Interplay with other legislation
The CRA does not stand alone. This page serves two purposes: avoiding duplicated work by pooling evidence, and avoiding blind spots between two regimes.
Interplay table
| Text | What it governs | Relationship to the CRA |
|---|---|---|
| Directive (EU) 2022/2555 (NIS 2) | Entities: risk governance, supply chain security, incident notification | Complementary. The CRA governs products, NIS 2 governs organisations. One group can fall under both. Convergence point: the European vulnerability database (EUVD), created under NIS 2, is fed by CRA reports. |
| Regulation (EU) 2019/881 (Cybersecurity Act) | European cybersecurity certification schemes, including EUCC | An instrument the CRA relies on: a certificate at assurance level at least “substantial” counts as a conformity assessment route. |
| Regulation (EU) 2024/1689 (AI Act) | AI systems, including high-risk ones | Explicit articulation: for a high-risk AI system that is also a PDE, compliance with the CRA essential requirements gives a presumption of conformity with the cybersecurity requirements of AI Act Article 15, to the extent they are covered. |
| Directive 2014/53/EU (RED) and Delegated Regulation (EU) 2022/30 | Cybersecurity of radio equipment, standards EN 18031-1/-2/-3 | An interim regime, to be superseded by the CRA for products covered by both. Work done on EN 18031 remains reusable as evidence. |
| Regulation (EU) 2023/1230 (Machinery) | Machinery safety, including protection against corruption of safety software | Partial overlap on safety functions; the two markings coexist. |
| Regulation (EU) 2023/988 (GPSR) | General consumer product safety | Residual safety net, applicable where no sectoral legislation exists. |
| Regulation (EU) 2022/2554 (DORA) | Digital operational resilience of the financial sector and its critical ICT providers | If you supply financial entities, their contractual requirements often anticipate the CRA’s. |
| Regulation (EU) 2016/679 (GDPR) | Personal data protection | Overlap on security by design (Art. 25) and security of processing (Art. 32). The notifications do not merge: see below. |
| Directive (EU) 2024/2853 | Product liability | Now explicitly covers software, and takes the absence of security updates into account when assessing defectiveness. A CRA breach becomes evidence in a civil claim. |
| Regulation (EU) 2019/1020 | Market surveillance | Amended by the CRA; grounds the powers of national authorities. |
The concurrent notification trap
A single event — a compromise exploiting a flaw in your product, with customer data leaking — can trigger three separate notifications, to three recipients, within three deadlines, with three different contents.
| CRA (Art. 14) | NIS 2 | GDPR (Art. 33) | |
|---|---|---|---|
| Subject | Actively exploited vulnerability in your product, or severe incident affecting its security | Significant incident affecting the provision of your services | Personal data breach |
| Who notifies | The product manufacturer | The essential or important entity | The controller |
| Recipient | Coordinating CSIRT + ENISA, via the single reporting platform | National CSIRT or competent authority | Data protection authority |
| Early warning | 24 h | 24 h | — |
| Notification | 72 h | 72 h | 72 h |
| Final report | 14 days after a corrective measure is available (vulnerability) or 1 month (incident) | 1 month | — |
| Informing individuals / users | Affected users, without undue delay | Recipients of services, where applicable | Data subjects, where high risk |
Organisational consequence. A single crisis cell must rule on all three regimes at once, with three distinct templates ready to use. Handling the regimes in sequence mechanically misses the shortest deadline.
Pooling evidence
Many artefacts serve several texts at once. Produce them once, file them once:
| Artefact | CRA | NIS 2 | GDPR | Customers |
|---|---|---|---|---|
| SBOM | Annexes I and VII | Supply chain | — | Tenders |
| Cybersecurity risk assessment | Art. 13, Annex VII | Risk management | Art. 32 | Questionnaires |
| Coordinated disclosure policy | Annex I, Part II | Expected good practice | — | Market expectation |
| Vulnerability handling log | Annex I, Part II | Incident management | Breach register | Audits |
| Notification procedure | Art. 14 | Incident notification | Art. 33 | — |
| Encryption and access control | Annex I, Part I | Technical measures | Art. 32 | Certifications |
That “one piece of evidence, several texts” column is what makes the programme fundable: the CRA does not add a silo, it structures evidence that was already partly owed.