CRA: 17 draft ETSI standards open for comment
News · Harmonised standards
On 13 August 2026, ETSI announced that the 17 final draft vertical standards developed for the Cyber Resilience Act, the EN 304 6xx series, are under Public Enquiry. These texts are intended to become harmonised standards, which is what unlocks the presumption of conformity in Article 27 of Regulation (EU) 2024/2847. None is cited in the OJEU yet, and that absence is not a formality: for a class I important product, it currently forces the manufacturer through a notified body.
In short:
- 17 final drafts, from EN 304 617 to EN 304 636, are under public enquiry. The procedure runs until mid-September to mid-November 2026 depending on the vertical.
- They cover 15 of the 19 class I categories and 2 of the 4 class II categories in Annex III to Regulation (EU) 2024/2847.
- The drafts are public and downloadable without ETSI membership.
- Comments go through the 41 member organisations, including the national standardisation bodies of the European Economic Area, plus ANEC, ECOS, ETUC and SBS.
- While no standard is cited, Article 32(2) leaves a class I manufacturer with module B followed by module C, or module H.
What is under public enquiry
Section titled “What is under public enquiry”The 17 files sit in the open area of ETSI's TC CYBER-EUSR group. Each draft targets one category of Annex III, the list of important products with digital elements.
| Standard | Draft version | Product covered | Annex III |
|---|---|---|---|
| EN 304 617 | V1.0.0, 12 August 2026 | Browsers | Class I, 2 |
| EN 304 618 | V0.2.2, 22 June 2026 | Password managers | Class I, 3 |
| EN 304 619 | V1.0.0, 15 July 2026 | Anti-virus and anti-malware software | Class I, 4 |
| EN 304 620 | V1.0.0, 12 August 2026 | Virtual private networks (VPN) | Class I, 5 |
| EN 304 621 | V1.0.5, 12 August 2026 | Network management systems | Class I, 6 |
| EN 304 622 | V1.0.0, 12 August 2026 | SIEM systems | Class I, 7 |
| EN 304 623 | V0.1.3, 17 June 2026 | Boot managers | Class I, 8 |
| EN 304 624 | V1.0.0, 5 August 2026 | Public key infrastructure and certificate issuance | Class I, 9 |
| EN 304 625 | V1.0.0, 10 August 2026 | Physical and virtual network interfaces | Class I, 10 |
| EN 304 626 | V1.0.1, 12 August 2026 | Operating systems | Class I, 11 |
| EN 304 627 | V1.0.1, 6 July 2026 | Routers, internet modems and switches | Class I, 12 |
| EN 304 631 | V1.0.0, 20 July 2026 | Smart home general purpose virtual assistants | Class I, 16 |
| EN 304 632 | V1.0.0, 20 July 2026 | Smart home products with security functionalities | Class I, 17 |
| EN 304 633 | V1.0.0, 20 July 2026 | Internet connected toys under Directive 2009/48/EC | Class I, 18 |
| EN 304 634 | V1.0.0, 24 July 2026 | Personal wearables with a health monitoring purpose | Class I, 19 |
| EN 304 635 | V1.0.1, 24 June 2026 | Hypervisors and container runtime systems | Class II, 1 |
| EN 304 636 | V1.0.0, 9 July 2026 | Firewalls, intrusion detection and prevention systems | Class II, 2 |
Two things stand out. The versions are uneven: EN 304 618 and EN 304 623 are still at V0.x while the rest are at V1.0.x. And the draft dates span June to August 2026, which is why the comment windows do not all close together.
Why a missing citation changes the assessment route
Section titled “Why a missing citation changes the assessment route”This is the point many teams discover late. The CRA does not merely set essential requirements, it makes the conformity assessment procedure depend on whether an applicable harmonised standard exists.
| Product status | If harmonised standards are applied | Otherwise, or if none exist |
|---|---|---|
| Not listed in Annex III or IV | Module A, internal control | Module A, internal control |
| Annex III, class I | Module A available | Module B then C, or module H |
| Annex III, class II | Module B then C, module H, or a European certification scheme at level 'substantial' or above | Same |
| Annex IV, critical products | European certification scheme under Article 8(1), or the class II procedures | Same |
Article 32(1) sets the principle: the manufacturer picks the procedure, and internal control under module A is enough. Article 32(2) closes that door for class I where the manufacturer "has not applied or has applied only in part" harmonised standards, common specifications or a European cybersecurity certification scheme, or where those do not exist. What remains is module B followed by module C, or module H, both of which bring in a third party.
A manufacturer of routers, operating systems, home security cameras, connected toys or activity trackers is therefore directly exposed to the fate of these 17 drafts. Until a reference is published in the OJEU, module A is not available. Class II is a different case: for hypervisors and firewalls, Article 32(3) requires a third party regardless, and harmonised standards will only structure that assessment rather than remove it.
What this batch does not cover
Section titled “What this batch does not cover”Mandate M/606 covers 41 standards in total, split across the three European standardisation organisations. The 17 ETSI drafts are one share of that, and the joint work programme published on 2 April 2025 shows where the rest sit.
- Identity management and privileged access management, category 1 of class I, belongs to CEN/TC 224, not to ETSI.
- Microprocessors, microcontrollers, and the ASIC and FPGA categories with security-related functionalities, along with their tamper-resistant variants, belong to CLC/TC 47X. Those five silicon categories are not in the EN 304 6xx series.
- The horizontal standards, the ones that apply to any product with digital elements, are developed by CEN-CLC/JTC 13 WG 9. The work programme sets adoption of the cyber resilience principles standard and the vulnerability handling standard at 30 August 2026, and the generic security requirements at 30 October 2027.
- Four verticals are in parallel getting IEC 62443-based security profiles from CLC/TC 65X: VPN, network management, SIEM and firewalls.
In other words, a class I product may map onto an ETSI draft available today, onto CEN or CENELEC work that has not reached enquiry, or onto both.
The timeline, and the margin left
Section titled “The timeline, and the margin left”Commission Implementing Decision C(2025) 618 final of 3 February 2025 carries the standardisation request. The joint work programme sets the adoption deadline for the vertical standards at 30 October 2026. Only then come the vote, the ratification, and the citation in the Official Journal by Commission implementing decision.
| Step | Date |
|---|---|
| Standardisation request C(2025) 618 final | 3 February 2025 |
| Accepted by CEN, CENELEC and ETSI | 3 April 2025 |
| Public enquiries on the 17 drafts close | mid-September to mid-November 2026 |
| Work programme adoption deadline for the vertical standards | 30 October 2026 |
| Reporting of exploited vulnerabilities, Article 14 | 11 September 2026 |
| Full application of the CRA, including CE marking | 11 December 2027 |
| Final joint report from the standardisation organisations | 30 October 2027 |
The margin is thin. An enquiry closing in November 2026 leaves roughly a year for the vote, the ratification and the citation before the regulation applies in full. Building a compliance plan on the assumption that a standard will be cited in time is a bet, not a plan.
What to do
Section titled “What to do”- Place the product in Annex III. Class I and class II do not lead to the same procedure, and a product outside Annex III stays on module A whatever happens.
- Read the matching draft now. It is public, free, and it describes the requirements the assessment will apply. It is the best specification available at this stage.
- Line up the third-party route as a fallback if the product is class I. A notified body is booked in advance, not summoned the week before placing on the market.
- Comment before your vertical closes, through your national standardisation body.
- Document the Annex I essential requirements without waiting for a citation. They apply on 11 December 2027 whatever the standardisation process delivers.
Going further
Section titled “Going further”- Cyber Resilience Act guide: scope, product classes and assessment routes
- Cyber Resilience Act, 2026 and 2027 timeline: the 11 September 2026 reporting deadline
- CE harmonised standards: how citation in the Official Journal works and what it buys you
Sources & references
- ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act, 13 August 2026 , ETSI www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/
- Drafts under public enquiry, ETSI TC CYBER-EUSR , ETSI docbox.etsi.org/CYBER/EUSR/Open/
- Regulation (EU) 2024/2847, Cyber Resilience Act , EUR-Lex eur-lex.europa.eu/eli/reg/2024/2847/oj
- CEN, CENELEC and ETSI joint work programme for mandate M/606, version V1 of 2 April 2025 , CEN-CENELEC www.cencenelec.eu/media/CEN-CENELEC/News/Newsletters/2025/m_606_work_programme_final.pdf
- Cyber Resilience Act, standardisation , European Commission digital-strategy.ec.europa.eu/en/policies/cra-standardisation
- CRA standardisation request accepted by CEN, CENELEC and ETSI, 3 April 2025 , CEN-CENELEC www.cencenelec.eu/news-events/news/2025/newsletter/ots-62-cra/