ETSI TC CYBER has published draft Cyber Resilience Act standards covering individual product categories, in an open consultation area that anyone can read. The drafts belong to the EN 304 6xx series, the vertical half of standardisation request M/606, which allocates one standard to each product category listed in Annex III of the Regulation.
The series numbers 18 deliverables in total, running from EN 304 617 for standalone and embedded browsers to EN 304 642 for telecommunications network functions. Public drafts now exist for anti-malware software, firewalls and intrusion detection systems, routers and switches, hypervisors and container runtimes, VPN products, password managers, boot managers, network interfaces, network management systems, internet-connected toys and personal wearables. The numbering follows the mandate directly, with each deliverable numbered 304 600 plus its M/606 line item.
Nine Annex III and Annex IV categories sit outside the ETSI series. Identity management and privileged access management, the semiconductor categories, smart meter gateways and smartcards are being drafted by CEN and CENELEC committees instead. A separate CENELEC series, prEN 50770, is producing operational-technology equivalents for six of the same product types on IEC 62443 foundations.
None of these standards is cited in the Official Journal of the European Union. Until a reference is published there, applying one confers no presumption of conformity under Article 27, and the conformity assessment route for an Annex III product is unchanged. What the public drafts do offer is an early view of the requirements a given product category will be measured against, which is time a manufacturer can use before the Regulation applies on 11 December 2027.