Orientation
How the laws interact
Lex specialis, overlaps and reporting cascades — where instruments complement or supersede each other.
How the laws interact
The hardest part of EU cyber law is not any single act — it is the overlaps. This is the routing table.
1. NIS2 vs DORA — lex specialis
A bank sits in NIS2’s “banking” sector and in DORA. DORA wins for what it regulates (NIS2 Art. 4: equivalent sector-specific acts displace NIS2’s risk-management and reporting duties). Financial entities follow DORA’s ICT-risk framework and incident reporting; NIS2 still matters to them indirectly (national strategies, CSIRT ecosystem).
2. NIS2 vs CER — cyber twin / physical twin
Same logic, opposite domain. NIS2 = security of network & information systems; CER = all-hazards physical resilience (sabotage, terrorism, natural disaster). Entities identified critical under CER are automatically essential under NIS2 (Art. 3(1)(f)). Many states run both through connected authorities; France transposes both (plus DORA) in one bill.
3. NIS2 vs GDPR — dual reporting
One incident involving personal data triggers both:
| NIS2 | GDPR | |
|---|---|---|
| What | significant incident | personal data breach |
| To whom | CSIRT / competent authority | Data Protection Authority |
| Deadline | 24h early warning, 72h notification | 72h notification |
| Fines | €10M / 2% (essential) | €20M / 4% |
Run both workflows in parallel from awareness. The Digital Omnibus proposes to merge the submission channel (Single Entry Point) and move GDPR notification to 96h at a “high risk” threshold — but the underlying legal tests stay separate.
4. CRA vs RED — the product handover
RED’s cybersecurity delegated regulation (since 1 Aug 2025) reached connected radio equipment before the CRA. The CRA (fully applicable 11 Dec 2027) is broader and supersedes RED’s cyber requirements once applicable — so RED compliance is the on-ramp to CRA compliance (standards families aligned).
5. CRA vs NIS2 — product vs operator
CRA regulates the product (manufacturer’s duty: secure by design, updates, vulnerability handling). NIS2 regulates the operator using it (risk management, incl. supply-chain security under Art. 21(2)(d)). They meet in procurement, and under the Digital Omnibus a CRA severe-incident report could also satisfy a manufacturer’s NIS2 reporting.
6. CRA vs AI Act — high-risk AI products
A product with digital elements that is also a high-risk AI system: meeting CRA essential requirements can create a presumption of conformity with the AI Act’s cybersecurity requirement (Art. 15) for those aspects. One assessment, two badges.
7. Certification as glue (Cybersecurity Act → CSA2)
The certification framework (EUCC etc.) is voluntary today, but NIS2 Art. 24 lets states mandate certified products, and the CSA2 proposal turns certification into a horizontal compliance tool — “cyber posture certification” giving NIS2 entities a presumption of conformity and reducing duplicative audits across NIS2/CRA/DORA.
8. eIDAS 2 and the trust layer
Trust service and wallet providers have their own security and breach-notification duties under eIDAS 2 — and trust services are simultaneously a NIS2 sector. The Digital Omnibus would fold eIDAS reporting into the SEP; CSA2 would extend NIS2-style duties to wallet providers.
9. Incident reporting: today vs tomorrow
Today: an EU-wide incident at a financial-sector cloud user with personal data can require NIS2 (24h), GDPR (72h), DORA (4h/24h initial), and possibly CER/eIDAS notifications — different authorities, formats, languages. Tomorrow (if the Digital Omnibus passes): one submission to the ENISA-run Single Entry Point, auto-routed — live ~18–24 months after adoption. Thresholds and legal tests stay regime-specific, so classification decision-trees remain necessary.
Quick router — “which laws apply to me?”
| You are… | Primary regimes (in order) |
|---|---|
| Hospital, energy grid, water utility, transport operator | NIS2 + CER (+ sector rules) |
| Bank, insurer, investment firm, crypto provider | DORA (+ NIS2 residually, GDPR) |
| Software vendor / IoT manufacturer | CRA (+ RED until 2027, PLD, GDPR if processing) |
| Cloud / DNS / data centre / managed service provider | NIS2 (digital infrastructure) + CRA for products + DORA reach-through if serving finance |
| Any company processing personal data | GDPR Art. 32–34 |
| AI provider (high-risk / GPAI) | AI Act Art. 15 & 55 (+ CRA if a product) |
| Public administration | NIS2 (public administration sector) + national schemes |