CRA standards timetable remains uncertain

CRA standards timetable remains uncertain

A proposed change to the Cyber Resilience Act standards timetable is not yet adopted. Manufacturers should prepare against the binding requirements while monitoring the status of harmonised standards.

The proposed timetable change is not yet law

The European Commission adopted Implementing Decision C(2025) 618 on 3 February 2025. It issued standardisation request M/606 to CEN, CENELEC and ETSI in support of Regulation (EU) 2024/2847, the Cyber Resilience Act.

In July 2026, Commission services published a consultation draft proposing changes to part of the timetable. The draft is explicit that it has not been adopted or endorsed by the Commission. The consultation is now recorded as expired, while the Commission's live record continues to show M/606 as under execution. As accessed on 26 September 2026, no adopted amendment was identified in the reviewed official sources. The Commission notification record, the consultation draft and the eNorm record for M/606 should therefore be treated as the current public status sources.

This matters because the dates in M/606 are deadlines for the European standardisation organisations to adopt requested standards. They are not direct manufacturer compliance deadlines.

Which dates the proposal would change

The consultation draft would move the deadlines for 28 requested items, while leaving the remaining 13 horizontal items unchanged.

Standards group Original deadline for ESO adoption Proposed deadline for ESO adoption
Item 1, secure product design 30 August 2026 30 October 2026
Item 15, vulnerability handling 30 August 2026 30 October 2026
Items 16-41, product-specific standards 30 October 2026 31 December 2026
Items 2-14, other horizontal standards 30 October 2027 Unchanged

The proposal therefore does not delay all 41 requested standards. It changes items 1 and 15, plus items 16 to 41. Items 2 to 14 would retain their 30 October 2027 deadline.

The Commission's CRA standardisation page provides the current high-level description of the 41 requested standards and links to the adopted request.

Adoption, citation and application are different milestones

A standard being adopted by CEN, CENELEC or ETSI does not by itself create a presumption of conformity. Under Article 27 of the Cyber Resilience Act, that presumption applies only where the reference to a harmonised standard has been published in the Official Journal of the European Union. It applies only to the requirements covered by the cited standard, or the relevant part of it.

That distinction leaves an unavoidable period of uncertainty. A timetable for adoption does not establish when the Commission will assess a standard or when its reference may appear in the Official Journal. Equally, a draft standard can help a team understand the likely direction of travel, but it does not have the legal effect of an Official Journal-cited harmonised standard.

The Cyber Resilience Act generally applies from 11 December 2027. This does not mean that nothing applies beforehand: Chapter IV has applied since 11 June 2026, and Article 14 has applied since 11 September 2026. The applicable dates and provisions are set out in Article 71.

Prepare against the binding requirements

The practical question is not whether every harmonised standard will be available at a particular point. It is how to make preparation resilient to changing standards status.

A sensible preparation sequence is to:

  • identify the product's relevant essential cybersecurity requirements and maintain a clear record of how each is addressed;
  • assess product cybersecurity risks across its lifecycle and retain the decisions, assumptions and evidence behind that assessment;
  • embed secure-development controls in design, development, release and maintenance activities;
  • establish vulnerability-handling arrangements, including processes for identifying, recording, assessing and addressing vulnerabilities;
  • organise technical evidence so that product decisions, security controls, test results and supporting records can be traced; and
  • maintain a standards-status register that distinguishes drafts, adopted standards and standards cited in the Official Journal.

This is practical preparation, not a claim of conformity or a substitute for product-specific legal and technical assessment. The binding essential requirements remain the starting point. Harmonised standards may later provide a route to the Article 27 presumption for the requirements they cover.

Use drafts carefully in gap analysis

Drafts may be useful for internal gap analysis, planning and testing assumptions. They can help teams spot likely evidence needs or process changes before a final standard is available.

Their limits should remain clear. A draft should be labelled as such in internal records, reviewed as it changes and never presented as proof of Article 27 conformity. Teams should also avoid treating an ESO adoption deadline as if it were an Official Journal citation date or a manufacturer deadline.

Keep the position under review

The most reliable approach is to check status at regular decision points, rather than relying on a single published timetable. Review the Commission document register, the eNorm record, the Official Journal and current records from the relevant standards bodies.

This creates a clearer audit trail: what was known at the time, which standard status applied, and why a product-security decision was made. It also allows teams to incorporate an adopted and cited harmonised standard when it becomes relevant, without postponing work on the Cyber Resilience Act's binding requirements.

Need help implementing cyber regulation?

Talk to Secuvi →