CRA and related legislation
The CRA does not replace every other cybersecurity, product-safety or liability rule. One business may have duties under several regimes—for example, as a product manufacturer under the CRA and as an essential or important entity under NIS2.
| Legislation | When to check it | Relationship with the CRA |
|---|---|---|
| NIS2 — Directive (EU) 2022/2555 | If the organisation is within NIS2’s scope or supports the supply chain of an in-scope entity. | NIS2 focuses on cybersecurity risk management and incident reporting by covered entities; the CRA focuses on product security and economic operators. Both may apply. CRA-conforming products can support, but do not replace, NIS2 supply-chain compliance. Check national scope and terminology under Slovak law. |
| DORA — Regulation (EU) 2022/2554 | If the organisation is a financial entity or provides ICT services to the financial sector. | DORA governs financial entities’ digital operational resilience and ICT third-party risk; the CRA governs products and their economic operators. DORA is not a blanket exclusion from the CRA, and “lex specialis” should not be used without defining the precise issue. |
| General Product Safety Regulation (EU) 2023/988 | If the product is a consumer product and health or safety risks are being assessed. | CRA Article 11 preserves specified parts of Regulation 2023/988 for aspects and risk categories not covered by the CRA, where no other Union harmonisation legislation lays down specific safety requirements. It is therefore inaccurate to say that the CRA automatically “takes precedence” in every cybersecurity-related question. |
| Artificial Intelligence Act — Regulation (EU) 2024/1689 | If the product includes an AI system, particularly a high-risk AI system. | CRA Article 12 coordinates cybersecurity requirements and conformity assessment for products that are also high-risk AI systems. Compliance with one act does not automatically satisfy every requirement of the other. |
| Product Liability Directive (EU) 2024/2853 | When assessing compensation for damage caused by a defective product, including software or missing security updates. | The CRA chiefly sets ex-ante product, conformity, support and surveillance requirements. The Directive provides an ex-post no-fault liability regime and requires national transposition. They are distinct and may apply alongside each other. |
Product-specific legislation may also matter, including Machinery Regulation (EU) 2023/1230, rules on radio equipment, medical devices, vehicles, civil aviation or marine equipment. Assess CRA scope and exclusions under CRA Article 2 and later delegated acts; Delegated Regulation (EU) 2025/1535 introduced a specific exclusion for certain products covered by Regulation (EU) No 168/2013.
Important: This orientation is not a legal opinion. For a combined product or regulated sector, assess the product’s specific functionality, how it is made available on the market and every applicable act.