).
The deadlines depend on what you report:
- Actively exploited vulnerability: early warning notification within 24 hours, notification within 72 hours, final report no later than 14 days after a corrective or mitigating measure is available (Art. 14(2) CRA).
- Severe incident having an impact on the security of the product: likewise 24 and 72 hours, final report within one month of the 72-hour notification (Art. 14(4) CRA).
The timing resembles the NIS2 reporting obligation under § 32 BSIG, with its early initial notification, notification and final report. The trigger, platform and language, however, differ.
Every CRA notification goes simultaneously to ENISA and to the coordinating CSIRT, which in Germany is CERT-Bund at the BSI.
ENISA's Single Reporting Platform runs at portal.cra-srp.enisa.europa.eu. Reports are submitted in English, and access is via EU Login with multi-factor authentication. According to the BSI, you do not need to register in advance.
If the platform is down, the BSI says the mandatory notification exceptionally goes to CERT-Bund by email; you then resubmit it via the platform once it is back up.
Does a Machinery Manufacturer Have to Report the Same Incident Under Both NIS2 and the CRA?
Yes, that can happen. The BSI states on its page about the CRA reporting platform: „In diesem Fall ist der Vorfall sowohl nach NIS-2 (via BSI-Portal), als auch nach dem CRA (via CRA-SRP) zu melden.“ (our translation: "In this case, the incident must be reported both under NIS-2 (via the BSI portal) and under the CRA (via the CRA SRP).") So far, only the Commission's "Digital Omnibus" proposal would let a CRA notification count toward the NIS2 obligation, and it has not been adopted.
Take a fictitious machinery manufacturer with around 180 employees as an example. It is an important entity under § 28 BSIG, makes connected controllers and sells them under its own brand, which also makes it a manufacturer under the CRA (Art. 3(13)).
Now a vulnerability in the firmware of this controller is being actively exploited.
As the manufacturer, the company reports the vulnerability via the ENISA platform to CERT-Bund and ENISA (Art. 14(1) CRA) and informs affected customers (Art. 14(8)). As an entity, it also checks whether the vulnerability has caused a significant security incident in its own production. Only then does it also report via the BSI portal under § 32 BSIG.
A municipal utility that operates the controller as a customer does not report under the CRA. It assesses the manufacturer's information under § 30 and § 32 BSIG for its own operations.
In the dual case, this means: two legal bases, two platforms, two languages, one team.
The BSI recommends cross-referencing the two notifications. Whether the duplication will remain is open: the European Commission's Digital Omnibus proposal of 19 November 2025 is still before the European Parliament. Until it is adopted, both reporting obligations apply side by side.
Can CRA Fines Already Be Imposed Since 11 September?
No, the CRA's penalty provision (Art. 64) only applies with full application from 11 December 2027. The German draft implementing act likewise only brings its penalty rules into force then. The reporting obligation itself has applied since 11 September 2026; for reporting violations, fines of up to EUR 15 million or 2.5% of worldwide annual turnover will be possible later (Art. 64(2) CRA, according to the BSI).
The German draft bill (BT-Drs. 21/6134) is with the Committee on Internal Affairs after its first reading and has not been passed.
For comparison: NIS2 reporting violations can lead to fines of up to EUR 10 million for essential entities and EUR 7 million for important entities (§ 65 BSIG). Art. 64(10) provides an exemption from fines for microenterprises and small enterprises regarding the 24-hour deadline; how far it reaches has not been conclusively settled based on the wording. The obligation itself remains.
First clarify whether your company places its own products on the market at all. If not, your task lies with NIS2: check the status of your NIS2 implementation with the Pre-Check from NIS2Compass.
Frequently Asked Questions
As a NIS2 entity, am I automatically covered by the Cyber Resilience Act?
No. NIS2 applies to your organization, the CRA to products you place on the market. You only have a CRA reporting obligation as a manufacturer, that is, if you develop connected products, or have them developed, and market them under your own name. As a mere operator, you are affected indirectly, through procurement and manufacturer notices.
Do I have to report to ENISA myself as a distributor or importer?
No. Under Art. 14 CRA, only manufacturers have had to report since 11 September 2026. Separate obligations for importers and distributors only apply from 11 December 2027. Goods you market under your own name or brand are a borderline case: you may then already count as a manufacturer under Art. 3(13) today.
Is the ENISA Single Reporting Platform already up and running?
Yes, since 11 September 2026. Reports are submitted in English via an EU Login account. According to the BSI, you do not need to register in advance. If the platform is down, the mandatory notification exceptionally goes to CERT-Bund by email and is resubmitted via the platform later.
Does a CRA notification also count as a NIS2 notification under § 32 BSIG?
Not as things currently stand. The BSI treats the two reporting channels as separate processes, so an incident may have to be reported twice. So far, only the Commission's "Digital Omnibus" proposal would allow one to count toward the other. Until it is adopted, § 32 BSIG and Art. 14 CRA apply side by side.
Does the CRA reporting obligation also cover products I sold years ago?
Yes. Under Art. 69(3) CRA, the reporting obligation under Art. 14 applies to all products within scope, even if they were placed on the market before 11 December 2027. An inventory of your connected products with versions and support status is therefore the sensible first step.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedRelated Articles
§65 BSIG: What Fine Tiers Apply to NIS2 Violations?
§65 BSIG tiers NIS2 fines into seven brackets, from EUR 100,000 to EUR 10 million or 2% of turnover. NIS2Compass explains the assessment criteria and real GDPR comparison cases.
12 min read
AI Agents in GRC Tools: Which Vendor Leads in 2026?
No clear leader has emerged among AI agents in GRC tools in 2026. NIS2Compass compares KaitoSec, Kertos, Athereon, Drata, and Vanta on features, NIS2 coverage, and price.
15 min read
Ransomware Attack on a Hospital: Which NIS2 Duties Apply?
A ransomware attack on Nipigon Hospital (Canada) knocked out lab and diagnostics. Which NIS2 duties (§§30, 32, 65 BSIG) apply to German hospitals.
5 min read