[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:harmonised-standards-for-the-cra-what-request-m-606-asks-for-when-and-what-a-manufacturer-has-today":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","harmonised-standards-for-the-cra-what-request-m-606-asks-for-when-and-what-a-manufacturer-has-today","Harmonised standards for the CRA: what request M\u002F606 asks for, when, and what a manufacturer has today","Article 27 gives a presumption of conformity to products that follow harmonised standards cited in the Official Journal. On 3 February 2025 the Commission asked CEN, CENELEC and ETSI for 41 of them, with deadlines from 30 August 2026 to 30 October 2027; the three accepted on 3 April 2025. On 12 September 2026 the Commission's index of harmonised standards still has no entry for the Regulation, which for a class I product means no self-assessment route under Article 32(2). What was requested, the dates, and what to build against in the meantime.","2026-09-12","\nEvery conformity assessment under Regulation (EU) 2024\u002F2847 comes back to a question the Regulation cannot answer by itself: against which technical text is the product assessed? Annex I sets essential requirements in a sentence each, and Article 27 says how they become checkable: \"products with digital elements and processes put in place by the manufacturer which are in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I covered by those standards or parts thereof\". The presumption needs three things: a standard, drafted on the Commission's request; its adoption by a European standardisation organisation; and its citation in the Official Journal. This article is where each of the three stands, read from the request itself and from the bodies that accepted it.\n\n## The request\n\nCommission Implementing Decision C(2025) 618 of 3 February 2025 is the standardisation request, M\u002F606 in the Commission's numbering, addressed to CEN, CENELEC and ETSI under Article 10(1) of Regulation (EU) No 1025\u002F2012. Article 1 of the Decision asks for the European standards \"listed in Annex I to this Decision, in support of the Cyber Resilience Act by the deadlines set out in that Annex\": 41 entries, of which entries 1 to 15 and 39 to 41 are for CEN and CENELEC and entries 16 to 38 are to be developed jointly by CEN, CENELEC and ETSI. Article 4 makes the three report on progress every six months until every draft reaches the enquiry stage, then annually, with a final joint report by 30 October 2027; Article 5 makes the Decision expire on 30 November 2027. CEN and CENELEC announced on 1 May 2025 that the three organisations had accepted the request on 3 April 2025, \"committed to delivering harmonized standards well in advance, at least one year before the CRA enters into application\".\n\nThe 41 entries are of three kinds. The Commission's own FAQ on the Regulation, question 6.10 in version 1.4 of 4 September 2026, says the 15 horizontal standards have been clustered by the standardisation organisations into three deliverables, two due by 30 August 2026 and one by 30 October 2027, and that the 26 vertical standards, addressed through 31 separate deliverables, are due by 30 October 2026; CEN and CENELEC's workshop of 9 April 2025 gave the same dates entry by entry:\n\n| Entries | What they are | Who drafts | Deadline |\n| --- | --- | --- | --- |\n| 1 | The horizontal framework: \"Cybersecurity requirements for products with digital elements, principles for cyber resilience\", covering Annex I Part I point 1 | CEN and CENELEC, JTC 13 WG 9 | 30 August 2026 |\n| 2 to 14 | The generic security requirements, one per point of Annex I Part I point 2, letters (a) to (m) | CEN and CENELEC, JTC 13 WG 9 | 30 October 2027 |\n| 15 | Vulnerability handling, covering Annex I Part II points 1 to 8 | CEN and CENELEC, JTC 13 WG 9 | 30 August 2026 |\n| 16 to 38 | The vertical standards for the important products of Annex III, class I and class II | CEN, CENELEC and ETSI jointly | 30 October 2026 |\n| 39 to 41 | The vertical standards for the critical products of Annex IV | CEN and CENELEC | 30 October 2026 |\n\nTwo dates in that table matter more than the rest. The two horizontal standards with the earliest deadline, the framework and vulnerability handling, are the ones every conformity assessment will lean on for every product, and their deadline was 30 August 2026. The vertical standards for the class I and class II categories are due on 30 October 2026, thirteen months before the Regulation applies in full on 11 December 2027. Adoption by the organisations is not citation: Article 27(6) has the Commission assess each adopted standard under Regulation (EU) No 1025\u002F2012 before publishing its reference, and only the publication gives the presumption.\n\n## What exists on 12 September 2026\n\nThe Commission publishes, for every act that has one, a page listing the harmonised standards cited in the Official Journal under it; the index of those pages lists dozens of acts, the Machinery Regulation, the Radio Equipment Directive and the Low Voltage Directive among them. On 12 September 2026 it has no page for the Cyber Resilience Act. Whatever CEN and CENELEC delivered on the 30 August deadline, no reference to a harmonised standard under Regulation (EU) 2024\u002F2847 has been published in the Official Journal, and Article 27's presumption of conformity is available for no product. StandardOS rechecks that index monthly; the day a page appears, this sentence is corrected.\n\nThat is not a gap the Regulation left unguarded. Article 27(2) lets the Commission adopt common specifications by implementing act where a request \"has not been accepted\", where the standards \"are not delivered within the deadline\", or where they \"do not comply with the request\", and no reference \"is expected to be published within a reasonable period\". No common specification has been adopted. The request was accepted, so the first of those conditions is closed; whether the second is met for the two horizontal standards depends on what the organisations delivered by 30 August 2026, which their six-monthly reports to the Commission will say.\n\n## What the absence means for each tier\n\nFor a default-tier product the absence costs a shortcut, not a route. Article 32(1) lets the manufacturer assess conformity under module A, the internal control procedure of Annex VIII, whether or not a harmonised standard exists; the standard would have made the assessment presumptive, and without it the manufacturer documents conformity with each Annex I requirement against the state of the art it chose. [What module A actually requires is its own article](\u002Farticles\u002Fself-assessment-under-the-cra-what-module-a-actually-requires).\n\nFor an important product of class I the absence closes the route. Article 32(2) sends a class I product to a notified body, modules B and C or module H, where the manufacturer \"has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes\" or \"where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist\". They do not exist. A manufacturer of a password manager, a VPN client, a router or any other class I category therefore has, today, only the third-party route to conformity, and [the register of notified bodies under the Regulation was empty when it was read](\u002Farticles\u002Fthe-eu-s-own-cra-machinery-on-the-day-the-duty-started). Both will change before 11 December 2027, or the tier will be unassessable on that day; which of the two changes first decides whether a class I manufacturer needs a notified body's calendar or a standard's text.\n\nFor class II and critical products nothing changes: a notified body or a certification scheme was always the route (Article 32(3) and (4)).\n\n## What to build against in the meantime\n\nThe essential requirements of Annex I apply from 11 December 2027 whether or not a standard exists, and Article 13's risk assessment is due for every product regardless of tier. The request tells a manufacturer what the standards will be built from: the framework standard covers Annex I Part I point 1, the generic requirements cover the thirteen letters of point 2, and the vulnerability handling standard covers the eight points of Part II, so a technical file organised by those points today will map onto the standards when they are cited. The Commission's FAQ says at 4.1.7 that the use of harmonised standards is voluntary and that a manufacturer may demonstrate conformity by other technical means, documented in the technical file; the CEN and CENELEC drafts, once at enquiry stage, are public on the national standards bodies' enquiry portals. [Annex I as a checklist](\u002Farticles\u002Fcra-annex-i-the-22-essential-requirements-as-a-checklist) and [what goes in the technical file](\u002Farticles\u002Fwhat-goes-in-the-cra-technical-file-annex-vii-point-by-point) are the two pieces to build from; [the tiers, and which categories are class I](\u002Farticles\u002Fis-your-product-important-or-critical-under-the-cyber-resilience-act), decide whether the absence is a shortcut lost or a route closed.\n\n## Sources\n\n- Regulation (EU) 2024\u002F2847 (CRA), Article 13, Article 27(1), (2) and (6), Article 32(1) to (4), Article 71(2), Annex I, Annex VIII.\n- Commission Implementing Decision C(2025) 618 of 3 February 2025 on a standardisation request to CEN, Cenelec and ETSI as regards products with digital elements, Articles 1, 4 and 5.\n- European Commission, FAQs on the Cyber Resilience Act, version 1.4 of 4 September 2026, questions 4.1.7 and 6.10.\n- CEN and CENELEC, \"Cyber Resilience Act: Standardization Request Officially Accepted by CEN, CENELEC, and ETSI\", posted 1 May 2025; CEN and CENELEC workshop \"Cyber Resilience Act and the horizontal standards\", 9 April 2025, for the categories and deadlines; STAN4CR, the ESOs' CRA standardisation site, for the topics assigned to JTC 13 WG 9.\n- European Commission, harmonised standards by legislation, read on 12 September 2026.\n\nThis is not legal advice. Deadlines in a standardisation request bind the standardisation organisations, not manufacturers; the dates that bind manufacturers are the Regulation's.\n",1789383983467]