Decoding the world of cybersecurity

CRA standards enter formal approval process

Seventeen product-specific cybersecurity standards have entered public enquiry as Europe moves from the Cyber Resilience Act’s legal requirements towards the technical rules manufacturers can use to demonstrate conformity.

CRA standards enter formal approval process
Summary
  • ETSI has placed 17 product-specific Cyber Resilience Act draft standards into formal public enquiry across European standardisation bodies.
  • The standards cover products including password managers, security software, smart-home technology, connected toys, and wearables.
  • Reporting duties begin in September 2026, while most CRA obligations apply from December 2027, increasing pressure on manufacturers to translate legal requirements into engineering controls.

European manufacturers are getting a clearer view of the technical standards that could eventually underpin compliance with the Cyber Resilience Act, as 17 product-specific cybersecurity standards enter formal public enquiry.

ETSI has submitted the final draft standards in its EN 304 series to 41 member organisations across Europe, including national standardisation bodies in the European Economic Area. The consultation periods run until dates between mid-September and mid-November, depending on the individual standard.

The standards cover categories of connected products including password managers, anti-virus products, smart-home assistants, connected toys, and wearables. They are intended to become European harmonised standards supporting the Cyber Resilience Act, although they have not yet acquired that status.

If ultimately adopted and cited as harmonised standards, they could give manufacturers a recognised technical route to demonstrate that products conform with particular CRA requirements through the EU system known as presumption of conformity.

That process sits at the junction between legislation and product engineering. The CRA establishes horizontal cybersecurity obligations for products with digital elements, but manufacturers still need detailed technical criteria against which software, devices, development practices, vulnerability handling, and security functions can be designed and assessed.

The timing is becoming more practical than theoretical. The CRA entered into force in December 2024. Provisions covering the notification of conformity-assessment bodies began applying in June this year, and manufacturers will be subject to the Act’s reporting obligations for actively exploited vulnerabilities and severe security incidents from 11 September 2026. Most other requirements apply from 11 December 2027.

ETSI says the 17 vertical standards form part of the technical machinery intended to bridge that gap. Sandra Feliciano, chair of the ETSI group responsible for CRA work, said legislation defines what manufacturers and the market must achieve while standards bodies specify the technical means by which compliance can be demonstrated.

The distinction is especially consequential for manufacturers with broad product ranges. A horizontal legal obligation can be implemented differently in a password manager, a connected toy, an endpoint security product, or an internet-connected appliance. Product-specific standards can reduce that ambiguity, but they also place detailed implementation choices into a standards process that vendors, national bodies, consumer groups, environmental representatives, trade unions, and small-business organisations are now being invited to scrutinise.

That scrutiny will shape more than certification paperwork. CRA obligations cover cybersecurity throughout a product lifecycle, including vulnerability handling and the period during which security support is provided. Engineering teams therefore need to connect design decisions, software composition, update mechanisms, vulnerability disclosure, technical documentation, and post-market processes to the eventual conformity regime.

The standards are not a safe harbour merely by existing. They remain drafts, and ETSI says comments submitted through the public-enquiry process will form part of the formal approval procedure. Harmonised-standard status would follow later through the EU process.

Manufacturers selling into Europe also face an unusually compressed implementation period. Reporting obligations arrive in less than a month, while the broader conformity framework continues to mature. The European Commission published additional implementation guidance in July, and the standardisation work now moving into public review will determine how much technical certainty companies have ahead of the December 2027 deadline.

The result is a compliance programme that cannot be treated solely as a legal exercise. Product architecture, security testing, update infrastructure, supplier assurance, vulnerability management, and documentation all need to converge on technical requirements that are still moving through the standards system.

ETSI has made the 17 final drafts publicly available during the enquiry period. Their eventual form will help determine how the CRA moves from a horizontal cybersecurity law into repeatable engineering and conformity practices across one of the world’s largest markets for connected products.

×