Skip to content

CRA harmonised standards: status September 2026

CRA standards in September 2026: 41 standards under M/606, 17 ETSI drafts in public enquiry, none cited in the Official Journal yet. What it means for you.

Marius Gill6 min readDeutsche Fassung

As of September 2026, no harmonised standard for the Cyber Resilience Act has been cited in the EU Official Journal. Standardisation request M/606 covers 41 standards; on 13 August 2026 ETSI launched the public enquiry for 17 product-specific drafts in the EN 304 xxx series.

For manufacturers this means the presumption of conformity that harmonised standards provide is not yet available. The obligations from December 2027 apply regardless – and evidence built now can later be mapped to the standards.

Standardisation request M/606

With standardisation request M/606 the Commission asked the European standardisation organisations to develop 41 standards in two groups:

  • Horizontal standards: apply across products, e.g. security requirements for the development process and vulnerability handling.
  • Product-specific (vertical) standards: prioritise the important and critical product categories in Annex III and IV.

CRA standardisation: status September 2026

CRA standardisation: status September 2026
Standards requested under M/60641 standards
ETSI EN 304 xxx drafts in public enquiry17 standards
Cited in the Official Journal0 standards
Source: European Commission: CRA standardisation; ETSI, 13 Aug 2026

ETSI EN 304 xxx: 17 drafts

On 13 August 2026 ETSI launched the approval process for 17 product-specific draft standards. They are in public enquiry with the national standardisation bodies. Covered products include password managers, anti-virus software, smart home assistants, connected toys and wearables – Annex III products. The enquiries close between mid-September and mid-November 2026, depending on the product area.

Timeline

DateMilestone
13 Aug 2026ETSI launches public enquiry for 17 product-specific drafts
30 Oct 2026Deadline in the request for product-specific standards
30 Oct 2027Deadline for horizontal standards
11 Dec 2027Full application of the CRA

Once finished, the Commission assesses the standards before citing them in the Official Journal. Only about six weeks separate the horizontal-standards deadline from full application – far too little to start implementation then.

Consequences for class I products

Important products of class I are hit hardest. They may only be placed on the market by self-assessment (module A) if the manufacturer fully applies harmonised standards, common specifications or European cybersecurity certification. Otherwise a notified body is required (module B+C or H). See CRA product categories for classification.

Class I manufacturers should therefore plan on two tracks: follow the relevant drafts and talk to a notified body in parallel in case standards are not cited in time.

Meanwhile: build evidence

The essential requirements in Annex I are fixed – standards only specify how to demonstrate them. What you do today stays valid:

  • Document and maintain a risk assessment per product.
  • Generate SBOMs automatically and archive them per release.
  • Run vulnerability handling, CVD policy and updates in a demonstrable way.
  • Store test results and configuration decisions under version control.
  • Capture requirements in a structured way so you can map them to standard clauses later.

The CRA compliance checklist offers a prioritised list.

What manufacturers can do now

  1. Identify relevant drafts: check whether one of the 17 ETSI drafts covers your product category.
  2. Comment: through your national standards body you can take part in enquiries or receive information.
  3. Prepare a gap analysis: map your existing evidence to the Annex I requirements – it can later be transferred to the standards' structure.
  4. Define plan B: for class I products, identify a possible notified body in case standards are not cited in time.
  5. Use existing frameworks: established secure-development frameworks help with structure, even though they do not provide a CRA presumption of conformity.

Scenarios for class I manufacturers

ScenarioConsequenceRecommendation
Product standard cited in time and fully appliedSelf-assessment (module A) possibleMap evidence to standard clauses
Standard cited but only partially appliedNotified body requiredJustify deviations, involve the body early
No standard cited in timeNotified body requiredPrepare assessment while tracking standards

Example: password manager maker

Password managers are class I, and ETSI has put a draft for this category into enquiry. A manufacturer should read the draft now, provisionally map its evidence to it and talk to a notified body at the same time. If the draft changes, only the mapping needs adjusting – the evidence itself stays.

Example: machine builder with a default product

For a default product, self-assessment is allowed regardless of standards. Horizontal standards will still be useful here to demonstrate requirements on the development process and vulnerability handling in a traceable way.

Common misunderstandings

  • 'Without standards the CRA does not apply yet.' Wrong – obligations apply from 11 December 2027 regardless of standardisation.
  • 'A draft is enough for self-assessment.' No, the version cited in the Official Journal counts.
  • 'Standards are mandatory.' They are voluntary, but make demonstration much easier.

An evidence dossier that grows with the standards

Nuowei (beta, launch November 2026) collects evidence from repository and pipeline per Annex I requirement. Once standards are cited, the evidence can be mapped to their clauses. Early access via the waitlist.

At ETSI and via your national standards body; the Commission publishes the citation status.

As of September 2026, none has been cited in the Official Journal. 17 ETSI drafts are in public enquiry.

Yes. Standards are voluntary and provide a presumption of conformity. You can demonstrate the requirements otherwise – but for class I products you then need a notified body.

No. The Annex I requirements are fixed and the time to December 2027 is short.

Join the waitlist

We launch in November. Be the first to get access.