A product law, not an organisation law
Most EU digital rules bind organisations or data. The Cyber Resilience Act, Regulation (EU) 2024/2847, binds products. It sits inside the New Legislative Framework, the same machinery that governs toys, lifts and radio equipment: meet essential requirements, assess conformity, draw up a declaration, affix a CE mark, then place the product on the market. What is new is the subject matter. For the first time, software and connected hardware carry a CE mark for cybersecurity.
The distinction decides who has to do the work.
| Instrument | Binds | Trigger |
|---|---|---|
| GDPR | Controllers and processors | Processing personal data |
| NIS2 | Entities in listed sectors | Being an in-scope organisation |
| Cyber Resilience Act | Products with digital elements | Placing a product on the EU market |
An organisation can sit outside NIS2 entirely and still ship a product squarely inside the CRA. Scoping the company tells you nothing about scoping the catalogue.

