CRA Compliance

The ETSI EN 304 Series: One CRA Standard Per Annex III Product Category

By CVD Portal Team
11 min read

Ask most people tracking Cyber Resilience Act standardisation what they are waiting for and you will hear about prEN 40000. That is the horizontal series from CEN-CENELEC JTC 13, the one that covers vocabulary, cyber resilience principles, vulnerability handling and generic security requirements for every product with digital elements.

It is half the story. Standardisation request M/606 asked for 41 standards, and the horizontal series accounts for five of them. The rest are vertical: one standard per Annex III product category, describing what that specific type of product has to do. Most of that work sits with ETSI, and it has been going on in public.

If you make a password manager, a smart door lock, or a hypervisor, there is a draft standard with your product's name on it that you can read today.

Horizontal and vertical

The distinction matters because the two families answer different questions.

A horizontal standard tells you how to run a risk assessment, how to handle vulnerability reports, and what a "secure by default configuration" means in general. It applies whether you ship an industrial controller or a children's toy.

A vertical standard tells you what a children's toy specifically has to do. It takes the Annex I essential requirements and makes them concrete for one product category, which is the level of specificity a test lab needs to actually assess something.

A manufacturer of an important product will likely end up needing both. The horizontal series carries the general obligations and the process requirements, and the vertical standard adds the product-type detail. Neither replaces the other.

The numbering is not arbitrary

ETSI's vertical deliverables are numbered EN 304 617 through EN 304 642, and the rule behind those numbers is worth knowing because it makes the whole series legible at a glance.

The deliverable number is 304 600 plus its M/606 line item.

Annex I of the standardisation request numbers its requested standards. Items 1 to 15 are the horizontal ones. From item 16 onward they are vertical, one per Annex III category, in the order the Annex lists them. So:

  • Line item 17, standalone and embedded browsers, becomes EN 304 617
  • Line item 19, software that searches for, removes or quarantines malicious software, becomes EN 304 619
  • Line item 27, routers, modems and switches, becomes EN 304 627
  • Line item 36, firewalls and intrusion detection or prevention systems, becomes EN 304 636

Once you see it, the gaps explain themselves. There is no EN 304 628, 629 or 630 because line items 28, 29 and 30 are the semiconductor categories, and those went to CENELEC rather than ETSI. The same is true of the run from 637 to 641.

The full mapping

Here is every ETSI vertical deliverable against the Annex III or Annex IV point it covers.

StandardProduct categoryAnnex point
EN 304 617BrowsersAnnex III, Class I, point 2
EN 304 618Password managersAnnex III, Class I, point 3
EN 304 619Anti-malware softwareAnnex III, Class I, point 4
EN 304 620VPN productsAnnex III, Class I, point 5
EN 304 621Network management systemsAnnex III, Class I, point 6
EN 304 622SIEM systemsAnnex III, Class I, point 7
EN 304 623Boot managersAnnex III, Class I, point 8
EN 304 624PKI and certificate issuanceAnnex III, Class I, point 9
EN 304 625Network interfacesAnnex III, Class I, point 10
EN 304 626Operating systemsAnnex III, Class I, point 11
EN 304 627Routers, modems, switchesAnnex III, Class I, point 12
EN 304 631Smart home virtual assistantsAnnex III, Class I, point 16
EN 304 632Smart home security productsAnnex III, Class I, point 17
EN 304 633Internet-connected toysAnnex III, Class I, point 18
EN 304 634Personal wearablesAnnex III, Class I, point 19
EN 304 635Hypervisors and container runtimesAnnex III, Class II, point 1
EN 304 636Firewalls, IDS/IPSAnnex III, Class II, point 2
EN 304 642Telecom network functionsNo Annex III point

EN 304 642 is the odd one out. It has no Annex III category behind it and no corresponding line item in the mandate's Annex I list, which ends at 41.

Public drafts are downloadable for most of these from ETSI's open consultation area. Coverage is partial, so a handful are work items with nothing public yet, and the ones that are published sit at different stages: some are early mature drafts, some are at enquiry, and a few have reached final draft. We keep a current status table with versions and dates, checked directly against ETSI.

What ETSI is not covering

This is the part that catches people out. Nine Annex III and Annex IV points are outside the EN 304 series entirely, and if your product is one of them, watching the ETSI work programme will tell you nothing.

  • Identity management and privileged access management (Annex III, Class I, point 1) sits with CEN/TC 224 WG 17, the cards and security devices committee.
  • Microprocessors, microcontrollers, and ASICs and FPGAs with security-related functionalities (points 13, 14 and 15) are with CENELEC CLC/TC 47X, as prEN 50765.
  • Tamper-resistant microprocessors and microcontrollers (Annex III, Class II, points 3 and 4) are also at CLC/TC 47X, as prEN 50766.
  • All three Annex IV critical categories are elsewhere: hardware devices with security boxes at CEN/TC 224, smart meter gateways at CEN-CLC/JTC 13 WG 6, and smartcards including secure elements split between prEN 50764 and prEN 18330.

If you make secure elements or smart meter gateways, your standards conversation is with CENELEC, and it has been all along.

Six product types are being standardised twice

There is a second CENELEC series worth knowing about. CLC/TC 65X WG 3 is drafting prEN 50770 on IEC 62443 foundations, aimed at operational technology, and it covers six of the same product types as their ETSI counterparts:

Operational technologyCovers the same ground as
prEN 50770-1EN 304 636, firewalls and IDS/IPS
prEN 50770-2EN 304 621, network management systems
prEN 50770-3EN 304 625, network interfaces
prEN 50770-4EN 304 620, VPN products
prEN 50770-5EN 304 627, routers, modems and switches
prEN 50770-6EN 304 622, SIEM systems

The overlap is deliberate. The mandate wording for the firewall line item reaches products intended for industrial use explicitly, and an industrial firewall has a different threat model, a different installed base, and very different patching constraints than an office one.

For a manufacturer selling the same product into both markets, this may become a choice of which standard to apply, or a requirement to satisfy both. It is not a decision to make today, because neither track is cited. It is a decision to have on your radar for when they are.

Why none of this changes your route yet

Here is the part that has to be said plainly, because the existence of a V1.0.0 document with your product category in the title creates a strong and wrong impression.

Article 27(1) attaches the presumption of conformity to harmonised standards "the references of which have been published in the Official Journal of the European Union." Not to standards that exist. Not to standards that are approved. To references that have been published in the Official Journal.

No CRA standard, horizontal or vertical, has been published there. As a result the presumption of conformity is unavailable for every product category without exception.

That has a concrete cost for Annex III Class I products. Article 32(2) removes the module A self-assessment option where a manufacturer "has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes," or where such standards do not exist. With nothing cited, that last limb is satisfied today, so third-party assessment through module B and C, or module H, is the live route. Class II products are on third-party assessment under Article 32(3) regardless.

It is also worth knowing what ETSI's version numbers mean, because they are easy to over-read. A deliverable at V1.0.0 has reached an approval stage inside ETSI. The document itself is still headed "Draft". Ratification as an EN is a further step, and citation in the Official Journal under the CRA is a separate step again. Only that last one triggers Article 27.

What to do with a draft

None of this makes the drafts useless. It makes them a preview rather than a shortcut.

Read the one for your category. It tells you what your product will eventually be measured against, in more detail than Annex I ever will. That is genuinely useful information to have two years before the Regulation applies on 11 December 2027.

Build the evidence now. A technical file argued against the current drafts is far easier to migrate than one argued from scratch, because the cited version will be a descendant of what you can read today, not a fresh document.

Know which committee holds your category. If you are in one of the nine points outside the ETSI series, subscribing to ETSI updates is wasted effort. Watch CEN/TC 224 or CLC/TC 47X instead.

Do not wait. Compliance is owed on 11 December 2027 whatever the standards do, and notified body capacity is itself a scheduling constraint. The manufacturers who struggle will be the ones who treated standardisation as a reason to postpone the underlying work.

If you want to know which vertical standard applies to your product, our free classifier works out your Annex III class and conformity assessment route, and now names the vertical standard being drafted for your category alongside it.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Get Started for Free

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.