Four EU regulatory frameworks, four distinct objectives - and yet they keep landing on the same compliance agenda. That's no coincidence: for manufacturers of connected products, SaaS providers, and mid-market companies operating in regulated sectors, all four can apply simultaneously. Confusing or conflating them creates gaps in your compliance program - and the stakes are high, with fines ranging from tens of millions of euros to one percent of global annual revenue.

This article cuts through the complexity: what does each regulation cover, who does it affect, and where do the obligations intersect?


The Four Frameworks at a Glance

Cyber Resilience Act (CRA) - Product Safety and Cybersecurity

The CRA, officially Regulation (EU) 2024/2847, is the newest of the four frameworks. It entered into force on December 10, 2024. Its regulatory scope is clearly defined: for the first time, it establishes binding cybersecurity requirements for products with digital elements - meaning hardware and software placed on the EU market. [1]

Manufacturers, importers, and distributors are all in scope. The reach is broader than many expect: [2] makes clear that beyond traditional IT and IoT manufacturers, the regulation also covers machine builders with networked control systems, vendors of desktop software with update functionality, and sensor manufacturers with remote maintenance access. Pure cloud SaaS services are explicitly excluded.

Obligations phase in on a staggered timeline:

  • From September 11, 2026: Reporting obligations for actively exploited vulnerabilities and serious incidents - a 24-hour early warning, a 72-hour notification, and a final report within 14 days - submitted via a central platform to the relevant CSIRT and ENISA. [3]
  • From December 11, 2027: Full core obligations: secure-by-design, vulnerability management across the entire product lifecycle, a Software Bill of Materials (SBOM - a complete inventory of all software components used), conformity assessment, and CE marking. [4]

Violations can result in fines of up to €15 million or 2.5% of global annual revenue, whichever is higher. [3]

For our in-depth pillar post on the CRA, see: Cyber Resilience Act - the comprehensive overview.


EU Data Act - Data Access, Data Sharing, and Contract Law

The Data Act, Regulation (EU) 2023/2854, pursues a fundamentally different goal: it does not address cybersecurity, but rather governs access to and sharing of data generated through the use of connected products and related services. The regulation has been in force since January 11, 2024, and has been applicable since September 12, 2025.

Its core obligations include pre-contractual transparency toward users, data access and portability on user request, fair B2B contract terms under the FRAND principle (fair, reasonable, and non-discriminatory), rules on cloud switching, and protection against unlawful third-country access. For connected products newly placed on the market, additional design obligations (data-access-by-design) will apply from September 12, 2026.

One important point: the Data Act also applies to providers outside the EU if they serve the EU market. Those in scope include manufacturers of connected products, providers of related services, and cloud providers.

For the full pillar post on the EU Data Act, see: EU Data Act - the comprehensive overview for decision-makers and compliance professionals.


NIS2 - Cybersecurity for Operators and Essential Entities

NIS2 (Directive (EU) 2022/2555) is not a product regulation - it is an operator directive. It targets organizations active in specific sectors and requires them to implement risk management measures, meet reporting obligations, and register with the relevant authority. In Germany, it was transposed into national law through the NIS2UmsuCG. The law was passed by the Bundestag on November 13, 2025, and entered into force on December 6, 2025 - with no transition period. [5]

According to estimates by Germany's Federal Office for Information Security (BSI), approximately 29,500 to 30,000 companies across 18 sectors fall under NIS2 in Germany. [5] Affected entities are divided into two categories: "essential entities" (generally those with 250 or more employees or annual revenue above €50 million) and "important entities" (generally 50-249 employees or revenue between €10 million and €50 million). [6]

The three central obligations are: registration with the BSI, implementation of risk management measures (both technical and organizational, in line with the state of the art), and reporting of significant security incidents - again with a 24-hour early warning and a 72-hour report. [7] Particularly relevant for mid-market companies: NIS2 also has indirect reach. Suppliers and service providers to in-scope entities must maintain appropriate security standards, because supply chain security is explicitly part of the requirements. [8]

For essential entities, violations can result in fines of up to €10 million or 2% of global annual revenue. [6] Management bears personal liability. [9]


GDPR - Protection of Personal Data

The GDPR is the oldest and best-known of the four frameworks. Its subject matter is unambiguous: the protection of natural persons in connection with the processing of personal data. It applies to any controller or processor that handles personal data of EU residents - regardless of industry, company size, or place of establishment. For serious violations, the GDPR provides for fines of up to €20 million or 4% of global annual revenue, whichever is higher. [10]

Vectocon supports small and mid-sized businesses comprehensively in the area of data protection - learn more on our [11].


Comparison Table: Who Falls Under What?

CRA, Data Act, NIS2, and GDPR Compared
KriteriumCRAData ActNIS2DSGVO
RegelungszielProduktsicherheit / CybersicherheitDatenzugang & VertragsrechtCybersicherheit von BetreibernSchutz personenbezogener Daten
RechtsformEU-Verordnung (unmittelbar)EU-Verordnung (unmittelbar)EU-Richtlinie (national umgesetzt)EU-Verordnung (unmittelbar)
Primäre AdressatenHersteller, Importeure, Händler von Produkten mit digitalen ElementenHersteller vernetzter Produkte, Anbieter verbundener Dienste, Cloud-AnbieterBetreiber in 18 kritischen Sektoren (ab Mittelgröße)Alle Verantwortlichen / Auftragsverarbeiter mit Personendaten
SaaS / CloudReine Cloud-SaaS ausgenommenCloud-Anbieter direkt betroffenDigitale Dienste als eigener SektorImmer betroffen (Nutzerdaten)
IoT / HardwareKernbereich der VerordnungVernetzte Produkte im FokusIndirekt (Lieferkette)Nur wenn Personendaten verarbeitet
Meldepflichten24h / 72h / 14 Tage (ab Sept. 2026)Keine Vorfallsmeldung24h / 72h / 1 Monat (sofort)72h bei Datenpannen
Max. Bußgeld15 Mio. EUR / 2,5 % UmsatzNational geregelt10 Mio. EUR / 2 % Umsatz20 Mio. EUR / 4 % Umsatz
GeschäftsführerhaftungJa (Konformitätspflicht)VertragsrechtlichJa, persönlich (§ 38 BSIG)Ja, mittelbar

Where the Obligations Overlap

The four frameworks are not alternatives to one another - they can apply cumulatively. Here are three typical overlap scenarios for mid-market companies:

IoT manufacturers with consumer or industrial products: A company that manufactures and distributes networked industrial sensors is simultaneously subject to the CRA (product security), the Data Act (user data access), and the GDPR (if the sensors collect personal data). If the company is large enough and operates in one of the 18 NIS2 sectors, NIS2 applies on top of that.

SaaS providers in regulated sectors: A cloud service for the healthcare sector is subject to the GDPR (patient data), the Data Act (data access and switching), and - as a provider of digital services - potentially NIS2 as well. The CRA only applies if the service includes a locally installed software component.

Machine builders with networked equipment: A company supplying machines with an Ethernet interface or remote maintenance access qualifies as a CRA manufacturer. If the machines generate usage data, the Data Act applies. If they process personal data (such as operator profiles), the GDPR kicks in. And as a supplier to a NIS2-obligated operator, the company must also meet that operator's supply chain security requirements.

star Important

Overlap ≠ duplicate work. The CRA and NIS2 both cover cybersecurity, but address different levels: the CRA governs the product, NIS2 governs the operator. Both can apply simultaneously — and each has its own reporting obligations with similar but not identical deadlines. A careful case-by-case assessment is essential.


Self-Assessment: Which Frameworks Apply to Your Business?

The interactive tool below provides an initial orientation. It is not a substitute for legal advice, but it offers a structured starting point for assessing your regulatory exposure.


What This Means for Decision-Makers and Compliance Professionals

The regulatory reality for many mid-market companies is this: not one, but two to four of these frameworks are likely to apply at the same time. That has concrete implications for how businesses are run.

First, reporting processes need to be coordinated. The CRA, NIS2, and the GDPR all impose incident reporting obligations - with similar but not identical deadlines and different reporting channels. Companies that are not prepared risk missing multiple deadlines under multiple frameworks simultaneously.

Second, management liability is a serious issue. NIS2 explicitly enshrines the personal liability of governing bodies in law. Under the CRA, the manufacturer bears responsibility for conformity. And the GDPR carries indirect liability risks for controllers. Any CEO or CFO who does not have a clear picture of their company's regulatory exposure is acting negligently.

Third, an integrated approach pays off. Many measures - such as structured vulnerability management, clear contractual clauses on data access, and supply chain security - address multiple frameworks at once. That reduces effort and creates legal certainty.

We'll work with you to identify which of the four frameworks specifically apply to your organization — and what that means for your compliance agenda. Get in touch.

Map Your Regulatory Footprint Now

This article is for general informational purposes only and does not constitute individual legal advice. Whether the frameworks discussed apply to your business depends on the specific circumstances of your situation.

auto_awesome This article was created with the help of AI.