Compare / ISO 27001 vs CRA
Regulation comparison
ISO 27001 vs CRA
The CRA certifies the product; ISO 27001 certifies the organisation. Enterprise buyers ask for both, and product teams routinely pass the first while failing the second, because nobody owns the information security management system.
| ISO 27001 / 27002 | EU Cyber Resilience Act | |
|---|---|---|
| Applies when | Enterprise buyers that require ISMS alignment from suppliers | Any product with digital elements placed on the EU market, consumer or industrial |
| Who demands it | Procurement and tenders | Market access, mandatory (CE marking) |
| What it is | Standard, organisational | Regulation |
| Scope | Not a product standard. Organisational risk treatment, asset ownership, supplier agreements, internal audit. A product can pass every ETSI provision and still fail procurement if nobody owns the ISMS | Security by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period |
| In force | 2022 edition current | In force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027 |
| Penalties | None; losing the tender | Up to EUR 15M or 2.5% of global turnover |
| Authoritative text | ISO 27001 text โ | CRA text โ ยท on this site |
What a product team should do
If your customers are enterprises, assign an ISMS owner before the first tender. The CRA file covers the product questions; 27001 covers the questions about you.
Check your own product
The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.
Sources: ISO 27001 / 27002 (official text) and EU Cyber Resilience Act (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.
โ All comparisons