Orientation

How the laws interact

Lex specialis, overlaps and reporting cascades — where instruments complement or supersede each other.

How the laws interact

The hardest part of EU cyber law is not any single act — it is the overlaps. This is the routing table.

1. NIS2 vs DORA — lex specialis

A bank sits in NIS2’s “banking” sector and in DORA. DORA wins for what it regulates (NIS2 Art. 4: equivalent sector-specific acts displace NIS2’s risk-management and reporting duties). Financial entities follow DORA’s ICT-risk framework and incident reporting; NIS2 still matters to them indirectly (national strategies, CSIRT ecosystem).

2. NIS2 vs CER — cyber twin / physical twin

Same logic, opposite domain. NIS2 = security of network & information systems; CER = all-hazards physical resilience (sabotage, terrorism, natural disaster). Entities identified critical under CER are automatically essential under NIS2 (Art. 3(1)(f)). Many states run both through connected authorities; France transposes both (plus DORA) in one bill.

3. NIS2 vs GDPR — dual reporting

One incident involving personal data triggers both:

NIS2GDPR
Whatsignificant incidentpersonal data breach
To whomCSIRT / competent authorityData Protection Authority
Deadline24h early warning, 72h notification72h notification
Fines€10M / 2% (essential)€20M / 4%

Run both workflows in parallel from awareness. The Digital Omnibus proposes to merge the submission channel (Single Entry Point) and move GDPR notification to 96h at a “high risk” threshold — but the underlying legal tests stay separate.

4. CRA vs RED — the product handover

RED’s cybersecurity delegated regulation (since 1 Aug 2025) reached connected radio equipment before the CRA. The CRA (fully applicable 11 Dec 2027) is broader and supersedes RED’s cyber requirements once applicable — so RED compliance is the on-ramp to CRA compliance (standards families aligned).

5. CRA vs NIS2 — product vs operator

CRA regulates the product (manufacturer’s duty: secure by design, updates, vulnerability handling). NIS2 regulates the operator using it (risk management, incl. supply-chain security under Art. 21(2)(d)). They meet in procurement, and under the Digital Omnibus a CRA severe-incident report could also satisfy a manufacturer’s NIS2 reporting.

6. CRA vs AI Act — high-risk AI products

A product with digital elements that is also a high-risk AI system: meeting CRA essential requirements can create a presumption of conformity with the AI Act’s cybersecurity requirement (Art. 15) for those aspects. One assessment, two badges.

7. Certification as glue (Cybersecurity Act → CSA2)

The certification framework (EUCC etc.) is voluntary today, but NIS2 Art. 24 lets states mandate certified products, and the CSA2 proposal turns certification into a horizontal compliance tool — “cyber posture certification” giving NIS2 entities a presumption of conformity and reducing duplicative audits across NIS2/CRA/DORA.

8. eIDAS 2 and the trust layer

Trust service and wallet providers have their own security and breach-notification duties under eIDAS 2 — and trust services are simultaneously a NIS2 sector. The Digital Omnibus would fold eIDAS reporting into the SEP; CSA2 would extend NIS2-style duties to wallet providers.

9. Incident reporting: today vs tomorrow

Today: an EU-wide incident at a financial-sector cloud user with personal data can require NIS2 (24h), GDPR (72h), DORA (4h/24h initial), and possibly CER/eIDAS notifications — different authorities, formats, languages. Tomorrow (if the Digital Omnibus passes): one submission to the ENISA-run Single Entry Point, auto-routed — live ~18–24 months after adoption. Thresholds and legal tests stay regime-specific, so classification decision-trees remain necessary.

Quick router — “which laws apply to me?”

You are…Primary regimes (in order)
Hospital, energy grid, water utility, transport operatorNIS2 + CER (+ sector rules)
Bank, insurer, investment firm, crypto providerDORA (+ NIS2 residually, GDPR)
Software vendor / IoT manufacturerCRA (+ RED until 2027, PLD, GDPR if processing)
Cloud / DNS / data centre / managed service providerNIS2 (digital infrastructure) + CRA for products + DORA reach-through if serving finance
Any company processing personal dataGDPR Art. 32–34
AI provider (high-risk / GPAI)AI Act Art. 15 & 55 (+ CRA if a product)
Public administrationNIS2 (public administration sector) + national schemes