Standards & alignment

CRA vertical and horizontal standards

The Cyber Resilience Act rests on a European Commission standardization request (M/606) issued to CEN, CENELEC, and ETSI. Explore our mappings to horizontal standards (EN 40000 series) and product-specific CRA vertical standards (ETSI EN 304 series, CENELEC prEN 50770 for operational technology, and prEN 50764-50766), with transparent presumption-of-conformity status for each.

Free Product Classifier

Which vertical standard applies to your product?

Use our free classifier to check your CRA Annex III/IV class, find your Article 32 conformity route, and identify the specific ETSI EN 304 or CEN/CENELEC vertical standard drafted for your category.

Classify your product →
Regulation (EU) 2024/2847

EU Cyber Resilience Act

The regulation itself. Every requirement grouped the way the CRA groups them, the document set a manufacturer ends up with, and the product surfaces that produce them. Scope and classes, Annex I, vulnerability handling, conformity assessment, CE marking, and the Article 14 reporting clocks.

The regulationNot a conformity standard
CEN / CENELEC

EN 40000 series

The horizontal harmonised standards CEN and CENELEC are drafting for the CRA. Part-by-part overview plus full clause mapping for vulnerability handling, so you are ready for presumption of conformity once the references are cited in the Official Journal.

Draft harmonised standardsDoes not confer CRA presumption
ETSI

EN 304 6xx vertical standards

The 18 product-specific CRA standards ETSI is drafting under M/606, one per Annex III category, from browsers and password managers to firewalls and hypervisors. Includes the Annex III and Annex IV points ETSI does not cover and the CENELEC operational-technology and semiconductor alternatives.

Draft vertical standardsDoes not confer CRA presumption
ENISA

ENISA, the EUVD & Article 14

How the platform aligns with ENISA's Single Reporting Platform, the European Vulnerability Database, and national CSIRTs. Includes a live EUVD feed.

Regulatory infrastructureNot a conformity standard
ENISA

Secure by Design and Default Playbook

All 22 ENISA playbooks with their full release gates, mapped to CRA Annex I using ENISA's own Annex C, plus the requirements that rest on a single playbook.

Guidance, not a standardDoes not confer CRA presumption
ETSI

ETSI EN 303 645

The consumer-IoT security baseline that accredited labs test against. All 13 provisions mapped to CRA Annex I evidence.

Supporting standardDoes not confer CRA presumption
ISO/IEC · IEC

ISO/IEC 27001 & IEC 62443

The ISMS and industrial-security standards manufacturers most often already hold, mapped to CRA process and product requirements.

Supporting standardsDoes not confer CRA presumption
ISO/IEC

ISO/IEC 29147

The international standard for vulnerability disclosure, paired with ISO/IEC 30111 for internal handling. Each phase mapped to the Annex I vulnerability handling requirements, from receiving a report to publishing an advisory.

Supporting standardDoes not confer CRA presumption
NIST / OSCAL

OSCAL catalog

The CRA vulnerability-handling requirements expressed as a machine-readable OSCAL catalog for automated compliance tooling.

Machine-readable catalogNot a conformity standard
ENISA

Machine-processable attestation

Section 5 of the ENISA playbook: the control, implementation and assessment cascade, why the sensitive half belongs behind an authenticated endpoint, and the eleven formats in the ecosystem. Defines no schema, by design.

Illustrative guidanceDoes not confer CRA presumption
CRA Article 32

Notified bodies & testing labs

Directory of EU conformity-assessment bodies and cybersecurity testing laboratories, filterable by country and standard. Verify designation in NANDO.

Ecosystem directoryNot a conformity standard

Free, and not ours

The standards bodies run free CRA workshops for SMEs

CEN, CENELEC and ETSI, financed by the EU and EFTA under the STAN4CR projects run the CRA Standards Unlocked programme. The sessions explain the standardisation work above to manufacturers without a compliance team, and they cover how to comment on a draft while it is still open. Attendance is free. We do not run these and take no registration.

  • 2026-09-17Lisbon, Portugal09:00 to 17:00Details
  • 2026-09-21Nicosia, Cyprus09:00 to 16:15Details
  • 2026-10-01The Hague, Netherlands09:30 to 17:00Details
  • 2026-10-07Bonn, Germany09:00 to 17:00Details

Checked 2026-09-01against the programme's own events page. Sessions are added through the year, so see the full programme for anything after the dates above.

One platform across the whole standards stack

Threat modelling, SBOM tracking, vulnerability handling, Article 14 reporting, and technical-file assembly, all mapped to the standards above.