The CRA and NIS2 both use the word "important" for classification, and they mean different things. Teams that merge them into one field build a scale that is wrong.
---
The short answer
The CRA and NIS2 both use the word "important" as a formal classification. They do not mean the same thing.
CRA default · important (Annex III) · critical (Annex IV)
a PRODUCT class, driving conformity assessment route
NIS2 essential · important
an ENTITY class, driving supervisory regimeOne describes what you sell. The other describes what you are. A team that merges them into a single internal field produces a scale that is wrong in at least one regime — and the error is invisible, because the word looks right.
---
Why this is not pedantry
The two classifications drive completely different consequences.
Under the CRA, being "important" (Annex III) means your product cannot simply be self-assessed in every case — it pushes you toward stricter conformity assessment routes, and "critical" (Annex IV) can require a European cybersecurity certificate.
Under NIS2, being "important" rather than "essential" changes your *supervisory* regime: essential entities are supervised ex ante — an audit can arrive because of what you are. Important entities are supervised ex post — after evidence of a problem. The fine ceilings differ too.
So "we are important" can simultaneously mean a lighter supervisory regime and a heavier product assessment burden. Recorded in one field, that sentence is meaningless.
---
How the error actually happens
It is almost never a misunderstanding of the law. It is a data model decision.
A compliance tool, a spreadsheet or an internal register gets built with one field: criticality. It takes three values. Somebody maps CRA and NIS2 onto it because both vocabularies fit.
From that moment the register is confidently wrong, and every downstream artefact inherits the error — the risk assessment, the supplier questionnaire, the board report.
Nothing in the output looks wrong. That is exactly why it survives review.
---
The third collision nobody mentions
The AI Act adds a fourth vocabulary that overlaps semantically with neither:
AI Act unacceptable · high · limited · minimal"High risk" under the AI Act has no relationship to "critical" under the CRA. A high-risk AI system can be a default-class product; a critical product can contain no AI at all.
Three regulations, three scales, one word doing double duty in two of them.
---
What a correct register looks like
Separate fields, named after their instrument. It is not elegant and it is correct.
cra_class default | important_annex_iii | critical_annex_iv
nis2_class essential | important | out_of_scope
ai_act_class unacceptable | high | limited | minimal | not_applicableEach with its own reasoning field and its own date. An authority asks how you classified *under its own instrument* — a merged answer cannot be produced on demand.
---
How to check yours in ten minutes
- 1Open your compliance register and count the classification fields. One field for multiple regulations is the defect.
- 2Search for the word "important" and ask, for each occurrence, which regulation it refers to. If you cannot tell from the record, neither can an auditor.
- 3Check whether each classification carries a date and a reasoning. A value without reasoning is not a classification, it is an opinion.
- 4Look at what consumes the field downstream. The error propagates further than the register.
---
Why it matters more than it looks
Classification is the first question every market surveillance authority asks, and everything else follows from it. A wrong classification does not produce a small error later — it produces a programme aimed at the wrong obligations.
And unlike most compliance defects, this one cannot be repaired retroactively with any credibility, because the correction is dated after the product shipped.
---
Check your classification — free, no account
- [Free readiness assessment](/assess) — which class applies to you, under each instrument separately
- [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role
---
Further reading
→ Important versus critical under the CRA → Essential versus important under NIS2 → AI Act risk tiers → One evidence set across five EU regulations
---
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. NIS2 classification depends on national transposition and can differ between Member States. Verify against the applicable texts and consult your competent authority or a qualified adviser.*
Want the regulatory deep-dive ?
Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.
Browse Knowledge Base →