CRA alongside DORA, GPSR and the Product Liability Directive
The Cyber Resilience Act, Regulation (EU) 2024/2847, does not sit alone. Software and connected products can also be touched by DORA (the Digital Operational Resilience Act), the General Product Safety Regulation (GPSR), and the revised Product Liability Directive (PLD). These are separate instruments with their own scope and timing, and this guide stays high-level, flagging where specifics need checking against each source.
Four instruments, four angles
Each law looks at a product or its maker from a different angle.
- The CRA governs the cybersecurity of products with digital elements placed on the EU market, with main obligations applying from 11 December 2027.
- DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 to the financial entities listed in Article 2 and establishes risk-management and contractual controls over their ICT suppliers, together with direct EU oversight of providers formally designated as critical; a software supplier's CRA compliance may support customer due diligence but does not replace DORA obligations.
- GPSR, Regulation (EU) 2023/988, has applied since 13 December 2024 as a horizontal consumer-product safety net, applying where no EU provisions with the same safety objective exist and otherwise only to risks not covered by specific legislation; for products with digital elements, CRA Article 5 preserves specified GPSR provisions for non-cybersecurity safety risks not covered elsewhere.
- The Product Liability Directive, Directive (EU) 2024/2853, expressly includes software, updates and upgrades within EU product-liability law, allows safety-relevant cybersecurity requirements and missing safety updates to inform defectiveness, and must be transposed by 9 December 2026, but it does not itself impose a free-standing obligation to provide updates.
Where they intersect with the CRA
The intersections are real but bounded, and they should be mapped rather than assumed.
- DORA and the CRA. DORA does not directly regulate every ICT supplier: direct EU oversight applies principally to providers formally designated as critical, while ordinary suppliers are affected through their financial customers' risk management. A financial entity subject to DORA may procure products with digital elements that are themselves in CRA scope, so CRA conformity of a product can support the ICT risk management a DORA-regulated buyer expects, without replacing DORA's own obligations.
- GPSR and the CRA. Both concern products placed on the market, one from a general safety angle and one from a cybersecurity angle. The GPSR is a safety net that applies only where no EU provisions with the same objective exist, and CRA Article 5 preserves specified GPSR provisions for non-cybersecurity safety risks not covered elsewhere.
- PLD and the CRA. The revised PLD lets safety-relevant cybersecurity requirements and missing safety updates inform whether a product is defective, which links the CRA's product-security requirements to liability exposure. The PLD does not itself create a duty to provide updates; it determines liability where absent updates make a product defective.
A practical stance
Because the specifics of DORA, GPSR and the PLD sit outside this guide's verified facts, the practical stance is to establish your CRA position first, since it applies squarely to any product with digital elements, and then work out which of the other instruments reaches your organisation and products, mapping the overlaps deliberately.
How CRANIS2 helps
CRANIS2 is built for the EU Cyber Resilience Act. It gives software suppliers a solid CRA foundation: structured product-security evidence, SBOM, vulnerability handling, and conformity documentation. DORA, the GPSR and the Product Liability Directive appear here for orientation only. CRANIS2 is not a compliance tool for any of them, and any way its CRA evidence happens to help with them is a bonus, not a feature we sell. Create an account to build your CRA foundation.
Frequently asked questions
Does complying with the CRA mean I comply with DORA, GPSR and the PLD?
No. CRA conformity does not create an automatic safe harbour or presumption of compliance under DORA, the GPSR or the revised Product Liability Directive, although CRA evidence may assist supplier assurance, demonstrate compliance with applicable cybersecurity law and delimit risks already regulated by sector-specific rules.
Which of these applies to a software company?
It depends on what you make and who you serve. The CRA applies to products with digital elements on the EU market; DORA applies to the financial entities listed in its Article 2 and, for direct EU oversight, to ICT providers designated as critical; GPSR centres on consumer product safety; the PLD concerns liability for defective products, including software.
Where should I start?
A practical approach is to establish the CRA position first, because it applies to any product with digital elements, then map the reach of DORA, GPSR and the PLD onto the same products.
Related guides: CRA vs NIS2: how they differ and overlap and Does the CRA apply to my product?.