2026-09-21 · KeXinMaterials 編集チーム
EU NIS2 + EU CRA + EU CER + DORA Cybersecurity + Resilience Family Protective Case B2B Guide
EU NIS2 (effective October 2024) + EU CRA (effective 2025-2027 phased) + EU CER Directive + DORA Digital Operational Resilience Act (January 2025) are the four major EU cybersecurity + resilience regulations. IT + IoT + digital + critical infrastructure required.
EU NIS2 Directive (NIS 2) Cybersecurity
EU NIS 2 Directive (Directive (EU) 2022/2555) replaces NIS 1 (Directive (EU) 2016/1148). Effective October 2024 + transposition deadline October 2024 + application from October 2024.
EU NIS 2 Directive (EU) 2022/2555: "Directive on measures for a high common level of cybersecurity across the Union". Published December 2022 + effective October 2024 + application from October 2024.
NIS 2 scope: Essential entities (energy + transport + banking + financial market infrastructures + health + drinking water + waste water + digital infrastructure + public administration + space) + Important entities (digital services + postal services + waste management + chemicals + food + manufacturing + others).
NIS 2 entity classification: Essential entities (large + critical sectors) + Important entities (medium + other sectors). Different supervisory regimes.
NIS 2 cybersecurity risk management measures (Article 21): Risk assessment + policies + incident handling + business continuity + supply chain security + cryptography + access control + training + vulnerability handling + encryption + effectiveness assessment.
NIS 2 incident reporting (Article 23): Early warning within 24 hours + incident notification within 72 hours + final report within 30 days. Mandatory for essential + important entities.
NIS 2 supply chain security (Article 21(2)(d)): Address risks from suppliers + service providers + ICT products. Mandatory for essential entities.
NIS 2 senior management liability (Article 20): Management body approves cybersecurity measures + oversees implementation + can be held liable for non-compliance. Training mandatory.
NIS 2 registration: Essential + important entities register with national cybersecurity authority (e.g., BSI Germany + ANSSI France + ENISA EU).
NIS 2 enforcement: Penalties up to 10M EUR or 2% annual global turnover (whichever higher) for essential entities + 7M EUR or 1.4% for important entities.
NIS 2 + ISO 27001: NIS 2 Article 21 risk management aligned with ISO 27001:2022 ISMS + ISO 27005 risk assessment + ISO 27002 controls.
NIS 2 geographic scope: All 27 EU member states. UK + Switzerland + Norway + Iceland not directly but similar frameworks.
B2B relevance: For B2B protective cases containing IT + OT + IoT equipment supplied to essential or important entities in EU, NIS 2 compliance + supply chain security demonstration required.
EU Cyber Resilience Act (CRA)
EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements (PDE). Effective December 2024 + application from December 2027 (with phased exemptions).
EU Cyber Resilience Act (CRA) Regulation (EU) 2024/2847: "Regulation on horizontal cybersecurity requirements for products with digital elements". Published October 2024 + entry into force December 2024 + application from December 2027 (with phased exemptions).
CRA scope: All products with digital elements (PDE) including hardware + software + remote data processing solutions. Excludes medical devices (under MDR/IVDR) + automotive (under UN R155/R156) + aviation (under Part-IS) + certain open source.
CRA definition: "Products with digital elements" includes any software or hardware product with a digital data connection. Examples: smart speakers + baby monitors + connected appliances + IoT devices + firewalls + routers + industrial controllers.
CRA essential cybersecurity requirements (Annex I): (1) Designed secure (secure by default). (2) Vulnerability handling (vulnerability disclosure + patch management). (3) Software bill of materials (SBOM). (4) Secure update mechanism. (5) Secure authentication + access control. (6) Confidentiality + integrity of stored + transmitted data. (7) Resilience against DoS. (8) Minimize attack surface.
CRA conformity assessment: Self-assessment for most PDE. Third-party assessment for important + critical products (Annex III + IV). Critical products (Annex IV): (1) Identity management systems. (2) Password managers. (3) Smart home + consumer IoT. (4) Network equipment + firewalls + routers. (5) Microprocessors. (6) Operating systems. (7) Industrial automation + control systems (IACS). (8) Internet-connected toys. (10) Critical infrastructure monitoring.
CRA CE marking + EU Declaration of Conformity: Required for all PDE placed on EU market. CE marking per EU 765/2008. EU DoC per EU 2019/1020.
CRA technical documentation (Annex II): Required throughout product lifecycle. Includes design + development + vulnerability handling + risk assessment + SBOM.
CRA vulnerability handling (Article 11): Manufacturers must provide vulnerability handling process + SBOM + secure update + free security updates (at least 5 years).
CRA reporting (Article 14): Actively exploited vulnerabilities + severe incidents reported to ENISA within 24 hours + final report within 14 days. Mandatory for manufacturers.
CRA penalties: Up to 15M EUR or 2.5% annual global turnover (whichever higher). SME penalties smaller (up to 2.5M EUR or 1.25%).
CRA + NIS2: CRA for PDE cybersecurity + NIS2 for essential/important entity cybersecurity. CRA PDE supplied to NIS2 entities must comply with both.
CRA geographic scope: All PDE placed on EU market (manufacturer + importer + distributor). Non-EU manufacturers appoint EU authorized representative.
CRA + ISO 27001 + ETSI EN 303 645: CRA cybersecurity requirements aligned with ISO 27001 + ETSI EN 303 645 (consumer IoT cybersecurity) + NIST CSF 2.0.
B2B relevance: For B2B protective cases containing IoT + connected + smart + digital equipment, CRA compliance + CE marking + SBOM + vulnerability handling required.
EU CER Directive + Critical Infrastructure
EU CER Directive (Directive (EU) 2022/2557) replaces Critical Infrastructure Directive (2008/114/EC). Effective January 2023 + transposition deadline October 2024 + application from October 2024.
EU CER Directive (EU) 2022/2557: "Directive on the resilience of critical entities". Published December 2022 + effective January 2023 + application from October 2024.
CER scope: Critical entities providing essential services in 11 sectors: Energy + Transport + Banking + Financial market infrastructures + Health + Drinking water + Waste water + Space + Digital infrastructure + Public administration + Food.
CER entity identification: Member states identify critical entities providing essential services. Each entity subject to risk assessment + resilience measures + incident reporting.
CER risk assessment: Identify + assess risks that could disrupt essential services. Consider natural + man-made + terrorist + cyber threats.
CER resilience measures: All-hazards approach + business continuity + incident management + physical security + personnel security + supply chain resilience + cybersecurity alignment with NIS2.
CER incident reporting: Significant incidents reported to national authority within 24 hours + final report + cross-border impact assessment.
CER + NIS2 coordination: NIS2 for cybersecurity + CER for physical + all-hazards resilience. Both directives overlap on critical entities.
CER geographic scope: All 27 EU member states. Similar frameworks in UK (CIS Regs 2024) + US (CIRCIA 2022 + Presidential PP-21) + Japan (重要インフラ) + AU (SOCI Act 2018).
B2B relevance: For B2B protective cases supplied to critical entities (energy + transport + health + digital infrastructure), CER resilience + all-hazards + business continuity requirements.
EU DORA Digital Operational Resilience Act + Combined EU Cybersecurity Family
EU DORA Regulation (EU) 2022/2554 for financial services digital operational resilience. Combined EU cybersecurity + resilience regulatory family for B2B procurement.
EU DORA Regulation (EU) 2022/2554: "Regulation on digital operational resilience for the financial sector". Published December 2022 + application from January 17, 2025.
DORA scope: Financial entities (banks + insurance + investment firms + payment institutions + crypto-asset service providers + fund managers + credit rating agencies + ICT service providers to financial entities).
DORA 5 pillars: (1) ICT risk management. (2) ICT incident reporting. (3) Digital operational resilience testing. (4) ICT third-party risk management. (5) Information sharing arrangements.
DORA ICT risk management (Chapter II): ICT systems + risk identification + protection + detection + response + recovery. Aligns with ISO 27001 + NIST CSF 2.0.
DORA ICT incident reporting (Chapter III): Initial notification + intermediate report + final report. Mandatory for major ICT-related incidents.
DORA resilience testing (Chapter IV): Annual testing + vulnerability assessments + penetration testing + threat-led penetration testing (TLPT) for significant entities.
DORA ICT third-party risk (Chapter V): Critical ICT third-party service providers designated + European Supervisory Authorities (ESA) oversight. Register of information + contractual requirements.
DORA penalties: Up to 1% of daily average worldwide turnover per day for critical ICT third-party providers + 1M EUR for financial entities.
DORA + ISO 27001 + NIST CSF 2.0: DORA ICT risk management aligns with ISO 27001 ISMS + NIST CSF 2.0 Govern + Identify + Protect + Detect + Respond + Recover.
DORA + NIST 800-53 + NIST RMF: DORA resilience testing aligned with NIST 800-53 + NIST RMF (SP 800-37 Rev 2) + NIST SP 800-115 (technical security testing).
Combined EU cybersecurity family for B2B: NIS2 (essential/important entity cyber) + CRA (PDE cyber) + CER (critical entity resilience) + DORA (financial entity DORA). Combined + ISO 27001 + ISO 27005 + ISO 31000 + NIST CSF 2.0.
Common B2B mistakes: (1) Treating NIS2 + CRA + CER + DORA as separate. (2) Missing supply chain risk. (3) Missing vulnerability handling + SBOM. (4) No senior management accountability. (5) No cross-border compliance (UK + US + JP + AU).
B2B procurement workflow: (1) Identify customer EU regulatory regime (NIS2 + CRA + CER + DORA + combination). (2) Verify supplier compliance per regime. (3) Supply chain assessment (SBOM + vulnerability handling + security updates). (4) Contract terms: incident reporting + SLAs + liability + cross-border data + audit rights. (5) Continuous monitoring + periodic audit + CRA 5-year security updates.
B2B recommendation: For B2B protective cases with IT + IoT + digital + connected equipment supplied to EU, require NIS2 + CRA + CER + DORA compliance (per customer regime) + ISO 27001:2022 + ISO 27005 risk + ISO 31000 ERM + NIST CSF 2.0 + SBOM + 5-year security updates + CE marking, FOB Shenzhen/Ningbo/EXW delivery 30-45 days.
重要なポイント
- NIS2 (effective Oct 2024): essential + important entity cyber risk + incident reporting 24h/72h/30d + senior management liability.
- CRA (effective Dec 2027): PDE cybersecurity + SBOM + vulnerability handling + CE marking + 5-year security updates. Critical products need 3rd-party assessment.
- CER (effective Oct 2024): critical entity all-hazards resilience + 11 sectors + business continuity + incident reporting.
- DORA (effective Jan 2025): financial sector DORA + 5 pillars + ICT third-party oversight + critical ICT providers EU ESA.
- Layered + complementary: DORA (financial) + NIS2 (essential/important cyber) + CER (critical entity all-hazards) + CRA (PDE cyber).
- Geographic scope: All 27 EU member states. Non-EU manufacturers appoint EU authorized representative for CRA.
- B2B recommendation: Require NIS2 + CRA + CER + DORA compliance (per customer regime) + ISO 27001:2022 + ISO 27005 + ISO 31000 + NIST CSF 2.0 + SBOM + 5-year security updates, FOB Shenzhen/Ningbo/EXW.
よくある質問
q
a
q
a
q
a
q
a
q
a
q
a
q
a
関連記事
- Nist Csf 2 Iso 27005 Iso 31000 Cybersecurity Risk Management Protective Case B2B Guide
- Iso 27001 2022 Iso 27002 2022 Iso 27017 Iso 27018 Iso 27701 Isms Privacy Family Protective Case B2B Guide
- Iec 62443 Nis2 Eu Cra Industrial Cybersecurity Protective Case B2B Guide
- Iso 20243 O Ttps Soc 2 Hipaa Supply Chain Privacy Data Family Protective Case B2B Guide