Two pieces of EU law are quietly changing what "taking security seriously" means in practice. NIS2 raises the bar for organisations that run important services. The Cyber Resilience Act (CRA) does the same for anyone who makes or sells software and connected products. If you run a business or write code for a living, at least one of them probably touches you. Here is the plain-language version, without the hype.
Two laws, two jobs
They are easy to confuse, so start with the split. NIS2 is about how you operate. It obliges certain organisations to manage cyber risk, report serious incidents, and hold their leadership accountable. The CRA is about what you ship. It obliges makers of "products with digital elements" — essentially anything with software in it — to build security in and to keep supporting it after the sale. Some companies fall under both: a firm that runs critical services and sells software will need to satisfy each set of rules on its own terms.
Am I in scope?
For NIS2, scope depends on your sector and your size. It covers a broad list of sectors — energy, transport, water, health, digital infrastructure, cloud and managed IT providers, manufacturing, food, postal services and more — and sorts entities into essential and important. As a rough guide, medium-sized organisations and larger are caught (broadly, more than 50 staff or over €10 million turnover), with some digital and trust-service providers in scope regardless of size. Even if the law does not name you directly, your larger clients may pass these expectations down the supply chain through their contracts.
For the CRA, scope follows the product. If you place a product with digital elements on the EU market — commercial software, firmware, a connected device — it generally applies. There are carve-outs (for example, products already covered by sector-specific rules such as medical devices), and free and open-source software developed outside a commercial activity is treated more lightly. If you sell it, though, assume you are in.
The timelines that matter
NIS2 was due to be written into national law across the EU by 17 October 2024. As of mid-2026 most Member States have done so, but a handful are still finalising their statutes, and the Commission has opened infringement proceedings against the laggards. The practical takeaway: check the transposed law in each country where you operate, because national details and registration deadlines vary.
The CRA entered into force on 10 December 2024 and phases in. The vulnerability and incident reporting duties start on 11 September 2026, and the full set of obligations applies from 11 December 2027. That second date sounds distant, but security-by-design is not something you retrofit the week before — it shapes how you build now.
What you actually have to do
Under NIS2, the core duties are refreshingly concrete:
- Manage risk with real measures: access control, encryption, backups, business continuity, supply-chain security and staff training.
- Report significant incidents on a tight clock — an early warning within 24 hours and a fuller report within 72 hours.
- Make management accountable. Boards and senior leaders are expected to approve and oversee cyber-risk measures, and can be held personally responsible for failures.
Under the CRA, the obligations fall into two halves, drawn from its essential requirements:
- Security by design. Ship products with no known exploitable vulnerabilities, secure default settings, and the ability to receive timely security updates.
- Vulnerability handling over the support period. Keep an inventory of components — a software bill of materials (SBOM) in a machine-readable format — provide free security updates for a defined support period, and run a process for receiving and acting on vulnerability reports.
- Report fast. Actively exploited vulnerabilities and severe incidents trigger an early warning within 24 hours, filed through the EU's single reporting platform to the relevant CSIRT and ENISA, followed by fuller reports as the situation resolves.
Teeth
These are not advisory guidelines. NIS2 gives regulators audit and inspection powers and administrative fines — up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% for important ones, whichever is higher. The CRA carries its own significant penalties for non-compliant products. The point is not to frighten anyone; it is that the cost of ignoring this now exceeds the cost of getting ahead of it.
Where to start
You do not need a consultant and a binder to begin. Write down what you run and what you ship. For NIS2, do an honest risk assessment and confirm you can detect and report an incident within a day. For the CRA, start producing an SBOM, decide how long you will support each product, and set up a way for people to report vulnerabilities to you. Most of this is good engineering hygiene that pays off regardless of the regulation. Treat these laws less as paperwork and more as the industry finally writing down what careful builders were already doing — and give yourself the runway to meet the 2026 and 2027 dates calmly.