Compare / ISO 27001 vs CRA

Regulation comparison

ISO 27001 vs CRA

The CRA certifies the product; ISO 27001 certifies the organisation. Enterprise buyers ask for both, and product teams routinely pass the first while failing the second, because nobody owns the information security management system.

ISO 27001 / 27002EU Cyber Resilience Act
Applies whenEnterprise buyers that require ISMS alignment from suppliersAny product with digital elements placed on the EU market, consumer or industrial
Who demands itProcurement and tendersMarket access, mandatory (CE marking)
What it isStandard, organisationalRegulation
ScopeNot a product standard. Organisational risk treatment, asset ownership, supplier agreements, internal audit. A product can pass every ETSI provision and still fail procurement if nobody owns the ISMSSecurity by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period
In force2022 edition currentIn force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027
PenaltiesNone; losing the tenderUp to EUR 15M or 2.5% of global turnover
Authoritative textISO 27001 text โ†—CRA text โ†— ยท on this site

What a product team should do

If your customers are enterprises, assign an ISMS owner before the first tender. The CRA file covers the product questions; 27001 covers the questions about you.

Check your own product

The IoT security scorecard grades a product against these frameworks in 19 questions, and the requirements generator turns the applicable ones into PRD-ready requirements. Both cite the same provisions this page does. The full map is on the regulatory landscape reference.

Sources: ISO 27001 / 27002 (official text) and EU Cyber Resilience Act (official text). Educational reference, not legal advice. See Chapter 18 and Chapter 19 of Tangibles.

โ† All comparisons

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility