Skip to content

CRA: 17 draft ETSI standards open for comment

News · Harmonised standards

On 13 August 2026, ETSI announced that the 17 final draft vertical standards developed for the Cyber Resilience Act, the EN 304 6xx series, are under Public Enquiry. These texts are intended to become harmonised standards, which is what unlocks the presumption of conformity in Article 27 of Regulation (EU) 2024/2847. None is cited in the OJEU yet, and that absence is not a formality: for a class I important product, it currently forces the manufacturer through a notified body.

In short:

  • 17 final drafts, from EN 304 617 to EN 304 636, are under public enquiry. The procedure runs until mid-September to mid-November 2026 depending on the vertical.
  • They cover 15 of the 19 class I categories and 2 of the 4 class II categories in Annex III to Regulation (EU) 2024/2847.
  • The drafts are public and downloadable without ETSI membership.
  • Comments go through the 41 member organisations, including the national standardisation bodies of the European Economic Area, plus ANEC, ECOS, ETUC and SBS.
  • While no standard is cited, Article 32(2) leaves a class I manufacturer with module B followed by module C, or module H.

The 17 files sit in the open area of ETSI's TC CYBER-EUSR group. Each draft targets one category of Annex III, the list of important products with digital elements.

StandardDraft versionProduct coveredAnnex III
EN 304 617V1.0.0, 12 August 2026BrowsersClass I, 2
EN 304 618V0.2.2, 22 June 2026Password managersClass I, 3
EN 304 619V1.0.0, 15 July 2026Anti-virus and anti-malware softwareClass I, 4
EN 304 620V1.0.0, 12 August 2026Virtual private networks (VPN)Class I, 5
EN 304 621V1.0.5, 12 August 2026Network management systemsClass I, 6
EN 304 622V1.0.0, 12 August 2026SIEM systemsClass I, 7
EN 304 623V0.1.3, 17 June 2026Boot managersClass I, 8
EN 304 624V1.0.0, 5 August 2026Public key infrastructure and certificate issuanceClass I, 9
EN 304 625V1.0.0, 10 August 2026Physical and virtual network interfacesClass I, 10
EN 304 626V1.0.1, 12 August 2026Operating systemsClass I, 11
EN 304 627V1.0.1, 6 July 2026Routers, internet modems and switchesClass I, 12
EN 304 631V1.0.0, 20 July 2026Smart home general purpose virtual assistantsClass I, 16
EN 304 632V1.0.0, 20 July 2026Smart home products with security functionalitiesClass I, 17
EN 304 633V1.0.0, 20 July 2026Internet connected toys under Directive 2009/48/ECClass I, 18
EN 304 634V1.0.0, 24 July 2026Personal wearables with a health monitoring purposeClass I, 19
EN 304 635V1.0.1, 24 June 2026Hypervisors and container runtime systemsClass II, 1
EN 304 636V1.0.0, 9 July 2026Firewalls, intrusion detection and prevention systemsClass II, 2

Two things stand out. The versions are uneven: EN 304 618 and EN 304 623 are still at V0.x while the rest are at V1.0.x. And the draft dates span June to August 2026, which is why the comment windows do not all close together.

Why a missing citation changes the assessment route

Section titled “Why a missing citation changes the assessment route”

This is the point many teams discover late. The CRA does not merely set essential requirements, it makes the conformity assessment procedure depend on whether an applicable harmonised standard exists.

Product statusIf harmonised standards are appliedOtherwise, or if none exist
Not listed in Annex III or IVModule A, internal controlModule A, internal control
Annex III, class IModule A availableModule B then C, or module H
Annex III, class IIModule B then C, module H, or a European certification scheme at level 'substantial' or aboveSame
Annex IV, critical productsEuropean certification scheme under Article 8(1), or the class II proceduresSame

Article 32(1) sets the principle: the manufacturer picks the procedure, and internal control under module A is enough. Article 32(2) closes that door for class I where the manufacturer "has not applied or has applied only in part" harmonised standards, common specifications or a European cybersecurity certification scheme, or where those do not exist. What remains is module B followed by module C, or module H, both of which bring in a third party.

A manufacturer of routers, operating systems, home security cameras, connected toys or activity trackers is therefore directly exposed to the fate of these 17 drafts. Until a reference is published in the OJEU, module A is not available. Class II is a different case: for hypervisors and firewalls, Article 32(3) requires a third party regardless, and harmonised standards will only structure that assessment rather than remove it.

Mandate M/606 covers 41 standards in total, split across the three European standardisation organisations. The 17 ETSI drafts are one share of that, and the joint work programme published on 2 April 2025 shows where the rest sit.

  • Identity management and privileged access management, category 1 of class I, belongs to CEN/TC 224, not to ETSI.
  • Microprocessors, microcontrollers, and the ASIC and FPGA categories with security-related functionalities, along with their tamper-resistant variants, belong to CLC/TC 47X. Those five silicon categories are not in the EN 304 6xx series.
  • The horizontal standards, the ones that apply to any product with digital elements, are developed by CEN-CLC/JTC 13 WG 9. The work programme sets adoption of the cyber resilience principles standard and the vulnerability handling standard at 30 August 2026, and the generic security requirements at 30 October 2027.
  • Four verticals are in parallel getting IEC 62443-based security profiles from CLC/TC 65X: VPN, network management, SIEM and firewalls.

In other words, a class I product may map onto an ETSI draft available today, onto CEN or CENELEC work that has not reached enquiry, or onto both.

Commission Implementing Decision C(2025) 618 final of 3 February 2025 carries the standardisation request. The joint work programme sets the adoption deadline for the vertical standards at 30 October 2026. Only then come the vote, the ratification, and the citation in the Official Journal by Commission implementing decision.

StepDate
Standardisation request C(2025) 618 final3 February 2025
Accepted by CEN, CENELEC and ETSI3 April 2025
Public enquiries on the 17 drafts closemid-September to mid-November 2026
Work programme adoption deadline for the vertical standards30 October 2026
Reporting of exploited vulnerabilities, Article 1411 September 2026
Full application of the CRA, including CE marking11 December 2027
Final joint report from the standardisation organisations30 October 2027

The margin is thin. An enquiry closing in November 2026 leaves roughly a year for the vote, the ratification and the citation before the regulation applies in full. Building a compliance plan on the assumption that a standard will be cited in time is a bet, not a plan.

  1. Place the product in Annex III. Class I and class II do not lead to the same procedure, and a product outside Annex III stays on module A whatever happens.
  2. Read the matching draft now. It is public, free, and it describes the requirements the assessment will apply. It is the best specification available at this stage.
  3. Line up the third-party route as a fallback if the product is class I. A notified body is booked in advance, not summoned the week before placing on the market.
  4. Comment before your vertical closes, through your national standardisation body.
  5. Document the Annex I essential requirements without waiting for a citation. They apply on 11 December 2027 whatever the standardisation process delivers.

Sources & references

  1. ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act, 13 August 2026 , ETSI www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
  2. Drafts under public enquiry, ETSI TC CYBER-EUSR , ETSI docbox.etsi.org/CYBER/EUSR/Open/
  3. Regulation (EU) 2024/2847, Cyber Resilience Act , EUR-Lex eur-lex.europa.eu/eli/reg/2024/2847/oj
  4. CEN, CENELEC and ETSI joint work programme for mandate M/606, version V1 of 2 April 2025 , CEN-CENELEC www.cencenelec.eu/media/CEN-CENELEC/News/Newsletters/2025/m_606_work_programme_final.pdf
  5. Cyber Resilience Act, standardisation , European Commission digital-strategy.ec.europa.eu/en/policies/cra-standardisation
  6. CRA standardisation request accepted by CEN, CENELEC and ETSI, 3 April 2025 , CEN-CENELEC www.cencenelec.eu/news-events/news/2025/newsletter/ots-62-cra/