All articles
ComplianceCybersecurity

Cybersecurity Laws and Their Control Baselines: NIS2, the CRA, and What to Adopt

Two EU cyber laws now sit on most organizations: one governs how you run security, the other how you build products. The relief is that both are answerable with a mainstream control baseline you may already run, plus a few targeted additions.

Ilke Tosunoğlu
Ilke TosunoğluJune 4, 20265 min readUpdated July 20, 2026
Two pillars, organizational security under NIS2 and product security under the CRA, resting on a shared ISO 27001 and NIST CSF 2.0 control baseline.

Part of the pillar series Sovereignty You Can Actually Operate.

This is practical guidance for compliance teams, not legal advice. Current as of July 2026.

Two laws, two objects

NIS2 governs organizational cybersecurity. The Cyber Resilience Act governs product cybersecurity. Knowing which one is talking to you is the first step.

NIS2how you RUN security · org risk mgmt, incident reporting, supply chain
CRAhow you BUILD products · secure-by-design, vuln handling, updates
Shared control baselineISO 27001 / NIST CSF 2.0
+ targeted add-onsIEC 62443 (OT) · CRA product controls

NIS2: Directive (EU) 2022/2555

Why it exists: NIS1 was narrow, fragmented, and weakly enforced. NIS2 widens scope to 18 sectors, harmonizes the criteria, tightens reporting, and adds two things that changed the game: supply-chain security and direct management accountability.

Who's in scope: essential entities (energy, transport, banking, health, water, digital infrastructure, public administration and more) and important entities (postal, waste, chemicals, food, manufacturing, digital providers, research), generally medium-sized and above (≥50 staff or ≥€10M turnover), with some entities in scope regardless of size.

What it requires:

  • Article 21 (ten minimum risk-management measures): risk analysis and security policies, incident handling, business continuity and backups, supply-chain security, security in acquisition/development/maintenance, effectiveness assessment, cyber hygiene and training, cryptography, HR security and access control, and MFA/secure communications.
  • Article 20 (accountability): management bodies must approve and oversee the measures, undergo training, and can be held personally liable, including, in some Member States, temporary management bans.
  • Article 23 (reporting): early warning 24 hours, notification 72 hours, final report 1 month.

Fines: essential entities €10M or 2% of global turnover; important entities €7M or 1.4%. And enforcement is live: on 8 July 2026 the Commission referred Ireland, Spain, France, and the Netherlands to the EU Court of Justice for failing to transpose NIS2 (Commission).

The Cyber Resilience Act: Regulation (EU) 2024/2847

Why it exists: products with digital elements shipped with known vulnerabilities, no updates, and no transparency. The CRA imposes horizontal, lifecycle security requirements on hardware and software placed on the EU market: secure-by-design, no known exploitable vulnerabilities at release, vulnerability handling with coordinated disclosure, free security updates over a support period, and conformity assessment with CE marking.

Dates: in force 10 December 2024; reporting obligations from 11 September 2026 (actively exploited vulnerabilities and severe incidents, on a 24h/72h/14-day cadence); main obligations from 11 December 2027. Fines up to €15M or 2.5% of global turnover (EUR-Lex).

(A third instrument, the Cyber Solidarity Act (2025/38, in force February 2025), builds EU-wide detection and emergency response, context rather than a control obligation.)

The frameworks to adopt, and the official mapping

Here is the practical relief. In June 2025, ENISA published Technical Implementation Guidance that maps each NIS2 Article 21 measure directly to ISO/IEC 27001:2022 and NIST CSF 2.0, an official signal that you can reuse an existing security program as NIS2 evidence.

Framework What it is Why for NIS2 / CRA
ISO/IEC 27001:2022 Certifiable ISMS (93 Annex A controls) The certifiable baseline that maps directly to NIS2 Art. 21; primary compliance evidence
NIST CSF 2.0 Voluntary; adds a Govern function Govern mirrors NIS2 Art. 20 accountability; one of ENISA's mapped standards; board-friendly
CIS Controls v8.1 18 prioritized controls, IG1–IG3 Concrete safeguards; IG1 is a proportionate SME baseline
ISA/IEC 62443 OT/industrial security across the lifecycle The standard for NIS2's OT-heavy sectors and a leading reference for CRA secure-development

Sources: ENISA NIS2 guidance; NIST CSF 2.0.

The message, echoing the overlap dividend: you do not need a bespoke program per cyber law. Run a mainstream baseline (ISO 27001 / NIST CSF 2.0), add IEC 62443 where you have operational technology and CRA product controls where you ship software. And map, don't reinvent.

Where Soveryne fits

NIS2 and the CRA are the clearest case for "map once, prove many." Command does exactly what ENISA's guidance implies: it enrolls NIS2 alongside ISO 27001 and maps the shared controls once, so your ISO 27001 evidence counts as NIS2 evidence rather than being rebuilt. Its coverage spans People, Organization, and Technology, matching NIS2's mix of training (People), governance and supply-chain (Organization), and technical controls (Technology), with continuous validation so the 24/72-hour reporting posture and the Article 21 measures stay demonstrably in place. The Starter plan is built around exactly this: one framework (ISO 27001 or NIS2) operated, not papered.

And when the scoping and interpretation questions come (are we an essential or important entity? does Article 21 require MFA everywhere?), Counsel answers from NIS2, the CRA, and the ENISA guidance with citations, so the coverage question is settled from the source, not a forum thread.

FAQ

Who has to comply with NIS2? Essential and important entities across 18 sectors, generally medium-sized and above, plus some entities regardless of size (e.g. DNS and TLD registries). Exact scope depends on national transposition.

What frameworks satisfy NIS2? ISO/IEC 27001:2022 and NIST CSF 2.0 are the primary references. ENISA's June 2025 guidance officially maps NIS2's Article 21 measures to both. Add IEC 62443 for operational technology.

How is the CRA different from NIS2? NIS2 governs how an organization runs security; the CRA governs the security of products with digital elements across their lifecycle: secure-by-design, vulnerability handling, and updates.

Can management be held liable under NIS2? Yes. Article 20 makes management bodies responsible for approving and overseeing cyber measures, and Member States may impose personal liability, including temporary management bans.


Reuse your security program as NIS2 evidence rather than rebuilding it. Map controls once with Command, and settle scope and interpretation with cited answers from Counsel.

Sources