You have until September 2026 to figure out how three EU regulations apply to your product. Most founders won't. The ones who do will treat compliance as a market entry barrier that kills slower competitors.

The NIS2 Directive, the Cyber Resilience Act (CRA), and the AI Act don't just overlap. They form a single compliance stack that hits small companies harder than large ones, because large companies have legal teams and you have a roadmap.

Here's what you need to know before the deadline, and why ignoring it is a business risk, not a legal one.

What the NIS2 CRA AI Act overlapping compliance SME actually means

The NIS2 Directive, formally Directive (EU) 2022/2555, establishes a unified legal framework for cybersecurity across 18 critical sectors in the EU, according to the European Commission's digital strategy page. It replaces the older NIS Directive from 2016, which the Commission itself acknowledged was insufficient for modern threats.

The Cyber Resilience Act targets hardware and software products. The AI Act targets artificial intelligence systems based on risk tier. Neither exists in a vacuum.

For a small company, the overlap looks like this: if you build software that processes data for a healthcare provider, NIS2 applies to your customer, and their compliance requirements flow down to you. If your software uses any AI component, the AI Act applies to your product directly. If your product has network connectivity, the CRA applies to your product directly.

You are not looking at three separate checklists. You are looking at one set of requirements viewed from three angles.

The NIS2 Directive: why your customer's problem is your problem

The NIS2 Directive came into force on January 16, 2023, according to nis2directive.eu. It covers 18 sectors, including energy, transport, banking, health, and digital infrastructure.

Here's what most founders miss: NIS2 applies to entities that provide essential or important services. If you sell to one of those entities, you become part of their supply chain. And supply chain security is explicitly part of the NIS2 framework.

The directive requires covered entities to manage cybersecurity risks in their supply chains. That means your customers will start auditing your security practices. Not because they want to, but because their compliance depends on it.

If you are a solo founder selling a SaaS tool to a mid-sized logistics company in Germany, your security posture now affects their legal standing. They will ask you questions. They will demand documentation. They may drop you if you cannot provide it.

The full text of the directive, available on EUR-Lex, outlines these supply chain requirements in Article 21, which covers cybersecurity risk-management measures. It is not optional. It is the law.

The Cyber Resilience Act: your product is now regulated

The CRA takes a different approach. Instead of regulating organizations, it regulates products. If your software or hardware has digital elements, the CRA applies.

This is the regulation that catches most small companies off guard. A solo developer building a mobile app with Bluetooth connectivity is building a "product with digital elements" under the CRA. A bootstrapped founder shipping a web application is also in scope, though the risk classification depends on the product's function.

The CRA requires manufacturers to:

  • Ensure security by design and by default
  • Provide security updates for a defined period
  • Report actively exploited vulnerabilities
  • Submit to conformity assessment procedures
  • The practical effect: you need documentation, testing, and a vulnerability handling process before you can put a CE mark on your product. Without it, you cannot sell in the EU market.

    For a small company, this is not a paperwork exercise. It is a product development cost that must be budgeted from day one.

    The AI Act: risk tiers determine your obligations

    The AI Act takes a risk-based approach. High-risk AI systems face the strictest requirements. Limited and minimal risk systems face lighter obligations, but transparency requirements still apply.

    If your product uses AI for any function, you need to determine your risk tier. This is not optional. The classification determines what you must do.

    For example, if your AI system is used for recruiting or employee management, it is high-risk. If it powers a chatbot, it is minimal risk but still requires transparency — users must know they are interacting with AI.

    The intersection with the CRA is where things get complicated. AI systems that are also products with digital elements must comply with both regulations. The AI Act includes provisions that reference the CRA's conformity assessment procedures, meaning you might go through one assessment process that covers both.

    This is the overlap that creates the compliance stack. You cannot do one without the other.

    The September 2026 deadline: what changes and what doesn't

    The CRA's obligations apply from September 2026 for most products, with some provisions applying earlier. This is the date that matters for product development cycles.

    If you are building a product today, you have roughly one development cycle to design for compliance. You cannot retrofit security requirements after launch. You will have to redesign, re-test, and re-document, which costs more than building it right the first time.

    NIS2 has already transposed into national laws across EU member states. The directive was published in December 2022, according to EUR-Lex, and member states had until October 2024 to transpose it into national legislation. The enforcement is happening now.

    The AI Act has a staggered timeline. Some provisions apply earlier, but the full obligations for most systems align with the 2026 timeframe.

    What this means: September 2026 is when the CRA and AI Act obligations converge. If you are not compliant by then, you cannot sell in the EU. Period.

    What a small company must do before September 2026

    The response is not panic. It is engineering.

    First, map your product against all three regulations. Write down what your product does, what data it processes, and whether it uses AI. Determine which regulations apply. Most products will fall under at least two.

    Second, build security into your development process now. The NIS2 supply chain requirements mean your customers will audit you. The CRA requires security by design. The AI Act requires risk management for high-risk systems. All three point to the same conclusion: security is a feature, not an afterthought.

    Third, document everything. Compliance is a documentation exercise as much as a technical one. You need to show your work. Threat models, risk assessments, testing results, vulnerability handling procedures. Start a compliance folder today. Add to it as you develop.

    Fourth, budget for conformity assessment. If your product falls into certain categories, you will need third-party assessment. This costs money and time. Factor it into your pricing and your timeline.

    Fifth, treat compliance as a competitive advantage. Most small companies will ignore this until forced. When your competitors are scrambling in late 2025, you will already have documentation and processes in place. Enterprise customers will choose you because you make their NIS2 compliance easier.

    The turn: compliance is not a cost center, it is a market filter

    Here is the uncomfortable truth: these regulations are designed to raise the bar. The EU wants to reduce the number of insecure products on the market. That means some products will not make it.

    For you, this is good news. Every competitor who cannot meet the requirements is a competitor who disappears. Every market you enter becomes less crowded.

    The founders who treat this as an opportunity will build products that enterprise customers trust. The founders who treat it as bureaucracy will build products that cannot be sold.

    The regulations are not going away. They are not going to be delayed. They are the new baseline for doing business in the EU.

    The question is not whether you can afford to comply. The question is whether you can afford to build a product that cannot be sold.

    The resolution: start now, not in 2026

    You have a development cycle before the deadline. Use it.

    Map your compliance requirements today. Build security into your roadmap. Document as you go. Budget for assessment. And when September 2026 arrives, you will have a product that is not just compliant, but trusted.

    The founders who do this will find that compliance opens doors. Enterprise customers will prefer them. Procurement processes will be shorter. Sales cycles will be faster.

    The founders who ignore this will find themselves locked out of the EU market, watching their competitors take the customers they could have had.

    The choice is yours. The deadline is fixed.

    ---

    You are building a product anyway. Run it through the same analytical rigor you apply to your business model — compliance is just another constraint to engineer around.

    [Button: Evaluate your product's compliance risk in 15 minutes]