CRA vertical and horizontal standards
The Cyber Resilience Act rests on a European Commission standardization request (M/606) issued to CEN, CENELEC, and ETSI. Explore our mappings to horizontal standards (EN 40000 series) and product-specific CRA vertical standards (ETSI EN 304 series, CENELEC prEN 50770 for operational technology, and prEN 50764-50766), with transparent presumption-of-conformity status for each.
Free Product Classifier
Which vertical standard applies to your product?
Use our free classifier to check your CRA Annex III/IV class, find your Article 32 conformity route, and identify the specific ETSI EN 304 or CEN/CENELEC vertical standard drafted for your category.
EU Cyber Resilience Act
The regulation itself. Every requirement grouped the way the CRA groups them, the document set a manufacturer ends up with, and the product surfaces that produce them. Scope and classes, Annex I, vulnerability handling, conformity assessment, CE marking, and the Article 14 reporting clocks.
EN 40000 series
The horizontal harmonised standards CEN and CENELEC are drafting for the CRA. Part-by-part overview plus full clause mapping for vulnerability handling, so you are ready for presumption of conformity once the references are cited in the Official Journal.
EN 304 6xx vertical standards
The 18 product-specific CRA standards ETSI is drafting under M/606, one per Annex III category, from browsers and password managers to firewalls and hypervisors. Includes the Annex III and Annex IV points ETSI does not cover and the CENELEC operational-technology and semiconductor alternatives.
ENISA, the EUVD & Article 14
How the platform aligns with ENISA's Single Reporting Platform, the European Vulnerability Database, and national CSIRTs. Includes a live EUVD feed.
Secure by Design and Default Playbook
All 22 ENISA playbooks with their full release gates, mapped to CRA Annex I using ENISA's own Annex C, plus the requirements that rest on a single playbook.
ETSI EN 303 645
The consumer-IoT security baseline that accredited labs test against. All 13 provisions mapped to CRA Annex I evidence.
ISO/IEC 27001 & IEC 62443
The ISMS and industrial-security standards manufacturers most often already hold, mapped to CRA process and product requirements.
ISO/IEC 29147
The international standard for vulnerability disclosure, paired with ISO/IEC 30111 for internal handling. Each phase mapped to the Annex I vulnerability handling requirements, from receiving a report to publishing an advisory.
OSCAL catalog
The CRA vulnerability-handling requirements expressed as a machine-readable OSCAL catalog for automated compliance tooling.
Machine-processable attestation
Section 5 of the ENISA playbook: the control, implementation and assessment cascade, why the sensitive half belongs behind an authenticated endpoint, and the eleven formats in the ecosystem. Defines no schema, by design.
Notified bodies & testing labs
Directory of EU conformity-assessment bodies and cybersecurity testing laboratories, filterable by country and standard. Verify designation in NANDO.
Free, and not ours
The standards bodies run free CRA workshops for SMEs
CEN, CENELEC and ETSI, financed by the EU and EFTA under the STAN4CR projects run the CRA Standards Unlocked programme. The sessions explain the standardisation work above to manufacturers without a compliance team, and they cover how to comment on a draft while it is still open. Attendance is free. We do not run these and take no registration.
- 2026-09-17Lisbon, Portugal09:00 to 17:00Details
- 2026-09-21Nicosia, Cyprus09:00 to 16:15Details
- 2026-10-01The Hague, Netherlands09:30 to 17:00Details
- 2026-10-07Bonn, Germany09:00 to 17:00Details
Checked 2026-09-01against the programme's own events page. Sessions are added through the year, so see the full programme for anything after the dates above.
One platform across the whole standards stack
Threat modelling, SBOM tracking, vulnerability handling, Article 14 reporting, and technical-file assembly, all mapped to the standards above.