ETSI Opens Enquiry on 17 CRA Product Standards, and None Are Cited Yet
Draft standards for routers, firewalls, hypervisors and industrial operating systems are readable now, but with nothing published in the Official Journal no product category has a presumption of conformity.

On 13 August 2026 ETSI opened public enquiry on seventeen final draft European Standards written for the Cyber Resilience Act: EN 304 617 through EN 304 627, and EN 304 631 through EN 304 636. The approval procedure closes between mid-September and mid-November, with the exact date varying by vertical.
The drafts cover Annex III Class I items 2 to 12 and 16 to 19 plus Class II items 1 and 2 — a list that includes routers, modems and switches, operating systems, firewalls with intrusion detection, hypervisors and container runtimes, smart home assistants, connected toys, wearables, VPNs, SIEM software and public key infrastructure. They build on the EN 18031 series with additional controls to reach CRA scope.
For anyone specifying industrial gateways, switches or embedded operating systems this is the first concrete per-product statement of what the CRA's essential requirements actually mean, and it is readable before ratification rather than after.
The more consequential fact is what has not happened. As of 13 August no CRA harmonised standard had been ratified as an EN or had its reference published in the Official Journal, so the Article 27 presumption of conformity is available for no product category at all. That has a direct procurement consequence: a supplier claiming today that a product is CRA-compliant against a harmonised standard cannot be relying on presumption of conformity, because none exists. The right question to a vendor is not whether they are compliant but what evidence backs the claim.
Two areas sit outside this first round: identity and access management, which is being handled with CEN, and semiconductors. So does the horizontal tier that covers most products with digital elements — the default case for the majority of connected industrial hardware. Standardisation request M/606 covers 41 standards in total, and a July 2026 draft amendment pushed the horizontal deliverable deadlines back by two months.
Source: cyberresilienceact.eu