Skip to content

AI law comparison · Data verified 2026-08-22

EU Cyber Resilience Act vs EU DORA

EU Cyber Resilience Act and EU DORA are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.

Find which laws apply to my business

Side by side

Attribute
EU Cyber Resilience Act
EU DORA
Region
EU
EU
Effective date
2024-12-10
2025-01-17
Enforcement begins
2026-09-11
Who must comply
Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use includes a data connection) that is made available on the E…
DORA applies to 20 categories of EU financial entities: credit institutions (banks), payment institutions, e-money institutions, investment firms, crypto-asset service providers (MiCA), insurance undertakings, asset mana…
Maximum penalty
€15,000,000 or 2.5% of global annual turnover for essential requirement violations
No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance.
Compliance requirements
4 tracked
5 tracked
Enforcement actions on record
None on record yet
None on record yet
Data last verified
2026-08-22
2026-08-22

Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

The key difference

EU Cyber Resilience Act takes effect first, so it is usually the more urgent of the two. EU Cyber Resilience Act tracks 4 compliance requirements and EU DORA tracks 5. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.

EU

EU Cyber Resilience Act (CRA) — Software & AI Products

The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and publishers of any software or hardware "product with digital elements" sold or made available in the EU to meet essential cybersecurity requirements. This includes SaaS products, AI applications, connected devices, and any software deployed by EU users. Phase 1 reporting obligations (vulnerability…

Full EU Cyber Resilience Act requirements
EU

EU Digital Operational Resilience Act (DORA)

EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk management framework covering AI tools, mandatory third-party ICT risk assessment contracts (including AI vendors), regular resilience testing, and major ICT incident reporting. Financial entities using AI tools must include them…

Full EU DORA requirements

Common questions

Could both EU Cyber Resilience Act and EU DORA apply to my business?

Yes. EU Cyber Resilience Act and EU DORA are separate regulations with separate scopes — a business can fall under both at once. EU Cyber Resilience Act covers Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use… EU DORA covers DORA applies to 20 categories of EU financial entities: credit institutions (banks), payment institutions, e-money institutions, investment firms, crypto-asset… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.

Which has the higher maximum penalty — EU Cyber Resilience Act or EU DORA?

EU Cyber Resilience Act: €15,000,000 or 2.5% of global annual turnover for essential requirement violations EU DORA: No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance. Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.

When does each law take effect?

EU Cyber Resilience Act — effective 2024-12-10, enforcement from 2026-09-11. EU DORA — effective 2025-01-17. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.

Related comparisons

See all law comparisons

Stop guessing which laws apply

Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.

Start free compliance scan