Is there a CRA harmonised standard for my product category yet?
Also asked
- Which standard applies to my Annex III Class I product?
- Is ETSI writing a CRA standard for every important product?
- What is the difference between horizontal and vertical CRA standards?
- Why are there gaps in the EN 304 numbering?
- Do I follow the ETSI standard or the operational technology one?
A draft or a work item exists for every Annex III category, and none of it is cited in the Official Journal, so the Article 27 presumption of conformity is unavailable for every product category without exception. Standardisation request M/606 splits into horizontal standards covering all products and vertical standards covering one category each. ETSI drafts most verticals as the EN 304 6xx series, where the number is 304 600 plus the mandate line item. CEN and CENELEC hold the semiconductor, smartcard, identity and metering categories.
Knowing which committee drafts your category tells you which work programme to watch. It does not change your conformity assessment route today, because nothing in either family is cited.
Key takeaways
- The European Commission issued standardisation request M/606 to CEN, CENELEC, and ETSI to draft 41 harmonised CRA standards.
- ETSI opened the approval procedure for 17 vertical standards on 13 August 2026, and that procedure closes between mid-September and mid-November 2026.
- Until harmonised standards are officially cited in the Official Journal, no presumption of conformity under Article 27 exists.
- Manufacturers can reference established baseline standards such as ETSI EN 303 645 and IEC 62443 to evidence Annex I compliance.
- Compliance must be demonstrated directly against Annex I essential requirements even in the absence of category-specific standards.
At a glance
- Standardisation request
- M/606, Commission Implementing Decision C(2025) 618 final
- Vertical standards at ETSI
- 18 deliverables, EN 304 617 to EN 304 642
- Numbering rule
- Deliverable number is 304 600 plus the M/606 line item
- Drafting body for most verticals
- ETSI TC CYBER, EUSR group
- Annex III and IV points outside ETSI
- Nine, held by CEN/TC 224, CLC/TC 47X and CEN-CLC/JTC 13 WG 6
- In ETSI approval procedure
- 17 deliverables, opened 13 August 2026 at version 1.0.0
- Approval procedure closes
- Mid-September to mid-November 2026, depending on the vertical
- Cited in the Official Journal
- None, as at 1 September 2026
Last reviewed 1 September 2026
Verified against Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 29 July 2026, with the vertical standard list and draft stages rechecked on 1 September 2026 against the ETSI press release of 13 August 2026, the ETSI Work Programme work item reports for the CYBER EUSR technical body, and the ETSI CYBER-EUSR open consultation area
Draft stages in the ETSI series move quickly and the deliverable list can change with any amendment to the standardisation request. The first Official Journal citation would materially change this answer. Check the Official Journal and the ETSI work programme directly rather than relying on any status recorded here.
Horizontal and vertical standards under M/606
Article 27(1) obliges the Commission to request harmonised standards for the Annex I essential requirements.[1] It did so through standardisation request M/606, issued by Commission Implementing Decision C(2025) 618 final and accepted by CEN, CENELEC and ETSI on 3 April 2025. The request covers 41 standards.[3][4]
They divide into two kinds, and the distinction decides which work programme is relevant to you.
Horizontal standards apply to every product with digital elements and express the essential requirements in general terms. That is the EN 40000 series from CEN-CENELEC JTC 13, covering vocabulary, cyber resilience principles, vulnerability handling and generic security requirements.
Vertical standards cover one Annex III product category each. Most went to ETSI TC CYBER, which is drafting them as the EN 304 6xx series. A manufacturer of an important product will likely need both families: the horizontal standards for the general requirements and the vulnerability handling process, and the vertical standard for what that specific product type has to do.
Which deliverable covers your category
The ETSI numbering is mechanical rather than arbitrary. A deliverable number is 304 600 plus its M/606 line item, so line item 17 for standalone and embedded browsers becomes EN 304 617, and line item 36 for firewalls and intrusion detection or prevention systems becomes EN 304 636.[5]
That rule explains the gaps. There is no EN 304 628, 629 or 630 because those line items cover microprocessors, microcontrollers and programmable circuits with security functionalities, which went to CENELEC rather than ETSI.
The categories ETSI is not covering are worth knowing early, because watching the ETSI work programme will tell a manufacturer in one of them nothing at all:
- Identity management and privileged access management, at CEN/TC 224 WG 17.
- Microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities, and their tamper-resistant variants, at CENELEC CLC/TC 47X.
- All three Annex IV critical categories: hardware devices with security boxes, smart meter gateways, and smartcards including secure elements.
The full mapping from every Annex III and Annex IV point to its standard sets out which committee holds each one.
What a draft vertical standard changes, and what it does not
Article 27(1) attaches the presumption to harmonised standards, or parts of them, the references of which have been published in the Official Journal of the European Union.[1] A draft confers nothing under that article, however closely a product follows it and however advanced the draft is.
That matters most for Annex III Class I products. Article 32(2) removes the module A self-assessment option where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial, or where such standards do not exist.[2] With nothing cited, the final limb is satisfied today for every category, so third-party assessment through module B and C or module H is the live route. Article 32(3) puts Class II products there regardless.
What a public draft does buy is a preview of the requirements. Several ETSI deliverables are open for comment, so a manufacturer can read what its category will be measured against and build the evidence now rather than after citation.[5]
What the approval procedure changed on 13 August 2026
ETSI opened the formal approval procedure for 17 of the vertical standards on 13 August 2026.[6] Each of those deliverables now carries version 1.0.0 with a cover date of 13 August 2026. Its work item status reads "Deliverable approval procedure initiated".[7]
ETSI sent the drafts to 41 member organisations. Those include the national standardisation bodies of the European Economic Area. Four societal partners may also comment. ANEC represents consumers, ECOS environmental interests, ETUC trade unions and SBS small business. The procedure closes between mid-September and mid-November 2026, and the closing date depends on the vertical.[6]
One field on each work item is worth checking yourself, because it is the only one that decides Article 27. The Official Journal field is empty on every EN 304 deliverable. A separate Harmonised Standard flag reads Yes. That flag marks a candidate for harmonisation under M/606 and is not a citation.[7]
| Stage | What it means | Confers Article 27 presumption |
|---|---|---|
| Work item | Adopted by the committee, no public draft | No |
| Mature or stable draft | Sent to the Commission for assessment | No |
| Enquiry or final draft | Open for public comment | No |
| Approval procedure initiated | Sent to the national bodies for vote | No |
| Cited in the Official Journal | Reference published under Article 27 | Yes |
Six product types are being standardised twice
Firewalls, network management systems, physical and virtual network interfaces, VPN products, routers and switches, and SIEM systems each have two deliverables in progress. Alongside the ETSI vertical, CENELEC CLC/TC 65X WG 3 is drafting the prEN 50770 series on IEC 62443 foundations, aimed at operational technology.[8]
The overlap is deliberate rather than accidental. The M/606 wording for the firewall line item reaches products intended for industrial use explicitly, and industrial deployments of these product types have a different threat model and a different installed base than their IT equivalents.
For a manufacturer selling the same product into both IT and OT markets, this may eventually become a choice of which standard to apply, or a need to satisfy both. Neither track is cited in the Official Journal, so it is a decision to revisit once citations appear rather than one to make now. What is worth doing today is reading whichever draft is closer to your market, since the underlying engineering will carry across either way.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 27(1) · CELEX:32024R2847 · OJ L, 20.11.2024
“in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union”
Accessed 2026-07-29
- [2]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 32 (Conformity assessment procedures)Binding
Publications Office of the European Union · Article 32(2) and (3) · CELEX:32024R2847
“or where such harmonised standards do not exist”
Accessed 2026-07-29
- [3]
European Commission · Standardisation request M/606, Annex I · C(2025) 618 final, request M/606
Accessed 2026-07-29
- [4]Cyber Resilience Act, standardisationCommission guidance
European Commission, DG CONNECT · Scope of request M/606 and the split between horizontal and vertical standards · As published, July 2026
A Commission policy page describing the standardisation programme. It records progress and does not create obligations.
Accessed 2026-07-29
- [5]
ETSI · EN 304 617 to EN 304 642 · Drafts at mature, enquiry and final draft stage, none cited in the Official Journal
Drafts published for public comment. A harmonised standard confers a presumption of conformity only once its reference is published in the Official Journal, and no deliverable in this series is cited.
Accessed 2026-07-29
- [6]ETSI launches approval process for 17 European Standards supporting the Cyber Resilience ActStandard
ETSI · EN 304 6xx series, 17 final drafts · Public Enquiry, closing mid-September to mid-November 2026
An ETSI press release announcing the start of an approval procedure. A harmonised standard confers a presumption of conformity only once its reference is published in the Official Journal, and no deliverable in this series is cited.
Accessed 2026-09-01
- [7]
ETSI · DEN/CYBER-EUS-006, EN 304 617 · Version 1.0.0, cover date 2026-08-13, status Deliverable approval procedure initiated
The registry ETSI maintains for its own deliverables. It records the version, the cover date, the approval status, the mandate and an Official Journal field that is empty for every EN 304 deliverable. The Harmonised Standard flag on a work item marks a candidate for harmonisation and is not a citation.
Accessed 2026-09-01
- [8]prEN 50770 series, security for operational technologies, and the prEN 50764 to prEN 50766 semiconductor deliverablesHarmonised standard
CENELEC, CLC/TC 65X WG 3 and CLC/TC 47X · prEN 50770-1 to prEN 50770-6, prEN 50764, prEN 50765, prEN 50766
Drafts under the same standardisation request, covering the categories outside the ETSI series. None is cited in the Official Journal.
Accessed 2026-07-29
Follow-up questions
Why is there no EN 304 628, 629 or 630?+
The ETSI number is 304 600 plus the M/606 line item, and line items 28, 29 and 30 cover microprocessors, microcontrollers and programmable circuits with security-related functionalities. Those went to CENELEC CLC/TC 47X rather than ETSI, so the numbers are simply unused in the ETSI series. The same explains the gap between EN 304 636 and EN 304 642.
Does a V1.0.0 ETSI draft mean the standard is finished?+
No. Seventeen EN 304 deliverables reached version 1.0.0 on 13 August 2026. That version marks the start of the approval procedure, not the end of drafting. The document is still headed as a draft. Ratification as an EN is a further step, and citation in the Official Journal is a separate one again. Only that last step triggers Article 27.
What happens when the approval procedure closes?+
A positive vote lets ETSI ratify the deliverable as an EN. The Commission then assesses it and decides whether to cite the reference in the Official Journal. Citation is a Commission act rather than an ETSI one, and it can lag ratification. Article 27 applies from the citation date. Watch the Official Journal for that step rather than the ETSI work programme.
My product is an Annex IV critical product. Is ETSI drafting my standard?+
No. All three Annex IV categories sit outside the EN 304 series. Hardware devices with security boxes and smartcards including secure elements are with CEN/TC 224 WG 17 and CENELEC CLC/TC 47X, and smart meter gateways are with CEN-CLC/JTC 13 WG 6. Annex IV products need a European cybersecurity certification scheme or a notified body regardless of standards status.
Can I read the ETSI drafts before they are published?+
Many of them, yes. ETSI TC CYBER runs an open consultation area where drafts for the EN 304 6xx series are publicly downloadable, along with commenting instructions. Coverage is partial, so some deliverables are work items with no public draft, and the paths change as drafts progress.
The provisions behind this answer
Terms used in this answer
This answer is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.