CRA standards and what manufacturers should prepare for

CRA standards and what manufacturers should prepare for

Draft standards can help manufacturers prepare for the Cyber Resilience Act, but they do not create a presumption of conformity. That legal effect depends on an applicable harmonised standard being cited in the Official Journal of the European Union.

The legal effect of harmonised standards

Manufacturers of products with digital elements often ask which standard they should use to demonstrate compliance with the Cyber Resilience Act (CRA), formally Regulation (EU) 2024/2847. The answer depends on the product, the applicable requirements and the status of the relevant standard.

Under Article 27 of the CRA, a product or manufacturer process that conforms with a harmonised standard is presumed to conform with the essential requirements covered by that standard, but only where the standard's reference has been published in the Official Journal of the European Union. The presumption is limited to the requirements that the cited standard covers.

A draft, a Public Enquiry document, or a standard published by a standards body is not equivalent to an Official Journal citation. It may be useful preparation material, but it does not itself create a CRA presumption of conformity.

The CRA applies independently of the progress of standardisation. Its main obligations apply from 11 December 2027, subject to specified earlier application dates for particular provisions. Where no applicable harmonised standard is available or it is not applied in full, manufacturers still need evidence that their products and processes meet the applicable requirements.

Article 35 also allows the Commission, under specified conditions, to adopt common specifications for essential cybersecurity requirements. Conformity with an applicable common specification can provide a presumption of conformity for the requirements it covers. This is a statutory mechanism, not evidence that a common specification has already been adopted for a particular product.

The CRA standardisation programme

Commission Implementing Decision C(2025) 618 issued standardisation request M/606 to CEN, CENELEC and ETSI. The Commission describes the programme as covering 41 horizontal and vertical standards. CEN, CENELEC and ETSI accepted the request on 3 April 2025. The Commission's CRA standardisation information distinguishes between product-agnostic horizontal work and vertical work for particular product types.

Workstream Standards or work items Intended focus
Horizontal EN 40000 series Common requirements and processes for products with digital elements
Vertical IT and consumer ETSI EN 304 series Requirements for specified IT and consumer product types
Vertical operational technology OT security profiles and supporting European adaptations Specified OT products, drawing on IEC 62443

These workstreams are part of a development programme. Their legal status must be assessed separately for each exact work item and requirement.

Horizontal EN 40000 work

The EN 40000 work covers common CRA terminology, principles and processes, vulnerability handling, and generic security requirements. EN 40000-1-4 is identified as the work item on generic security requirements.

For manufacturers, this horizontal work can help structure preparation across product categories, particularly for secure development, vulnerability handling and generic security controls. Until an applicable harmonised standard is cited in the Official Journal, however, the work should not be treated as a completed conformity route.

ETSI vertical work for IT and consumer products

ETSI is developing vertical standards for particular product types in the ETSI EN 304 series. On 13 August 2026, ETSI reported that 17 vertical final drafts were under Public Enquiry, with approval procedures running to dates between mid-September and mid-November 2026. See ETSI's status announcement and its public draft directory.

The drafts include examples such as:

  • browsers and password managers;
  • antivirus software, VPN products and network management systems;
  • operating systems, routers and switches;
  • smart-home products, connected toys and wearables; and
  • firewalls.

These are product-specific final drafts under Public Enquiry. They are not yet evidence of harmonisation or presumption of conformity under the CRA. Manufacturers should check the status and scope of the exact document relevant to their product rather than assume that a vertical draft exists for every product with digital elements.

OT work based on IEC 62443

The M/606 programme also includes OT security profiles based on IEC 62443, supported by planned European adaptations of EN IEC 62443-3-3, EN IEC 62443-4-1 and EN IEC 62443-4-2.

IEC 62443 can provide useful existing engineering and process evidence for industrial automation and control environments. It does not automatically provide CRA presumption of conformity. Any later presumption will depend on the final European standard, its Official Journal citation and the CRA requirements it covers.

Preparing while standards are still developing

Manufacturers do not need to wait for every work item to reach its final legal status. A practical preparation process is to:

  • determine whether the product and its functions fall within the CRA;
  • map the applicable Annex I requirements to the product, its lifecycle and manufacturer processes;
  • identify relevant horizontal, vertical and OT work items;
  • collect product-specific evidence from secure development, vulnerability handling, testing, technical documentation and existing standards work;
  • assess any evidence based on IEC 62443, EN 18031, ETSI EN 303 645 or internal processes against the applicable CRA requirements, without treating it as automatic proof of compliance;
  • record which requirements each standard, process or other evidence source covers, and where gaps remain; and
  • monitor the exact status of relevant standards and Official Journal citations.

A concise status-check process

For each product, start with the applicable CRA requirements rather than a standard number. Then identify the relevant work item, verify its current status with the responsible standards body, and check whether an applicable reference has been cited in the Official Journal. Finally, document the requirements covered by that standard or other evidence and retain a clear record of any remaining gaps.

Need help implementing cyber regulation?

Talk to Secuvi →