• Cybersecurity Glossary
AI Act, NIS2, CRA and DORA: How the four regulations fit your compliance plan?
AI Act,NIS2, CRA and DORA are four EU regulations that increasingly overlap in any Compliance plan. NIS2 governs cybersecurity risk management and incident reporting for Essential and important entities, DORA governs digital operational resilience for the Financial sector, the CRA sets cybersecurity requirements for products with digital elements, and the AI Act regulates Artificial intelligence by risk. Many organizations fall under more than one, so treating them as a single coordinated programme, rather than four separate projects, saves effort and avoids conflicts. This page maps which regulation applies to whom, how their obligations overlap, and the deadlines that shape a joined up compliance plan.
The four regulations at a glance
The EU has built a dense cybersecurity and digital rulebook in a short time. Four regulations sit at its centre, and while each has its own focus, they are best understood together. Here is what each one does.
The compliance matrix
The clearest way to see how the four fit together is a single matrix of what each regulates, who it obliges, its core duty and when it applies. This is the map to keep beside any compliance plan.
| Regulation | What it regulates? | Who is obliged? | Key date |
|---|---|---|---|
| NIS2 | Cybersecurity risk management and incident reporting | Essential and important entities across sectors | Applies since transposition, 2026 reform proposed |
| DORA | Digital operational resilience | Financial entities and their ICT providers | Applies since 17 January 2025 |
| CRA | Cybersecurity of products with digital elements | Manufacturers, importers and distributors | Reporting 11 Sep 2026, full 11 Dec 2027 |
| AI Act | Artificial intelligence, by risk level | Providers and deployers of AI systems | High-risk from 2 Dec 2027 and 2 Aug 2028 |
How to read the matrix: the key insight is the second column. NIS2 and DORA regulate organizations, the CRA regulates products, and the AI Act regulates AI systems. An organization can be all of these at once, which is exactly why the obligations overlap and why one plan works better than four.
Where they overlap?
The four regulations were written separately but share several themes. These common threads are where a coordinated approach pays off most, because the same underlying capability can satisfy several regimes at once.
Which applies to whom?
The quickest way to scope your obligations is to look at your organization type. These examples show how the same body can sit under several regulations at once.
| Organization | Likely regulations | Why? |
|---|---|---|
| Bank or insurer | DORA, AI Act | Financial entity under DORA, plus high-risk AI such as credit scoring |
| Industrial manufacturer | NIS2, CRA | Important entity under NIS2 and maker of connected products under the CRA |
| Hospital | NIS2, AI Act, CRA | Essential entity using high-risk AI medical devices that are CRA products |
| Energy or utility operator | NIS2, CRA | Essential entity relying on connected operational technology |
| Software or device vendor | CRA, sometimes AI Act | Maker of products with digital elements, plus AI features where relevant |
Building one compliance plan
Once the overlaps are clear, the practical move is to run one programme that satisfies all applicable regulations at once. A few principles make that work.
One programme, not four: the regulations differ in detail but converge on the same goals, resilient, well managed, secure operations. Organizations that build once against those shared goals, then adapt for each regulation’s specifics, spend less and end up more secure than those running four disconnected projects.
A European foundation with Teldat
The four regulations share technical foundations: risk management, resilience, incident detection and reporting, and secure infrastructure. Teldat, a European manufacturer under European jurisdiction, provides infrastructure that supports those shared foundations across all four.
One infrastructure, four regulations: because AI Act, NIS2, CRA and DORA converge on resilience, detection and secure infrastructure, a single European foundation supports them all. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction. Teldat does not certify compliance with any of these regulations, and each organization remains responsible for its own obligations, but coordinated European infrastructure is a practical base for the whole plan.
Frequently asked questions – FAQ’s
❯ What is the difference between AI Act, NIS2, CRA and DORA?
The four regulations govern different things but overlap. NIS2, Directive (EU) 2022/2555, is about cybersecurity risk management and incident reporting for essential and important entities across many sectors. DORA, Regulation (EU) 2022/2554, is about digital operational resilience specifically for the financial sector, and it acts as lex specialis over NIS2 there. The CRA, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements and targets their manufacturers, importers and distributors. The AI Act, Regulation (EU) 2024/1689, regulates artificial intelligence based on risk. In short, NIS2 and DORA regulate organizations, the CRA regulates products, and the AI Act regulates AI systems, but they share themes like risk management and incident or vulnerability reporting.
❯ Can an organization be subject to more than one of these regulations?
Yes, and many are. A bank builds and uses AI, so it can fall under DORA as a financial entity and under the AI Act for any high-risk AI it deploys. A manufacturer of connected industrial equipment can be an important entity under NIS2 and, as a maker of products with digital elements, be directly obliged under the CRA. A hospital can be an essential entity under NIS2 while using high-risk AI medical devices covered by the AI Act, whose products also fall under the CRA. Because the same organization often sits under several regimes, treating them as one coordinated compliance programme, rather than four separate projects, avoids duplicated effort and conflicting processes.
❯ Do these regulations have different incident reporting timelines?
They share a similar philosophy but differ in detail. NIS2 requires an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. DORA uses a comparable staged model for major ICT related incidents, with initial, intermediate and final reports. The CRA requires manufacturers to report an actively exploited vulnerability or a severe incident with an early warning within 24 hours, a fuller notification within 72 hours and a final report within 14 days for vulnerabilities. Because the clocks are tight and similar, a single detection and response capability that can feed all of these processes is far more practical than separate ones.
❯ When do these regulations apply?
The dates are staggered. NIS2 has applied since national transposition following its October 2024 deadline, with a 2026 reform proposal easing some obligations. DORA has applied since 17 January 2025. The CRA entered into force in December 2024, with reporting obligations applying from 11 September 2026 and full application from 11 December 2027. The AI Act entered into force on 1 August 2024, with prohibited practices from February 2025, general purpose AI rules from August 2025, transparency duties from August 2026 and, after the Digital Omnibus, high-risk obligations from 2 December 2027 and 2 August 2028. Mapping these deadlines onto one timeline helps organizations sequence their compliance work.
❯ How can Teldat help with compliance across these regulations?
The four regulations share common technical foundations: cybersecurity risk management, resilience, incident detection and reporting, and secure infrastructure. Teldat, as a European manufacturer operating under European jurisdiction, provides infrastructure that supports these shared foundations. Teldat SD-WAN delivers resilient, self healing connectivity for operational resilience, be.Safe Pro adds cloud security with secure web gateway and NGFW features, and be.Safe XDR provides monitoring and extended detection and response that support the incident awareness all four regimes rely on. As a maker of products with digital elements, Teldat is also directly addressed by the CRA and speaks to it from the inside. Teldat does not certify compliance with any of these regulations, and each organization remains responsible for its own obligations, but coordinated, resilient European infrastructure is a practical foundation for all four.
One European foundation for AI Act, NIS2, CRA and DORA
The four regulations converge on resilience, detection and secure infrastructure. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction to support the shared foundation your whole compliance plan relies on.







