CRA alongside DORA, GPSR and the Product Liability Directive

The Cyber Resilience Act, Regulation (EU) 2024/2847, does not sit alone. Software and connected products can also be touched by DORA (the Digital Operational Resilience Act), the General Product Safety Regulation (GPSR), and the revised Product Liability Directive (PLD). These are separate instruments with their own scope and timing, and this guide stays high-level, flagging where specifics need checking against each source.

Four instruments, four angles

Each law looks at a product or its maker from a different angle.

Where they intersect with the CRA

The intersections are real but bounded, and they should be mapped rather than assumed.

A practical stance

Because the specifics of DORA, GPSR and the PLD sit outside this guide's verified facts, the practical stance is to establish your CRA position first, since it applies squarely to any product with digital elements, and then work out which of the other instruments reaches your organisation and products, mapping the overlaps deliberately.

How CRANIS2 helps

CRANIS2 is built for the EU Cyber Resilience Act. It gives software suppliers a solid CRA foundation: structured product-security evidence, SBOM, vulnerability handling, and conformity documentation. DORA, the GPSR and the Product Liability Directive appear here for orientation only. CRANIS2 is not a compliance tool for any of them, and any way its CRA evidence happens to help with them is a bonus, not a feature we sell. Create an account to build your CRA foundation.

Frequently asked questions

Does complying with the CRA mean I comply with DORA, GPSR and the PLD?

No. CRA conformity does not create an automatic safe harbour or presumption of compliance under DORA, the GPSR or the revised Product Liability Directive, although CRA evidence may assist supplier assurance, demonstrate compliance with applicable cybersecurity law and delimit risks already regulated by sector-specific rules.

Which of these applies to a software company?

It depends on what you make and who you serve. The CRA applies to products with digital elements on the EU market; DORA applies to the financial entities listed in its Article 2 and, for direct EU oversight, to ICT providers designated as critical; GPSR centres on consumer product safety; the PLD concerns liability for defective products, including software.

Where should I start?

A practical approach is to establish the CRA position first, because it applies to any product with digital elements, then map the reach of DORA, GPSR and the PLD onto the same products.


Related guides: CRA vs NIS2: how they differ and overlap and Does the CRA apply to my product?.