Definition
NIS2 Directive
Directive (EU) 2022/2555 on cybersecurity of essential and important entities — regulates organisations, whereas the CRA regulates products.
The Network and Information Security Directive (EU) 2022/2555 sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in listed sectors. It regulates organisations and their operations; the CRA regulates products placed on the market. Many manufacturers are subject to both: NIS2 incident reporting concerns their own services and systems, CRA Article 14 concerns their products. The CRA reuses NIS2's CSIRT network and its definition of incident.
Reference: Directive (EU) 2022/2555 · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.