Interplay with other legislation

The CRA does not stand alone. This page serves two purposes: avoiding duplicated work by pooling evidence, and avoiding blind spots between two regimes.

Interplay table

Text What it governs Relationship to the CRA
Directive (EU) 2022/2555 (NIS 2) Entities: risk governance, supply chain security, incident notification Complementary. The CRA governs products, NIS 2 governs organisations. One group can fall under both. Convergence point: the European vulnerability database (EUVD), created under NIS 2, is fed by CRA reports.
Regulation (EU) 2019/881 (Cybersecurity Act) European cybersecurity certification schemes, including EUCC An instrument the CRA relies on: a certificate at assurance level at least “substantial” counts as a conformity assessment route.
Regulation (EU) 2024/1689 (AI Act) AI systems, including high-risk ones Explicit articulation: for a high-risk AI system that is also a PDE, compliance with the CRA essential requirements gives a presumption of conformity with the cybersecurity requirements of AI Act Article 15, to the extent they are covered.
Directive 2014/53/EU (RED) and Delegated Regulation (EU) 2022/30 Cybersecurity of radio equipment, standards EN 18031-1/-2/-3 An interim regime, to be superseded by the CRA for products covered by both. Work done on EN 18031 remains reusable as evidence.
Regulation (EU) 2023/1230 (Machinery) Machinery safety, including protection against corruption of safety software Partial overlap on safety functions; the two markings coexist.
Regulation (EU) 2023/988 (GPSR) General consumer product safety Residual safety net, applicable where no sectoral legislation exists.
Regulation (EU) 2022/2554 (DORA) Digital operational resilience of the financial sector and its critical ICT providers If you supply financial entities, their contractual requirements often anticipate the CRA’s.
Regulation (EU) 2016/679 (GDPR) Personal data protection Overlap on security by design (Art. 25) and security of processing (Art. 32). The notifications do not merge: see below.
Directive (EU) 2024/2853 Product liability Now explicitly covers software, and takes the absence of security updates into account when assessing defectiveness. A CRA breach becomes evidence in a civil claim.
Regulation (EU) 2019/1020 Market surveillance Amended by the CRA; grounds the powers of national authorities.

The concurrent notification trap

A single event — a compromise exploiting a flaw in your product, with customer data leaking — can trigger three separate notifications, to three recipients, within three deadlines, with three different contents.

CRA (Art. 14) NIS 2 GDPR (Art. 33)
Subject Actively exploited vulnerability in your product, or severe incident affecting its security Significant incident affecting the provision of your services Personal data breach
Who notifies The product manufacturer The essential or important entity The controller
Recipient Coordinating CSIRT + ENISA, via the single reporting platform National CSIRT or competent authority Data protection authority
Early warning 24 h 24 h
Notification 72 h 72 h 72 h
Final report 14 days after a corrective measure is available (vulnerability) or 1 month (incident) 1 month
Informing individuals / users Affected users, without undue delay Recipients of services, where applicable Data subjects, where high risk

Organisational consequence. A single crisis cell must rule on all three regimes at once, with three distinct templates ready to use. Handling the regimes in sequence mechanically misses the shortest deadline.

Pooling evidence

Many artefacts serve several texts at once. Produce them once, file them once:

Artefact CRA NIS 2 GDPR Customers
SBOM Annexes I and VII Supply chain Tenders
Cybersecurity risk assessment Art. 13, Annex VII Risk management Art. 32 Questionnaires
Coordinated disclosure policy Annex I, Part II Expected good practice Market expectation
Vulnerability handling log Annex I, Part II Incident management Breach register Audits
Notification procedure Art. 14 Incident notification Art. 33
Encryption and access control Annex I, Part I Technical measures Art. 32 Certifications

That “one piece of evidence, several texts” column is what makes the programme fundable: the CRA does not add a silo, it structures evidence that was already partly owed.