Most organisations meet the rules one at a time, in the order they turn up. First the Cybersecurity Act, then a question from a customer about AI governance, then a demand from a distributor about product security. The result is often three separate projects describing the same organisation three times, with three different vocabularies and three sets of documents nobody reads together. This chapter argues that this order of work is both more expensive and worse than the alternative.
The chapter opens with the Cyber Resilience Act, what the CRA is, what separates it from NIS2 and what Swedish implementation looks like. The difference is one of principle. Where the Cybersecurity Act sets requirements on how an operation is run, the CRA sets requirements on the properties of what is placed on the market, which means one organisation can be caught by both in different parts of its business. Then follows the AI Act, its risk based structure where obligations follow the risk level of the use, who supervises it in Sweden, and how it connects to the rest of the security work. This is also where the regulatory triad of NIS2, the AI Act and ISO 42001 is introduced, showing how governance requirements converge. Electronic communications law gets a section of its own. After that comes the navigator, the structured walkthrough that answers step by step what applies to a given organisation. The chapter closes with a worked example of an operation caught by several sets of rules at once and how it can answer them with one effort. The underlying map is in chapter 3 on the regulatory map, and AI security in practice is covered in chapter 19.
The timing is worth noting. The CRA reaches full application in December 2027 and the high risk requirements of the AI Act also lie ahead. That sounds distant, but product development cycles are long, and anyone who starts adapting once the requirement already applies has spent years building the wrong thing. For those developing products, it is the design decisions taken now that determine whether the requirements can be met later.
This page shows what the chapter covers and why the rules are best met as a whole. The full logic of the navigator and the worked example are in chapter 4 of the book.
The rules are many, but the requirements run in the same direction. Build it right once and you answer several.
Key insights
- The CRA reaches whoever places products with digital elements on the EU market, meaning manufacturers and distributors rather than users.
- The AI Act is risk based. The obligations follow the risk level of the use, not the technology in itself.
- The regulatory triad of NIS2, the AI Act and ISO 42001 points at the same thing, governance you can demonstrate.
- Building systematic work once is cheaper than answering every set of rules separately.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Regulation navigator
The full navigator from appendix C, as an interactive tool.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.