This document is under active development and has not been finalized.
Skip to content

CRA & AI Act Synergies

Fundamental Principle

The BAUER GROUP is subject to three complementary EU cybersecurity regulations. To avoid duplication of effort and minimize internal compliance overhead, synergies are leveraged systematically: existing processes from CRA and AI Act compliance are referenced for NIS2 purposes, not duplicated.

Synergy Overview

NIS2 Measure (§30)CRA CoverageAI Act CoverageNIS2-Specific
No. 1 – Risk managementPartial (product-related, Art. 10)Art. 9 (AI risk management)ISMS, organizational risk analysis
No. 2 – Incident managementArt. 14 (product vulnerabilities)Operational incidents, §32 reporting
No. 3 – Business continuityEntirely NIS2-specific
No. 4 – Supply chainArt. 10(4), Annex I Part II No. 1Vendor assessment
No. 5 – VulnerabilitiesArt. 10(6), Art. 11 (product CVEs)Infrastructure CVEs
No. 6 – EffectivenessEntirely NIS2-specific
No. 7 – TrainingArt. 4 (AI Literacy)Cyber hygiene, BSIG-specific
No. 8 – CryptographyAnnex I Part II (product encryption)Art. 15 (AI cybersecurity)Infrastructure encryption
No. 9 – Access controlArt. 14 (human oversight)Personnel security, MFA
No. 10 – Secure communicationEntirely NIS2-specific

Detailed Synergies

Vulnerability Management (No. 5)

AspectCRA ProcessNIS2 Supplement
CVE monitoringCRA: Trivy + Grype + OSV-ScannerInfrastructure scanners (network, servers)
SBOMCRA: CycloneDX generation + Cosign signingReference to CRA SBOM
Patch managementCRA: product updatesNIS2: infrastructure patches (OS, firmware)
DisclosureCRA: ENISA reportingNIS2: BSI reporting

Reporting Obligations (No. 2 / §32)

AspectCRA (Art. 14)NIS2 (§32 BSIG)
TriggerActively exploited vulnerability in productsSignificant security incident in operations
Early warning24 hours to ENISA24 hours to BSI
Detailed report72 hours72 hours
Final report14 days1 month
Reporting authorityENISA Single Reporting PlatformBSI reporting platform

PARALLEL REPORTING OBLIGATIONS

An incident may trigger both reporting obligations. The shared initial assessment process automatically determines whether a CRA and/or NIS2 report is required. The templates are designed to be compatible.

Supply Chain (No. 4)

AspectCRA ProcessNIS2 Supplement
Software dependenciesCRA: Dependency Policy + SBOMReference to CRA
Service providersNIS2: hosting, cloud, support partners
Audit rightsCRA: supplier auditsNIS2: service provider audits

Effort Optimization

Through consistent use of existing CRA groundwork, the NIS2-specific additional effort is reduced to:

AreaEffort without SynergiesEffort with SynergiesSavings
Vulnerability managementFull build-outInfrastructure supplement only~60%
Incident responseFull build-outOperational incidents + §32 only~40%
Supply chainFull build-outVendor assessment only~50%
TrainingFull build-outReference AI Literacy (Art. 4)~20%

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT