Back to Newsroom
CRA · NexCyber Editorial

"Important" Means Two Different Things in EU Cyber Law

The CRA and NIS2 both use the word "important" for classification, and they mean different things. Teams that merge them into one field build a scale that is wrong.

---

The short answer

The CRA and NIS2 both use the word "important" as a formal classification. They do not mean the same thing.

CRA     default  ·  important (Annex III)  ·  critical (Annex IV)
        a PRODUCT class, driving conformity assessment route

NIS2    essential  ·  important
        an ENTITY class, driving supervisory regime

One describes what you sell. The other describes what you are. A team that merges them into a single internal field produces a scale that is wrong in at least one regime — and the error is invisible, because the word looks right.

---

Why this is not pedantry

The two classifications drive completely different consequences.

Under the CRA, being "important" (Annex III) means your product cannot simply be self-assessed in every case — it pushes you toward stricter conformity assessment routes, and "critical" (Annex IV) can require a European cybersecurity certificate.

Under NIS2, being "important" rather than "essential" changes your *supervisory* regime: essential entities are supervised ex ante — an audit can arrive because of what you are. Important entities are supervised ex post — after evidence of a problem. The fine ceilings differ too.

So "we are important" can simultaneously mean a lighter supervisory regime and a heavier product assessment burden. Recorded in one field, that sentence is meaningless.

---

How the error actually happens

It is almost never a misunderstanding of the law. It is a data model decision.

A compliance tool, a spreadsheet or an internal register gets built with one field: criticality. It takes three values. Somebody maps CRA and NIS2 onto it because both vocabularies fit.

From that moment the register is confidently wrong, and every downstream artefact inherits the error — the risk assessment, the supplier questionnaire, the board report.

Nothing in the output looks wrong. That is exactly why it survives review.

---

The third collision nobody mentions

The AI Act adds a fourth vocabulary that overlaps semantically with neither:

AI Act   unacceptable  ·  high  ·  limited  ·  minimal

"High risk" under the AI Act has no relationship to "critical" under the CRA. A high-risk AI system can be a default-class product; a critical product can contain no AI at all.

Three regulations, three scales, one word doing double duty in two of them.

---

What a correct register looks like

Separate fields, named after their instrument. It is not elegant and it is correct.

cra_class      default | important_annex_iii | critical_annex_iv
nis2_class     essential | important | out_of_scope
ai_act_class   unacceptable | high | limited | minimal | not_applicable

Each with its own reasoning field and its own date. An authority asks how you classified *under its own instrument* — a merged answer cannot be produced on demand.

---

How to check yours in ten minutes

  1. 1Open your compliance register and count the classification fields. One field for multiple regulations is the defect.
  2. 2Search for the word "important" and ask, for each occurrence, which regulation it refers to. If you cannot tell from the record, neither can an auditor.
  3. 3Check whether each classification carries a date and a reasoning. A value without reasoning is not a classification, it is an opinion.
  4. 4Look at what consumes the field downstream. The error propagates further than the register.

---

Why it matters more than it looks

Classification is the first question every market surveillance authority asks, and everything else follows from it. A wrong classification does not produce a small error later — it produces a programme aimed at the wrong obligations.

And unlike most compliance defects, this one cannot be repaired retroactively with any credibility, because the correction is dated after the product shipped.

---

Check your classification — free, no account

  • [Free readiness assessment](/assess) — which class applies to you, under each instrument separately
  • [Compliance responsibility mapper](/resources/responsibility-mapper) — a RACI by role

---

Further reading

Important versus critical under the CRAEssential versus important under NIS2AI Act risk tiersOne evidence set across five EU regulations

---

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. NIS2 classification depends on national transposition and can differ between Member States. Verify against the applicable texts and consult your competent authority or a qualified adviser.*

Want the regulatory deep-dive ?

Our regulatory engineering team publishes implementation guides + practical checklists for each regulatory update.

Browse Knowledge Base →