# NIS2, DORA and the CRA compared: object, legal nature and scope

> Three European cybersecurity acts, three different levels: the CRA regulates products, NIS2 organisations, DORA the financial sector. What each text says about object, legal form, dates of application and addressees, and how they fit together. A guide from the official sources, with references to the articles.

- URL: https://albertoscarpa.com/guide/en/nis2-dora-cra-compared/
- Lingua / Language: English
- Published: 2026-08-19
- Updated: 2026-08-19
- Tags: CRA, NIS2

---

The CRA, NIS2 and DORA are often cited together as "the European cyber package", and that is where the confusion starts: they look like three versions of the same rule. They are not. They act on different objects, have a different legal form and address different recipients. A manufacturer may fall under two of them, or all three, but for distinct reasons. This guide gathers what the official sources say about each and about how they fit together, with precise references to the articles.

*This guide reports the binding text of the three acts (regulations, directive and annexes) and, where flagged, the non-binding official guidance, with precise references. Operational readings, how this framework translates into decisions for a manufacturer, are in the linked blog articles at the end.*

If the CRA is not yet in focus, the starting point is [The CRA in one hour](/guide/en/cra-in-one-hour/).

## Three acts, three objects

The most useful distinction is not between the three names, but between the three things they regulate.

The **CRA** (Cyber Resilience Act, Regulation (EU) 2024/2847) regulates the **product**. It applies to products with digital elements placed on the Union market and imposes security requirements on the product itself and on the process that maintains it (Art. 1 and Annex I). It is independent of the sector in which the manufacturer operates.

**NIS2** (Directive (EU) 2022/2555) regulates the **organisation**. It concerns the security of the network and information systems of the entities within its scope, with governance obligations, risk management (Art. 21) and incident notification (Art. 23) borne by the entity, not by the product.

**DORA** (Digital Operational Resilience Act, Regulation (EU) 2022/2554) regulates the **digital operational resilience of the financial sector**. It applies to financial entities (banks, insurance undertakings, investment firms, and others listed in Art. 2) and to their ICT third-party service providers.

## Legal nature and dates of application

The legal form changes how and when each act takes effect.

The CRA and DORA are **regulations**: they apply directly in all Member States, without the need for a national transposition law. NIS2 is a **directive**: it sets common objectives but requires a national law to transpose it.

- **NIS2**: transposition deadline for Member States set at 17 October 2024 (Art. 41). In Italy transposition took place with Legislative Decree No 138 of 4 September 2024.
- **DORA**: applies from 17 January 2025 (Art. 64).
- **CRA**: in force since 10 December 2024, with staggered application. The obligations to report actively exploited vulnerabilities and severe incidents (Art. 14) apply from 11 September 2026; the essential requirements of Annex I and the other manufacturer obligations from 11 December 2027.

## Who is subject to each

**CRA.** The main addressees are the manufacturers of products with digital elements (Art. 3, point 1), with their own obligations also for importers and distributors. The criterion is the product: if you place on the EU market a product that falls within the definition, you are subject, regardless of your sector and your size.

**NIS2.** The addressees are the "essential entities" and "important entities" defined in Art. 3, identified on the basis of two combined criteria: belonging to one of the sectors of Annexes I and II, and exceeding the size thresholds. Among the sectors of Annex II is manufacturing, which includes, among others, the manufacture of medical devices, of computer, electronic and optical products, of electrical equipment, of machinery and equipment n.e.c. The reference size threshold is that of the medium-sized enterprise (from 50 employees, or more than EUR 10 million in turnover or balance-sheet total, under Recommendation 2003/361/EC). A manufacturer in these sectors that exceeds the threshold generally falls among the important entities.

**DORA.** The addressees are the financial entities listed in Art. 2 and the ICT third-party service providers (defined in Art. 3, point 19). For the latter, the obligations pass through contract via the financial customer (Chapter V, in particular Arts. 28 and 30). A subset of providers can be designated a "critical ICT third-party service provider" and placed under direct oversight at Union level (Art. 31 et seq.).

## How they fit together

The three acts do not overlap on the same object, but they have precise points of contact.

**NIS2 and DORA: a relationship of speciality.** Art. 4 of NIS2 governs the relationship with sector-specific Union acts. Where a sector-specific act imposes on essential or important entities risk-management measures at least equivalent, in substance, to those of Art. 21, or notification obligations at least equivalent to those of Art. 23, the sector-specific provisions apply in place of the corresponding NIS2 ones. The Commission guidelines on the application of Art. 4(1) and (2) (a non-binding document) identify DORA among the sector-specific acts that meet this condition for financial entities. In practice, for the aspects covered, a financial entity applies DORA instead of NIS2.

**CRA and NIS2: a relationship of complementarity.** The two acts act on different levels of the same chain: NIS2 on the entities, the CRA on the products those entities manufacture or use. A product's compliance with the CRA contributes to satisfying the supply-chain security obligations laid down for entities by Art. 21 of NIS2. The two do not exclude and do not replace one another.

**Incident notification.** All three provide for reporting obligations, each with its own object and recipients: the CRA on exploited vulnerabilities and severe incidents affecting the product (Art. 14), NIS2 on significant incidents affecting the delivery of the entity's services (Art. 23), DORA on major ICT-related incidents in the financial sector (Art. 19). The deadlines of the CRA channel and the workings of the single platform are covered in the [guide to the Single Reporting Platform](/guide/en/single-reporting-platform-guide/).

## Summary table

| | CRA | NIS2 | DORA |
| :--- | :--- | :--- | :--- |
| Object | The product with digital elements | The security of the entity's systems | The operational resilience of the financial sector |
| Legal form | Regulation (EU) 2024/2847 | Directive (EU) 2022/2555 | Regulation (EU) 2022/2554 |
| Application | 11 Sep 2026 (reporting), 11 Dec 2027 (essential requirements) | Transposition by 17 Oct 2024 (in Italy Legislative Decree 138/2024) | 17 Jan 2025 |
| Addressees | Manufacturers of PDEs (Art. 3, point 1) | Essential and important entities (Art. 3, Annexes I and II) | Financial entities (Art. 2) and ICT third-party providers (Art. 3, point 19) |
| Notification | Art. 14, to the CSIRT and ENISA | Art. 23, to the national CSIRT | Art. 19, to the financial supervisory authorities |

## Going deeper

How this framework translates into concrete obligations for those who manufacture devices, that is, when a manufacturer subject to the CRA is also a NIS2 entity as a company, is covered in the blog article [You are a manufacturer subject to the CRA. Does NIS2 concern you as a company too?](/blog/en/manufacturer-cra-nis2/).

---

*References: Regulation (EU) 2024/2847 (CRA), Articles 1, 3, 14 and Annex I; Directive (EU) 2022/2555 (NIS2), Articles 3, 4, 21, 23, 41 and Annexes I and II; Legislative Decree No 138 of 4 September 2024 (Italian transposition of NIS2); Regulation (EU) 2022/2554 (DORA), Articles 2, 3, 19, 28, 30, 31 and 64; Recommendation 2003/361/EC (definition of medium-sized enterprise). Non-binding guidance: Commission guidelines on the application of Art. 4(1) and (2) of the NIS2 directive. Article numbers verified against the official texts.*
