The EU Cyber Resilience Act Compared

One regulation, many neighbors: how the EU CRA relates to other EU legislation and to established security standards — and what applies to your products on top of what you already do.

How does the EU CRA differ from other regulations?

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is product legislation: it defines binding cybersecurity requirements that products with digital elements must meet before they are placed on the EU market. Most frameworks it is compared with regulate something else — NIS-2, ISO 27001 and DORA address how organizations manage security, while IEC 62443 and ETSI EN 303 645 are voluntary standards and RED, the Machinery Regulation and CE marking are sector or conformity frameworks the EU CRA plugs into. None of them replaces EU CRA conformity — the comparisons below show exactly where the lines run.

Source: Regulation (EU) 2024/2847 — full legal text in our knowledge base

Which requirements apply to you on top?

Our free maturity assessment maps your existing certifications and processes against the EU CRA — and shows the concrete gap in about 15 minutes.