Logo Teldat

• Cybersecurity Glossary

AI Act, NIS2, CRA and DORA: How the four regulations fit your compliance plan?

AI Act,NIS2, CRA and DORA are four EU regulations that increasingly overlap in any Compliance plan. NIS2 governs cybersecurity risk management and incident reporting for Essential and important entities, DORA governs digital operational resilience for the Financial sector, the CRA sets cybersecurity requirements for products with digital elements, and the AI Act regulates Artificial intelligence by risk. Many organizations fall under more than one, so treating them as a single coordinated programme, rather than four separate projects, saves effort and avoids conflicts. This page maps which regulation applies to whom, how their obligations overlap, and the deadlines that shape a joined up compliance plan.

The four regulations at a glance

The EU has built a dense cybersecurity and digital rulebook in a short time. Four regulations sit at its centre, and while each has its own focus, they are best understood together. Here is what each one does.

1
NIS2, cybersecurity for entities
Directive (EU) 2022/2555 requires essential and important entities across many sectors to manage cybersecurity risk and report significant incidents. It is the broad baseline for organizational cybersecurity in the EU, covering everything from energy and transport to digital infrastructure and public administration.
2
DORA, resilience for finance
Regulation (EU) 2022/2554 governs digital operational resilience for the financial sector, covering ICT risk management, incident reporting, resilience testing and third party risk. For financial entities it acts as lex specialis, meaning its specific rules take precedence over the more general NIS2.
3
CRA, security for products
Regulation (EU) 2024/2847, the Cyber Resilience Act, sets cybersecurity requirements for products with digital elements and obliges their manufacturers, importers and distributors. Unlike the others, it regulates the product itself across its lifecycle, from design to vulnerability handling.
4
AI Act, rules for artificial intelligence (AI)
Regulation (EU) 2024/1689 regulates AI on a risk based basis, with the strictest duties on high-risk systems, including a cybersecurity requirement in Article 15. It governs how AI is built and used, cutting across every sector that deploys artificial intelligence.

The compliance matrix

The clearest way to see how the four fit together is a single matrix of what each regulates, who it obliges, its core duty and when it applies. This is the map to keep beside any compliance plan.

Regulation What it regulates? Who is obliged? Key date
NIS2 Cybersecurity risk management and incident reporting Essential and important entities across sectors Applies since transposition, 2026 reform proposed
DORA Digital operational resilience Financial entities and their ICT providers Applies since 17 January 2025
CRA Cybersecurity of products with digital elements Manufacturers, importers and distributors Reporting 11 Sep 2026, full 11 Dec 2027
AI Act Artificial intelligence, by risk level Providers and deployers of AI systems High-risk from 2 Dec 2027 and 2 Aug 2028

How to read the matrix: the key insight is the second column. NIS2 and DORA regulate organizations, the CRA regulates products, and the AI Act regulates AI systems. An organization can be all of these at once, which is exactly why the obligations overlap and why one plan works better than four.

Where they overlap?

The four regulations were written separately but share several themes. These common threads are where a coordinated approach pays off most, because the same underlying capability can satisfy several regimes at once.

1
Incident and vulnerability reporting
NIS2, DORA and the CRA all use staged reporting clocks, typically an early warning within 24 hours and a fuller notification within 72 hours. A single detection and response capability that can feed each process is far more efficient than three separate ones.
2
Risk management as a common core
A documented, continuous risk management process is central to NIS2, DORA and the AI Act, and underpins CRA product security too. Build it once, to a high standard, and it becomes the backbone that each regulation can draw on rather than four parallel efforts.
3
Resilience and business continuity
DORA makes operational resilience explicit, NIS2 requires business continuity measures, and the AI Act expects high-risk systems to stay robust. Resilient, redundant infrastructure serves all three, keeping critical services available when something goes wrong.
4
Supply chain and third party risk
NIS2 and DORA both scrutinize third party and ICT supply chain risk, and the CRA effectively pushes security down the product supply chain. Choosing secure, European sourced infrastructure supports the supply chain expectations running through all four.

Which applies to whom?

The quickest way to scope your obligations is to look at your organization type. These examples show how the same body can sit under several regulations at once.

Organization Likely regulations Why?
Bank or insurer DORA, AI Act Financial entity under DORA, plus high-risk AI such as credit scoring
Industrial manufacturer NIS2, CRA Important entity under NIS2 and maker of connected products under the CRA
Hospital NIS2, AI Act, CRA Essential entity using high-risk AI medical devices that are CRA products
Energy or utility operator NIS2, CRA Essential entity relying on connected operational technology
Software or device vendor CRA, sometimes AI Act Maker of products with digital elements, plus AI features where relevant

Building one compliance plan

Once the overlaps are clear, the practical move is to run one programme that satisfies all applicable regulations at once. A few principles make that work.

1
Start with a scoping exercise
Map which of the four apply to you, using the matrix above. Knowing whether you are an entity, a product maker, an AI deployer, or several at once, defines the shape of your whole programme and prevents both gaps and wasted effort.
2
Build shared capabilities once
Invest in the common core, risk management, incident detection and reporting, and resilience, so one strong capability serves every regime. This avoids the duplication and contradictions that come from treating each regulation as a silo.
3
Sequence by deadline
Use the dates to prioritize. With DORA already in force, CRA reporting from September 2026 and AI Act high-risk duties in 2027 and 2028, a shared timeline lets you tackle the nearest obligations first while building toward the later ones.
4
Choose a resilient infrastructure base
Because resilience, detection and secure infrastructure run through all four, the technology foundation you choose matters. A secure, European infrastructure base supports every regulation at once and simplifies the whole programme.

One programme, not four: the regulations differ in detail but converge on the same goals, resilient, well managed, secure operations. Organizations that build once against those shared goals, then adapt for each regulation’s specifics, spend less and end up more secure than those running four disconnected projects.

A European foundation with Teldat

The four regulations share technical foundations: risk management, resilience, incident detection and reporting, and secure infrastructure. Teldat, a European manufacturer under European jurisdiction, provides infrastructure that supports those shared foundations across all four.

1
Detection across all regimes with be.Safe XDR
The incident and vulnerability reporting shared by NIS2, DORA and the CRA depends on fast detection. Teldat be.Safe XDR provides monitoring and extended detection and response that support the awareness those tight reporting clocks require.
2
Resilience with SD-WAN
Operational resilience runs through DORA, NIS2 and the AI Act. Teldat SD-WAN delivers self healing, redundant connectivity that keeps critical services available, supporting the continuity and robustness the regulations expect.
3
Layered security with be.Safe Pro
Strong baseline security supports the risk management common to all four. Teldat be.Safe Pro provides cloud security with secure web gateway and NGFW features, contributing to the security posture each regulation rewards.
4
A CRA obliged european manufacturer
As a maker of products with digital elements, Teldat is itself directly addressed by the CRA, and as a European manufacturer under European jurisdiction it fits the supply chain and sovereignty expectations running through all four regulations.

One infrastructure, four regulations: because AI Act, NIS2, CRA and DORA converge on resilience, detection and secure infrastructure, a single European foundation supports them all. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction. Teldat does not certify compliance with any of these regulations, and each organization remains responsible for its own obligations, but coordinated European infrastructure is a practical base for the whole plan.

Frequently asked questions – FAQ’s

❯ What is the difference between AI Act, NIS2, CRA and DORA?

The four regulations govern different things but overlap. NIS2, Directive (EU) 2022/2555, is about cybersecurity risk management and incident reporting for essential and important entities across many sectors. DORA, Regulation (EU) 2022/2554, is about digital operational resilience specifically for the financial sector, and it acts as lex specialis over NIS2 there. The CRA, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements and targets their manufacturers, importers and distributors. The AI Act, Regulation (EU) 2024/1689, regulates artificial intelligence based on risk. In short, NIS2 and DORA regulate organizations, the CRA regulates products, and the AI Act regulates AI systems, but they share themes like risk management and incident or vulnerability reporting.

❯ Can an organization be subject to more than one of these regulations?

Yes, and many are. A bank builds and uses AI, so it can fall under DORA as a financial entity and under the AI Act for any high-risk AI it deploys. A manufacturer of connected industrial equipment can be an important entity under NIS2 and, as a maker of products with digital elements, be directly obliged under the CRA. A hospital can be an essential entity under NIS2 while using high-risk AI medical devices covered by the AI Act, whose products also fall under the CRA. Because the same organization often sits under several regimes, treating them as one coordinated compliance programme, rather than four separate projects, avoids duplicated effort and conflicting processes.

❯ Do these regulations have different incident reporting timelines?

They share a similar philosophy but differ in detail. NIS2 requires an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. DORA uses a comparable staged model for major ICT related incidents, with initial, intermediate and final reports. The CRA requires manufacturers to report an actively exploited vulnerability or a severe incident with an early warning within 24 hours, a fuller notification within 72 hours and a final report within 14 days for vulnerabilities. Because the clocks are tight and similar, a single detection and response capability that can feed all of these processes is far more practical than separate ones.

❯ When do these regulations apply?

The dates are staggered. NIS2 has applied since national transposition following its October 2024 deadline, with a 2026 reform proposal easing some obligations. DORA has applied since 17 January 2025. The CRA entered into force in December 2024, with reporting obligations applying from 11 September 2026 and full application from 11 December 2027. The AI Act entered into force on 1 August 2024, with prohibited practices from February 2025, general purpose AI rules from August 2025, transparency duties from August 2026 and, after the Digital Omnibus, high-risk obligations from 2 December 2027 and 2 August 2028. Mapping these deadlines onto one timeline helps organizations sequence their compliance work.

❯ How can Teldat help with compliance across these regulations?

The four regulations share common technical foundations: cybersecurity risk management, resilience, incident detection and reporting, and secure infrastructure. Teldat, as a European manufacturer operating under European jurisdiction, provides infrastructure that supports these shared foundations. Teldat SD-WAN delivers resilient, self healing connectivity for operational resilience, be.Safe Pro adds cloud security with secure web gateway and NGFW features, and be.Safe XDR provides monitoring and extended detection and response that support the incident awareness all four regimes rely on. As a maker of products with digital elements, Teldat is also directly addressed by the CRA and speaks to it from the inside. Teldat does not certify compliance with any of these regulations, and each organization remains responsible for its own obligations, but coordinated, resilient European infrastructure is a practical foundation for all four.

One European foundation for AI Act, NIS2, CRA and DORA

The four regulations converge on resilience, detection and secure infrastructure. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction to support the shared foundation your whole compliance plan relies on.