2026-09-21 · Equipo editorial KeXinMaterials

EU NIS2 + EU CRA + EU CER + DORA Ciberseguridad Familia Resiliencia Maletín B2B Guía

EU NIS2 + EU CRA + EU CER + DORA son las cuatro grandes regulaciones UE ciberseguridad + resiliencia. Requerido para IT + IoT + digital + infraestructura crítica.

EU NIS2 Directive (NIS 2) Cybersecurity

EU NIS 2 Directive (Directive (EU) 2022/2555) replaces NIS 1 (Directive (EU) 2016/1148). Effective October 2024 + transposition deadline October 2024 + application from October 2024.

EU NIS 2 Directive (EU) 2022/2555: "Directive on measures for a high common level of cybersecurity across the Union". Published December 2022 + effective October 2024 + application from October 2024.

NIS 2 scope: Essential entities (energy + transport + banking + financial market infrastructures + health + drinking water + waste water + digital infrastructure + public administration + space) + Important entities (digital services + postal services + waste management + chemicals + food + manufacturing + others).

NIS 2 entity classification: Essential entities (large + critical sectors) + Important entities (medium + other sectors). Different supervisory regimes.

NIS 2 cybersecurity risk management measures (Article 21): Risk assessment + policies + incident handling + business continuity + supply chain security + cryptography + access control + training + vulnerability handling + encryption + effectiveness assessment.

NIS 2 incident reporting (Article 23): Early warning within 24 hours + incident notification within 72 hours + final report within 30 days. Mandatory for essential + important entities.

NIS 2 supply chain security (Article 21(2)(d)): Address risks from suppliers + service providers + ICT products. Mandatory for essential entities.

NIS 2 senior management liability (Article 20): Management body approves cybersecurity measures + oversees implementation + can be held liable for non-compliance. Training mandatory.

NIS 2 registration: Essential + important entities register with national cybersecurity authority (e.g., BSI Germany + ANSSI France + ENISA EU).

NIS 2 enforcement: Penalties up to 10M EUR or 2% annual global turnover (whichever higher) for essential entities + 7M EUR or 1.4% for important entities.

NIS 2 + ISO 27001: NIS 2 Article 21 risk management aligned with ISO 27001:2022 ISMS + ISO 27005 risk assessment + ISO 27002 controls.

NIS 2 geographic scope: All 27 EU member states. UK + Switzerland + Norway + Iceland not directly but similar frameworks.

B2B relevance: For B2B protective cases containing IT + OT + IoT equipment supplied to essential or important entities in EU, NIS 2 compliance + supply chain security demonstration required.

EU Cyber Resilience Act (CRA)

EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements (PDE). Effective December 2024 + application from December 2027 (with phased exemptions).

EU Cyber Resilience Act (CRA) Regulation (EU) 2024/2847: "Regulation on horizontal cybersecurity requirements for products with digital elements". Published October 2024 + entry into force December 2024 + application from December 2027 (with phased exemptions).

CRA scope: All products with digital elements (PDE) including hardware + software + remote data processing solutions. Excludes medical devices (under MDR/IVDR) + automotive (under UN R155/R156) + aviation (under Part-IS) + certain open source.

CRA definition: "Products with digital elements" includes any software or hardware product with a digital data connection. Examples: smart speakers + baby monitors + connected appliances + IoT devices + firewalls + routers + industrial controllers.

CRA essential cybersecurity requirements (Annex I): (1) Designed secure (secure by default). (2) Vulnerability handling (vulnerability disclosure + patch management). (3) Software bill of materials (SBOM). (4) Secure update mechanism. (5) Secure authentication + access control. (6) Confidentiality + integrity of stored + transmitted data. (7) Resilience against DoS. (8) Minimize attack surface.

CRA conformity assessment: Self-assessment for most PDE. Third-party assessment for important + critical products (Annex III + IV). Critical products (Annex IV): (1) Identity management systems. (2) Password managers. (3) Smart home + consumer IoT. (4) Network equipment + firewalls + routers. (5) Microprocessors. (6) Operating systems. (7) Industrial automation + control systems (IACS). (8) Internet-connected toys. (10) Critical infrastructure monitoring.

CRA CE marking + EU Declaration of Conformity: Required for all PDE placed on EU market. CE marking per EU 765/2008. EU DoC per EU 2019/1020.

CRA technical documentation (Annex II): Required throughout product lifecycle. Includes design + development + vulnerability handling + risk assessment + SBOM.

CRA vulnerability handling (Article 11): Manufacturers must provide vulnerability handling process + SBOM + secure update + free security updates (at least 5 years).

CRA reporting (Article 14): Actively exploited vulnerabilities + severe incidents reported to ENISA within 24 hours + final report within 14 days. Mandatory for manufacturers.

CRA penalties: Up to 15M EUR or 2.5% annual global turnover (whichever higher). SME penalties smaller (up to 2.5M EUR or 1.25%).

CRA + NIS2: CRA for PDE cybersecurity + NIS2 for essential/important entity cybersecurity. CRA PDE supplied to NIS2 entities must comply with both.

CRA geographic scope: All PDE placed on EU market (manufacturer + importer + distributor). Non-EU manufacturers appoint EU authorized representative.

CRA + ISO 27001 + ETSI EN 303 645: CRA cybersecurity requirements aligned with ISO 27001 + ETSI EN 303 645 (consumer IoT cybersecurity) + NIST CSF 2.0.

B2B relevance: For B2B protective cases containing IoT + connected + smart + digital equipment, CRA compliance + CE marking + SBOM + vulnerability handling required.

EU CER Directive + Critical Infrastructure

EU CER Directive (Directive (EU) 2022/2557) replaces Critical Infrastructure Directive (2008/114/EC). Effective January 2023 + transposition deadline October 2024 + application from October 2024.

EU CER Directive (EU) 2022/2557: "Directive on the resilience of critical entities". Published December 2022 + effective January 2023 + application from October 2024.

CER scope: Critical entities providing essential services in 11 sectors: Energy + Transport + Banking + Financial market infrastructures + Health + Drinking water + Waste water + Space + Digital infrastructure + Public administration + Food.

CER entity identification: Member states identify critical entities providing essential services. Each entity subject to risk assessment + resilience measures + incident reporting.

CER risk assessment: Identify + assess risks that could disrupt essential services. Consider natural + man-made + terrorist + cyber threats.

CER resilience measures: All-hazards approach + business continuity + incident management + physical security + personnel security + supply chain resilience + cybersecurity alignment with NIS2.

CER incident reporting: Significant incidents reported to national authority within 24 hours + final report + cross-border impact assessment.

CER + NIS2 coordination: NIS2 for cybersecurity + CER for physical + all-hazards resilience. Both directives overlap on critical entities.

CER geographic scope: All 27 EU member states. Similar frameworks in UK (CIS Regs 2024) + US (CIRCIA 2022 + Presidential PP-21) + Japan (重要インフラ) + AU (SOCI Act 2018).

B2B relevance: For B2B protective cases supplied to critical entities (energy + transport + health + digital infrastructure), CER resilience + all-hazards + business continuity requirements.

EU DORA Digital Operational Resilience Act + Combined EU Cybersecurity Family

EU DORA Regulation (EU) 2022/2554 for financial services digital operational resilience. Combined EU cybersecurity + resilience regulatory family for B2B procurement.

EU DORA Regulation (EU) 2022/2554: "Regulation on digital operational resilience for the financial sector". Published December 2022 + application from January 17, 2025.

DORA scope: Financial entities (banks + insurance + investment firms + payment institutions + crypto-asset service providers + fund managers + credit rating agencies + ICT service providers to financial entities).

DORA 5 pillars: (1) ICT risk management. (2) ICT incident reporting. (3) Digital operational resilience testing. (4) ICT third-party risk management. (5) Information sharing arrangements.

DORA ICT risk management (Chapter II): ICT systems + risk identification + protection + detection + response + recovery. Aligns with ISO 27001 + NIST CSF 2.0.

DORA ICT incident reporting (Chapter III): Initial notification + intermediate report + final report. Mandatory for major ICT-related incidents.

DORA resilience testing (Chapter IV): Annual testing + vulnerability assessments + penetration testing + threat-led penetration testing (TLPT) for significant entities.

DORA ICT third-party risk (Chapter V): Critical ICT third-party service providers designated + European Supervisory Authorities (ESA) oversight. Register of information + contractual requirements.

DORA penalties: Up to 1% of daily average worldwide turnover per day for critical ICT third-party providers + 1M EUR for financial entities.

DORA + ISO 27001 + NIST CSF 2.0: DORA ICT risk management aligns with ISO 27001 ISMS + NIST CSF 2.0 Govern + Identify + Protect + Detect + Respond + Recover.

DORA + NIST 800-53 + NIST RMF: DORA resilience testing aligned with NIST 800-53 + NIST RMF (SP 800-37 Rev 2) + NIST SP 800-115 (technical security testing).

Combined EU cybersecurity family for B2B: NIS2 (essential/important entity cyber) + CRA (PDE cyber) + CER (critical entity resilience) + DORA (financial entity DORA). Combined + ISO 27001 + ISO 27005 + ISO 31000 + NIST CSF 2.0.

Common B2B mistakes: (1) Treating NIS2 + CRA + CER + DORA as separate. (2) Missing supply chain risk. (3) Missing vulnerability handling + SBOM. (4) No senior management accountability. (5) No cross-border compliance (UK + US + JP + AU).

B2B procurement workflow: (1) Identify customer EU regulatory regime (NIS2 + CRA + CER + DORA + combination). (2) Verify supplier compliance per regime. (3) Supply chain assessment (SBOM + vulnerability handling + security updates). (4) Contract terms: incident reporting + SLAs + liability + cross-border data + audit rights. (5) Continuous monitoring + periodic audit + CRA 5-year security updates.

B2B recommendation: For B2B protective cases with IT + IoT + digital + connected equipment supplied to EU, require NIS2 + CRA + CER + DORA compliance (per customer regime) + ISO 27001:2022 + ISO 27005 risk + ISO 31000 ERM + NIST CSF 2.0 + SBOM + 5-year security updates + CE marking, FOB Shenzhen/Ningbo/EXW delivery 30-45 days.

Puntos clave

  • NIS2 (effective Oct 2024): essential + important entity cyber risk + incident reporting 24h/72h/30d + senior management liability.
  • CRA (effective Dec 2027): PDE cybersecurity + SBOM + vulnerability handling + CE marking + 5-year security updates. Critical products need 3rd-party assessment.
  • CER (effective Oct 2024): critical entity all-hazards resilience + 11 sectors + business continuity + incident reporting.
  • DORA (effective Jan 2025): financial sector DORA + 5 pillars + ICT third-party oversight + critical ICT providers EU ESA.
  • Layered + complementary: DORA (financial) + NIS2 (essential/important cyber) + CER (critical entity all-hazards) + CRA (PDE cyber).
  • Geographic scope: All 27 EU member states. Non-EU manufacturers appoint EU authorized representative for CRA.
  • B2B recommendation: Require NIS2 + CRA + CER + DORA compliance (per customer regime) + ISO 27001:2022 + ISO 27005 + ISO 31000 + NIST CSF 2.0 + SBOM + 5-year security updates, FOB Shenzhen/Ningbo/EXW.

Preguntas frecuentes

q

a

q

a

q

a

q

a

q

a

q

a

q

a