Is there a CRA harmonised standard for my product category yet?
Also asked
- Which standard applies to my Annex III Class I product?
- Is ETSI writing a CRA standard for every important product?
- What is the difference between horizontal and vertical CRA standards?
- Why are there gaps in the EN 304 numbering?
- Do I follow the ETSI standard or the operational technology one?
A draft or a work item exists for every Annex III category, and none of it is cited in the Official Journal, so the Article 27 presumption of conformity is unavailable for every product category without exception. Standardisation request M/606 splits into horizontal standards covering all products and vertical standards covering one category each. ETSI drafts most verticals as the EN 304 6xx series, where the number is 304 600 plus the mandate line item. CEN and CENELEC hold the semiconductor, smartcard, identity and metering categories.
Knowing which committee drafts your category tells you which work programme to watch. It does not change your conformity assessment route today, because nothing in either family is cited.
At a glance
- Standardisation request
- M/606, Commission Implementing Decision C(2025) 618 final
- Vertical standards at ETSI
- 18 deliverables, EN 304 617 to EN 304 642
- Numbering rule
- Deliverable number is 304 600 plus the M/606 line item
- Drafting body for most verticals
- ETSI TC CYBER, EUSR group
- Annex III and IV points outside ETSI
- Nine, held by CEN/TC 224, CLC/TC 47X and CEN-CLC/JTC 13 WG 6
- Cited in the Official Journal
- None, as at 29 July 2026
Last reviewed 29 July 2026
Verified against Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 29 July 2026, with the vertical standard list and draft stages checked against the ETSI CYBER-EUSR open consultation area and the Commission standardisation page on the same date
Draft stages in the ETSI series move quickly and the deliverable list can change with any amendment to the standardisation request. The first Official Journal citation would materially change this answer. Check the Official Journal and the ETSI work programme directly rather than relying on any status recorded here.
Horizontal and vertical standards under M/606
Article 27(1) obliges the Commission to request harmonised standards for the Annex I essential requirements.[1] It did so through standardisation request M/606, issued by Commission Implementing Decision C(2025) 618 final and accepted by CEN, CENELEC and ETSI on 3 April 2025. The request covers 41 standards.[3][4]
They divide into two kinds, and the distinction decides which work programme is relevant to you.
Horizontal standards apply to every product with digital elements and express the essential requirements in general terms. That is the EN 40000 series from CEN-CENELEC JTC 13, covering vocabulary, cyber resilience principles, vulnerability handling and generic security requirements.
Vertical standards cover one Annex III product category each. Most went to ETSI TC CYBER, which is drafting them as the EN 304 6xx series. A manufacturer of an important product will likely need both families: the horizontal standards for the general requirements and the vulnerability handling process, and the vertical standard for what that specific product type has to do.
Which deliverable covers your category
The ETSI numbering is mechanical rather than arbitrary. A deliverable number is 304 600 plus its M/606 line item, so line item 17 for standalone and embedded browsers becomes EN 304 617, and line item 36 for firewalls and intrusion detection or prevention systems becomes EN 304 636.[5]
That rule explains the gaps. There is no EN 304 628, 629 or 630 because those line items cover microprocessors, microcontrollers and programmable circuits with security functionalities, which went to CENELEC rather than ETSI.
The categories ETSI is not covering are worth knowing early, because watching the ETSI work programme will tell a manufacturer in one of them nothing at all:
- Identity management and privileged access management, at CEN/TC 224 WG 17.
- Microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities, and their tamper-resistant variants, at CENELEC CLC/TC 47X.
- All three Annex IV critical categories: hardware devices with security boxes, smart meter gateways, and smartcards including secure elements.
The full mapping from every Annex III and Annex IV point to its standard sets out which committee holds each one.
What a draft vertical standard changes, and what it does not
Article 27(1) attaches the presumption to harmonised standards, or parts of them, the references of which have been published in the Official Journal of the European Union.[1] A draft confers nothing under that article, however closely a product follows it and however advanced the draft is.
That matters most for Annex III Class I products. Article 32(2) removes the module A self-assessment option where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial, or where such standards do not exist.[2] With nothing cited, the final limb is satisfied today for every category, so third-party assessment through module B and C or module H is the live route. Article 32(3) puts Class II products there regardless.
What a public draft does buy is a preview of the requirements. Several ETSI deliverables are open for comment, so a manufacturer can read what its category will be measured against and build the evidence now rather than after citation.[5]
Six product types are being standardised twice
Firewalls, network management systems, physical and virtual network interfaces, VPN products, routers and switches, and SIEM systems each have two deliverables in progress. Alongside the ETSI vertical, CENELEC CLC/TC 65X WG 3 is drafting the prEN 50770 series on IEC 62443 foundations, aimed at operational technology.[6]
The overlap is deliberate rather than accidental. The M/606 wording for the firewall line item reaches products intended for industrial use explicitly, and industrial deployments of these product types have a different threat model and a different installed base than their IT equivalents.
For a manufacturer selling the same product into both IT and OT markets, this may eventually become a choice of which standard to apply, or a need to satisfy both. Neither track is cited in the Official Journal, so it is a decision to revisit once citations appear rather than one to make now. What is worth doing today is reading whichever draft is closer to your market, since the underlying engineering will carry across either way.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 27(1) · CELEX:32024R2847 · OJ L, 20.11.2024
“in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union”
Accessed 2026-07-29
- [2]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 32 (Conformity assessment procedures)Binding
Publications Office of the European Union · Article 32(2) and (3) · CELEX:32024R2847
“or where such harmonised standards do not exist”
Accessed 2026-07-29
- [3]
European Commission · Standardisation request M/606, Annex I · C(2025) 618 final, request M/606
Accessed 2026-07-29
- [4]Cyber Resilience Act, standardisationCommission guidance
European Commission, DG CONNECT · Scope of request M/606 and the split between horizontal and vertical standards · As published, July 2026
A Commission policy page describing the standardisation programme. It records progress and does not create obligations.
Accessed 2026-07-29
- [5]
ETSI · EN 304 617 to EN 304 642 · Drafts at mature, enquiry and final draft stage, none cited in the Official Journal
Drafts published for public comment. A harmonised standard confers a presumption of conformity only once its reference is published in the Official Journal, and no deliverable in this series is cited.
Accessed 2026-07-29
- [6]prEN 50770 series, security for operational technologies, and the prEN 50764 to prEN 50766 semiconductor deliverablesHarmonised standard
CENELEC, CLC/TC 65X WG 3 and CLC/TC 47X · prEN 50770-1 to prEN 50770-6, prEN 50764, prEN 50765, prEN 50766
Drafts under the same standardisation request, covering the categories outside the ETSI series. None is cited in the Official Journal.
Accessed 2026-07-29
Follow-up questions
Why is there no EN 304 628, 629 or 630?+
The ETSI number is 304 600 plus the M/606 line item, and line items 28, 29 and 30 cover microprocessors, microcontrollers and programmable circuits with security-related functionalities. Those went to CENELEC CLC/TC 47X rather than ETSI, so the numbers are simply unused in the ETSI series. The same explains the gap between EN 304 636 and EN 304 642.
Does a V1.0.0 ETSI draft mean the standard is finished?+
No. An ETSI version number in the 1.0.x range marks a deliverable that has reached an approval stage, and the document itself is still headed as a draft. Ratification as an EN is a further step, and citation in the Official Journal under the CRA is a separate one again. Only that last step triggers Article 27.
My product is an Annex IV critical product. Is ETSI drafting my standard?+
No. All three Annex IV categories sit outside the EN 304 series. Hardware devices with security boxes and smartcards including secure elements are with CEN/TC 224 WG 17 and CENELEC CLC/TC 47X, and smart meter gateways are with CEN-CLC/JTC 13 WG 6. Annex IV products need a European cybersecurity certification scheme or a notified body regardless of standards status.
Can I read the ETSI drafts before they are published?+
Many of them, yes. ETSI TC CYBER runs an open consultation area where drafts for the EN 304 6xx series are publicly downloadable, along with commenting instructions. Coverage is partial, so some deliverables are work items with no public draft, and the paths change as drafts progress.
The provisions behind this answer
Terms used in this answer
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.