CRA and NIS2 — when does which apply?
Two reporting duties, two roles. Anyone meeting both reports twice.
The role decides, not the event
Article 14 CRA obliges you in your role as manufacturer of a product with digital elements: it concerns vulnerabilities and incidents affecting the security of that product — including when it has long been in use at customers.
The NIS2 reporting duty, by contrast, attaches to your role as operator of an entity falling within the scope of the directive or its national transposition. It asks about significant incidents in your own operations.
Both can apply at once. A break-in to your build environment that leads to tampered releases is an operational incident and a product incident at the same time.
Similar deadlines, different addressees
Both regimes work with an early warning within 24 hours and a fuller notification within 72 hours. The similarity invites treating one report as covering both — but the addressees, the mandatory content and the final deadlines differ.
In practice: run separate cases, even where the description of facts overlaps. The reporting assistant covers the CRA path only and deliberately makes no automated statement on whether a NIS2 report is additionally due.
Deadline running? Work the case through step by step.
Open the reporting assistant