The EU Cyber Resilience Act Compared
One regulation, many neighbors: how the EU CRA relates to other EU legislation and to established security standards — and what applies to your products on top of what you already do.
How does the EU CRA differ from other regulations?
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is product legislation: it defines binding cybersecurity requirements that products with digital elements must meet before they are placed on the EU market. Most frameworks it is compared with regulate something else — NIS-2, ISO 27001 and DORA address how organizations manage security, while IEC 62443 and ETSI EN 303 645 are voluntary standards and RED, the Machinery Regulation and CE marking are sector or conformity frameworks the EU CRA plugs into. None of them replaces EU CRA conformity — the comparisons below show exactly where the lines run.
Source: Regulation (EU) 2024/2847 — full legal text in our knowledge base
EU CRA vs. EU Regulation
Binding EU law: who is addressed, which obligations overlap, and where both frameworks apply at the same time.
EU Directive for Operators
Cyber Resilience Act vs. NIS 2 Directive
Two pillars of the EU cybersecurity strategy compared side by side
Read the comparisonExisting Conformity System
Cyber Resilience Act and CE Marking
Cybersecurity becomes a mandatory prerequisite for EU market access
Read the comparisonExisting Radio Equipment Law
CRA vs. Radio Equipment Directive (RED)
How the Cyber Resilience Act replaces the cybersecurity requirements of the Radio Equipment Directive
Read the comparisonMachine Safety
CRA vs. Machinery Regulation
Cybersecurity and machine safety — two regulations, one product
Read the comparisonFinancial Supervisory Law
CRA vs. DORA
Product security meets digital financial resilience
Read the comparisonEU CRA vs. Standards & Norms
Voluntary standards: what existing certifications already cover — and which EU CRA obligations remain open.
Voluntary Management System Standard
Cyber Resilience Act vs. ISO 27001
Legal obligation and international standard working together
Read the comparisonVoluntary International Industry Standard
CRA vs. IEC 62443
Mandatory EU law meets established industrial standard for industrial cybersecurity
Read the comparisonEuropean Technical Standard
CRA vs. ETSI EN 303 645
From voluntary IoT standard to binding EU law
Read the comparisonWhich requirements apply to you on top?
Our free maturity assessment maps your existing certifications and processes against the EU CRA — and shows the concrete gap in about 15 minutes.