ETSI drafts standards to aid CRA compliance
- August 18, 2026
- Steve Rogerson

European standards body ETSI has created 17 vertical final draft standards to help companies demonstrate compliance with the EU Cyber Resilience Act (CRA).
These standards aim to become harmonised standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called presumption of conformity.
The EN 304 xxx series standards on cyber-security requirements have been submitted to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure.
The approval procedure will run from mid-September to mid-November 2026, depending on the vertical.
The standards apply to connected products with digital elements, including products exposed to a higher risk of compromise, such as password managers, anti-virus software, smart home assistants, connected toys and wearables.
“The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how,” said Sandra Feliciano, chair of the ETSI working group responsible for developing the CRA standards. “The role of the standards developing organisations is to detail the technical aspects of how to achieve compliance with the legislation through standards.”
For many small and medium enterprises, the challenge is not understanding that the CRA applies to them, but knowing how to comply in practice, which standards to follow, and which tools, guidance and funding opportunities are available to support compliance. Therefore, to help SMEs understand, prepare for and comply with the CRA, while translating regulatory requirements into practical guidance and tools and providing information on the ongoing standardisation process and opportunities to participate in open consultations, CEN, Cenelec and ETSI, the three European standards organisations, have organised a series of workshops across Europe, the CRA Standards Unlocked EU Tour (www.stan4cra.eu/events).
As the CRA applies to all products with digital elements, stakeholders including manufacturers, importers, distributors, service providers and developers of commercially available hardware and software products will be required to comply with the CRA by the end of 2027. Etsi standards play a fundamental role in helping manufacturers demonstrate compliance with the CRA and ensure consistent implementation across the EU.
The 17 fnal draft standards under public enquiry are publicly available at docbox.etsi.org/CYBER/EUSR/Open and on the ETSI web site (www.etsi.org).









