The Cyber Resilience Act places obligations on manufacturers of products with digital elements, and NIS2 places obligations on operators of essential services, so both apply to the devices and the operators in a mioty deployment rather than to the radio standard itself. The alliance’s position is that CRA compliance is the responsibility of the manufacturer and the operator, while the alliance keeps its specifications written in a way that supports compliance.

