AI law comparison · Data verified 2026-08-22
EU Cyber Resilience Act vs EU DORA
EU Cyber Resilience Act and EU DORA are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.
Find which laws apply to my businessSide by side
Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
The key difference
EU Cyber Resilience Act takes effect first, so it is usually the more urgent of the two. EU Cyber Resilience Act tracks 4 compliance requirements and EU DORA tracks 5. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.
EU Cyber Resilience Act (CRA) — Software & AI Products
The EU Cyber Resilience Act (CRA, Regulation 2024/2847, entered into force December 10, 2024) requires manufacturers and publishers of any software or hardware "product with digital elements" sold or made available in the EU to meet essential cybersecurity requirements. This includes SaaS products, AI applications, connected devices, and any software deployed by EU users. Phase 1 reporting obligations (vulnerability…
Full EU Cyber Resilience Act requirementsEU Digital Operational Resilience Act (DORA)
EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk management framework covering AI tools, mandatory third-party ICT risk assessment contracts (including AI vendors), regular resilience testing, and major ICT incident reporting. Financial entities using AI tools must include them…
Full EU DORA requirementsCommon questions
Could both EU Cyber Resilience Act and EU DORA apply to my business?
Yes. EU Cyber Resilience Act and EU DORA are separate regulations with separate scopes — a business can fall under both at once. EU Cyber Resilience Act covers Applies to: manufacturers, importers, and distributors of any 'product with digital elements' (hardware or software whose intended or reasonably foreseeable use… EU DORA covers DORA applies to 20 categories of EU financial entities: credit institutions (banks), payment institutions, e-money institutions, investment firms, crypto-asset… If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.
Which has the higher maximum penalty — EU Cyber Resilience Act or EU DORA?
EU Cyber Resilience Act: €15,000,000 or 2.5% of global annual turnover for essential requirement violations EU DORA: No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance. Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.
When does each law take effect?
EU Cyber Resilience Act — effective 2024-12-10, enforcement from 2026-09-11. EU DORA — effective 2025-01-17. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.
Related comparisons
See all law comparisonsStop guessing which laws apply
Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.
Start free compliance scan