← CRA FAQConformity and CE marking

Do I have to wait for the EN 40000 standards before I can comply with the CRA?

Also asked

  • Can I CE mark a product before the CRA harmonised standards exist?
  • Does applying a draft prEN 40000 give presumption of conformity?
  • Do I need a notified body because the CRA harmonised standards are missing?
  • Which standards should I use until EN 40000 is cited?
  • What happens if EN 40000 is not ready before December 2027?

Waiting is the wrong plan. No part of the EN 40000 series has been cited in the Official Journal, so the Article 27 presumption of conformity is unavailable, and Article 32(2) escalates a Class I important product to third-party assessment precisely where a manufacturer has not applied a harmonised standard or where none exists. Compliance is owed from 11 December 2027 whatever the standards do. The series is drafted under Commission standardisation request M/606, with parts 1-1, 1-2 and 1-3 past public enquiry and awaiting approval.

Applying the current drafts, and the recognised standards they build on, is the low-regret path. A technical file argued against those is far easier to migrate than one argued from scratch.

At a glance

Standardisation request
M/606, Commission Implementing Decision C(2025) 618 final
Accepted by the ESOs
3 April 2025, by CEN, CENELEC and ETSI
Scope of the request
41 standards, horizontal and product-specific
Horizontal drafting body
CEN-CLC/JTC 13 WG 9
Cited in the Official Journal
None, as at 27 July 2026
Effect of that
No presumption of conformity under Article 27

Last reviewed 27 July 2026

Verified against Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026, with series status checked against CEN-CENELEC and the Commission standardisation page on the same date

The status of the EN 40000 parts changes as they move through approval, and the first Official Journal citation would materially change this answer. Treat the status section as accurate on its review date and check the Official Journal directly.

What is the EN 40000 series and who is drafting it?

Article 27(1) obliges the Commission to ask one or more European standardisation organisations to draft harmonised standards for the Annex I essential cybersecurity requirements.[1] It did so through standardisation request M/606, issued by Commission Implementing Decision C(2025) 618 final of 3 February 2025 and accepted by CEN, CENELEC and ETSI on 3 April 2025. The request covers 41 standards, split between horizontal standards that apply to every product with digital elements and vertical standards for specific product categories, with priority given to the important and critical categories in Annexes III and IV.[4][5]

EN 40000 is the horizontal family. It is drafted by CEN-CLC/JTC 13 WG 9 and is structured in parts:

  • prEN 40000-1-1, vocabulary and terminology across the series.
  • prEN 40000-1-2, principles for cyber resilience, covering the risk methodology and lifecycle activities behind Annex I Part I.
  • prEN 40000-1-3, vulnerability handling, mapping to Annex I Part II.
  • prEN 40000-1-4, generic security requirements, the catalogue mapping to the Annex I Part I requirements.
  • TR 40000-1-5, a Technical Report on threats and security objectives. It is informative rather than normative.[6]

The part-by-part breakdown covers what each one contains. This answer is about whether their absence blocks you.

CRA referenceArticle 27(1)

What does citation in the Official Journal actually buy you?

Article 27(1) is precise about the trigger. Products and processes in conformity with harmonised standards, or parts of them, the references of which have been published in the Official Journal of the European Union, are presumed to conform to the essential requirements in Annex I covered by those standards.[1]

Two consequences follow from that wording.

The presumption attaches to publication of the reference in the Official Journal, not to a standard existing, being approved, or being useful. A draft carrying the pr prefix confers nothing under Article 27, however closely a product follows it.

The presumption is also partial. It reaches only the requirements the cited standard covers. Since the EN 40000 parts are horizontal and split across Annex I Part I and Part II, no single part will ever cover the whole of Annex I, and a manufacturer will still have to argue the remainder directly.

Presumption of conformity is an evidentiary shortcut. Its absence removes the shortcut and leaves the obligation intact.

CRA referenceArticle 27(1)

What waiting actually costs, under Article 32

For most products the answer is the assessment route, and it is a budget question rather than a paperwork one.

Article 32(1) lets a manufacturer demonstrate conformity through the internal control procedure based on module A, which is self-assessment, among other routes. Article 32(2) then removes that option for important products in Annex III Class I in a specific circumstance. Where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least substantial, or where such standards do not exist, the product has to go through EU-type examination (module B followed by module C) or full quality assurance (module H).[2]

Read that against the current state of the series. No CRA harmonised standard is cited, so for Annex III Class I products the "where such harmonised standards do not exist" limb is satisfied today, and third-party assessment is the live route. Article 32(3) puts Class II products on third-party assessment regardless.[2]

So waiting does not defer the work. It defers the option of avoiding a notified body, and notified body capacity is itself a scheduling constraint ahead of 11 December 2027.[3]

One route out is worth knowing. Article 32(5) allows a manufacturer of an Annex III product qualifying as free and open source software to use any Article 32(1) procedure, including module A, provided the Article 31 technical documentation is made public when the product is placed on the market.[2]

CRA referenceArticle 32(1), (2), (3) and (5)

Which standards carry weight before EN 40000 is cited?

Conformity still has to be demonstrated, and a technical file argued against recognised standards is the strongest available evidence short of a presumption. The practical set:

  • ETSI EN 303 645 for consumer IoT. Baseline provisions widely referenced in Europe and a natural fit for Annex I Part I arguments on consumer products.[7]
  • IEC 62443-4-1 for the secure product development lifecycle and IEC 62443-4-2 for component security requirements, drawn from industrial automation and control systems.[8]
  • ISO/IEC 29147 for vulnerability disclosure and ISO/IEC 30111 for vulnerability handling. These are the base standards behind the Annex I Part II process requirements.[9]
  • BSI TR-03183, parts 1 to 3, the most concrete official mapping to CRA obligations published by a national authority, covering general requirements, SBOM and vulnerability report intake.[10]
  • EN 18031, harmonised under the Radio Equipment Directive delegated regulation. Already citable for radio equipment and a likely input to the CRA product standards.[11]

None of these confers presumption of conformity under the CRA. What they buy is a defensible file and a migration path, because the harmonised set is being built on the same material.

The risk assessment is the piece to start with regardless of standards, since Article 13(3) makes it the thing that determines which Annex I requirements apply to your product in the first place.

CRA referenceAnnex I, Article 13(3)

Where the parts stand today

As at 27 July 2026, parts 1-1, 1-2 and 1-3 have completed their CEN public enquiry and sit in approval. Part 1-4 remains in development, with a target of 30 October 2027. Delivery of EN 40000-1-2 and EN 40000-1-3 has been indicated for the second half of 2026.[6][5]

No CRA harmonised standard has been ratified as an EN or had its reference published in the Official Journal, so the Article 27 presumption is available for no product category.[1]

The gap between the 30 October 2027 target for the later deliverables and the 11 December 2027 application date is about six weeks. That is not enough time to build a technical file from nothing, which is the practical reason the wait-and-see plan fails even if every deadline is met.[3]

Status here moves. Check the Official Journal citations directly rather than working from any draft list, including this one.

CRA referenceArticle 27, Article 71(2)

What if the standards are not cited before December 2027?

The obligation does not move. Article 71(2) applies the Regulation from 11 December 2027, and Article 27 offers a presumption rather than a precondition. A manufacturer demonstrates conformity with Annex I by whatever evidence it can stand behind, and the technical documentation under Article 31 and Annex VII is where that argument lives.[3][1]

The Regulation anticipates the standards being late. Article 27(2) empowers the Commission to adopt implementing acts establishing common specifications covering technical requirements that provide a means to comply with Annex I, and it may do so where a standardisation request has not been accepted, where the requested standard is not delivered within the deadline, or where the resulting standard does not satisfy the request.[1] Common specifications carry the same presumption of conformity as a cited harmonised standard.

A second route runs through certification. Article 27 extends the presumption, to the extent specified, to European cybersecurity certification schemes adopted under Regulation (EU) 2019/881. A delegated act setting out the presumption granted by the EUCC scheme has been signalled for late 2026.[1][5]

None of those fallbacks helps a manufacturer that has not done the underlying work. Each one is a shortcut for demonstrating conformity that already exists.

CRA referenceArticle 27(1) and (2), Article 71(2)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 27(1) and (2) · CELEX:32024R2847 · OJ L, 20.11.2024

    in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union

    Accessed 2026-07-27

  2. [2]

    Publications Office of the European Union · Article 32(1), (2), (3) and (5) · CELEX:32024R2847

    the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes

    Accessed 2026-07-27

  3. [3]

    Publications Office of the European Union · Article 71(2) · CELEX:32024R2847

    This Regulation shall apply from 11 December 2027

    Accessed 2026-07-27

  4. [4]

    European Commission · Standardisation request M/606, Annex · C(2025) 618 final, request M/606

    Accessed 2026-07-27

  5. [5]

    European Commission, DG CONNECT · Scope of request M/606 and priority product categories · As published, July 2026

    A Commission policy page describing the standardisation programme. It records progress and does not create obligations.

    Accessed 2026-07-27

  6. [6]

    CEN-CENELEC, CEN-CLC/JTC 13 WG 9 · Series status and drafting committee · prEN 40000-1-1 to 1-4, TR 40000-1-5 · Drafts. Parts 1-1, 1-2 and 1-3 past enquiry, none cited in the Official Journal

    A harmonised standard confers a presumption of conformity only once its reference is published in the Official Journal. No part of this series is cited yet.

    Accessed 2026-07-27

  7. [7]

    ETSI · ETSI EN 303 645

    Not harmonised under the CRA. Useful evidence in a technical file and no presumption of conformity.

    Accessed 2026-07-27

  8. [8]

    International Electrotechnical Commission · IEC 62443-4-1, IEC 62443-4-2

    An international standard with no harmonised status under the CRA. Alignment is evidence of a sound process and confers no presumption of conformity.

    Accessed 2026-07-27

  9. [9]

    ISO/IEC JTC 1/SC 27 · ISO/IEC 29147:2018, ISO/IEC 30111:2019

    The base process standards behind the Annex I Part II requirements. Not harmonised under the CRA.

    Accessed 2026-07-27

  10. [10]

    Bundesamt für Sicherheit in der Informationstechnik · BSI TR-03183

    Guidance from a national authority. It maps closely to CRA obligations and carries no presumption of conformity.

    Accessed 2026-07-27

  11. [11]

    CEN-CENELEC · EN 18031-1, EN 18031-2, EN 18031-3

    Harmonised under the Radio Equipment Directive delegated regulation, not under the CRA. It confers no CRA presumption of conformity.

    Accessed 2026-07-27

Follow-up questions

Does following a draft prEN 40000 give me presumption of conformity?+

No. Article 27(1) attaches the presumption to harmonised standards whose references have been published in the Official Journal. A pr prefix marks a proposed European Norm that has not been ratified, so following one closely is good evidence in a technical file and confers no presumption.

What is the difference between prEN 40000 and EN 40000?+

The pr prefix marks a draft. Once a part is approved and ratified it drops the prefix and becomes EN 40000. Ratification alone is still not enough for Article 27. The reference also has to be cited in the Official Journal of the European Union under the CRA.

Are common specifications a realistic fallback if the standards slip?+

Article 27(2) allows the Commission to adopt them by implementing act, but only once specific conditions are met, including a standardisation request that was not accepted, not delivered on time, or answered with a standard that does not satisfy the request. They are a contingency the Regulation holds in reserve rather than a parallel track to plan around.

Does EN 18031 help with CRA compliance?+

Indirectly. EN 18031 is harmonised under the Radio Equipment Directive delegated regulation and confers presumption of conformity there, not under the CRA. For radio equipment already assessed against it, the evidence and much of the engineering carry over into a CRA technical file, and the series is a likely input to the CRA product standards.

Which EN 40000 part covers vulnerability handling?+

prEN 40000-1-3 covers vulnerability handling and maps to the Annex I Part II obligations. prEN 40000-1-2 covers the principles behind the Annex I Part I product requirements, and prEN 40000-1-4 is the catalogue of generic security requirements mapping to Part I.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.