What are CRA harmonised standards?
CRA harmonised standards are European standards drafted by CEN, CENELEC and ETSI at the request of the European Commission (standardisation request M/606) that, once cited in the Official Journal of the EU, give manufacturers a presumption of conformity with the essential requirements of the Cyber Resilience Act. If you apply such a standard in full, you do not have to prove from scratch that your product meets the parts of Annex I of Regulation (EU) 2024/2847 that the standard covers. For OT vendors, these standards will decide how a PLC, an industrial router or a firewall earns its CE marking.
๐ง How does a harmonised standard work under the New Legislative Framework?
The CRA follows the New Legislative Framework (NLF), the same model used by the Machinery Regulation and the Radio Equipment Directive. The law itself only describes what a product must achieve: the essential requirements. How you meet them technically is laid down in standards.
The mechanism has four steps:
- Standardisation request โ the Commission asks the European standardisation organisations to produce standards on defined subjects
- Development โ technical committees draft the standards, followed by a public enquiry and a formal vote through national standards bodies such as BSI, DIN or NEN
- Assessment โ the Commission checks whether the standard actually covers the requested requirements
- Citation โ only once its reference is published in the Official Journal (OJEU) does the presumption of conformity under Article 27 apply
A standard that has been published but not cited is still useful as technical evidence, yet it carries no legal presumption. Where suitable standards are missing, the Commission may adopt common specifications by implementing act as a fallback.
๐ What does standardisation request M/606 contain?
Standardisation request M/606, Implementing Decision C(2025) 618, was issued to CEN, CENELEC and ETSI on 3 February 2025. Its Annex I lists 41 lines, which fall into three types:
| Type | Content | Lines in M/606 | Original deadline |
|---|---|---|---|
| A (horizontal) | Principles for cyber resilience: risk-based design across the lifecycle | Line 1 | 30 August 2026 |
| B (vulnerabilities) | Vulnerability handling and coordinated disclosure | Line 15 | 30 August 2026 |
| B (technical measures) | Generic security requirements per essential requirement in Annex I, Part 1 | Lines 2โ14 | 30 October 2027 |
| C (vertical) | Product-specific requirements for important and critical products | Lines 16โ41 | 30 October 2026 |
In July 2026 the Commission published a draft amendment that pushes the 2026 deadlines back by two months: types A and B (vulnerabilities) to 31 October 2026 and type C to 31 December 2026. As of early September 2026 that amending decision had still not been formally adopted. Bear in mind that these are delivery dates for the draft standards, not the dates on which they become usable.
๐๏ธ Which standards are being developed?
| Standard (series) | Committee | Subject | Status October 2026 |
|---|---|---|---|
| EN 40000-1-1 and -1-2 | CEN-CLC/JTC 13 WG 9 | Vocabulary and principles for cyber resilience | Formal approval completed; ratification scheduled for 2 November 2026; no OJ citation planned so far |
| EN 40000-1-3 | CEN-CLC/JTC 13 WG 9 | Vulnerability handling | In development; expected to be cited |
| EN 40000-1-4 | CEN-CLC/JTC 13 WG 9 | Generic security requirements (controls) | In development, 2027 deadline |
| EN 304 617โ636 (17 standards) | ETSI TC CYBER (WG EUSR) | Including browsers, password managers, VPN, SIEM, boot managers, operating systems, routers and switches, hypervisors, firewalls and IDS/IPS | 17 drafts sent to public enquiry on 13 August 2026 |
| prEN 50770-1 to -6 | CLC/TC 65X WG 3 | OT security profiles based on IEC 62443 for firewalls, network management, network interfaces, VPN, routers/switches and SIEM | In development |
| Semiconductor standards | CLC/TC 47X | Microprocessors and microcontrollers with security functions, tamper-resistant variants, smartcards and secure elements | In development |
| Smart meter gateways | CEN-CLC/JTC 13 WG 6 | Smart meter gateways and devices for advanced security purposes | In development |
As of early October 2026, not a single CRA harmonised standard has been cited in the Official Journal. The product categories themselves have been technically defined since 21 December 2025 by Implementing Regulation (EU) 2025/2392, which classifies products by their core functionality: a router with a built-in firewall is still a router.
๐ How do the CRA standards relate to IEC 62443?
IEC 62443-4-1 (secure product development) and IEC 62443-4-2 (technical requirements for components) have been adopted by CENELEC as EN IEC 62443-4-1:2018 and EN IEC 62443-4-2:2019. For the CRA, CLC/TC 65X is preparing amendments (prAA) that map them to the essential requirements. Observers expect that these amendments will probably not be cited in the Official Journal themselves.
The OT route therefore runs through the prEN 50770 series: security profiles that apply a defined subset of IEC 62443 to a single product category, following the profile scheme of IEC TS 62443-1-5. The risk analysis method of IEC 62443-4-1 is the common basis across all parts. A vendor that already develops to IEC 62443-4-1 and has its components certified against a security level in IEC 62443-4-2, for example through ISASecure, has a strong foundation, but no automatic presumption of conformity.
Precedent: EN 18031. For the Radio Equipment Directive, EN 18031-1, -2 and -3 were cited on 28 January 2025, but with restrictions: if you use the โno passwordโ option, that part gives no presumption of conformity. Expect CRA standards to be cited with restrictions as well.
๐ Which conformity route applies to each product class?
| Product class | Examples | Permitted routes |
|---|---|---|
| Default (about 90% of products) | Sensor, PLC, HMI, engineering software | Module A (self-assessment), B+C, H or EUCC |
| Important Class I (Annex III) | Routers, switches, VPN, SIEM, operating systems, network interfaces, microcontrollers with security functions | Module A only when harmonised standards, common specifications or EUCC (at least assurance level โsubstantialโ) are applied in full; otherwise B+C or H |
| Important Class II (Annex III) | Firewalls, IDS/IPS, hypervisors, tamper-resistant microcontrollers | Always a notified body: B+C, H or EUCC (at least assurance level โsubstantialโ) |
| Critical (Annex IV) | Smart meter gateways, smartcards and secure elements, hardware devices with security boxes | EUCC certification where a delegated act requires it; otherwise as Class II |
The standards matter most for Class I: without a cited standard, the maker of an industrial switch must still involve a notified body, which costs capacity and lead time. The rules on notified bodies have applied since 11 June 2026.
๐ ๏ธ How should OT vendors prepare now?
- Classify your portfolio โ decide for each product whether it is default, Class I, Class II or critical under Annex III/IV and Implementing Regulation 2025/2392
- Start with IEC 62443-4-1 โ a documented secure development process with threat modelling and a risk assessment aligns with EN 40000-1-2
- Set up vulnerability handling โ a PSIRT, responsible disclosure, an SBOM and vulnerability management in line with EN 40000-1-3; the CRA reporting obligations have applied since 11 September 2026
- Track the draft standards โ comment on the EN 304 6xx and prEN 50770 public enquiries through your national standards body and run a gap analysis against the drafts
- Plan for Class I without a standard โ book notified-body capacity early in case standards are not cited before 11 December 2027
- Record everything in the technical file โ which standards (or parts) you apply, which restrictions apply, and how you justify the remaining requirements
โ Frequently asked questions
When will the CRA harmonised standards be available?
Under M/606, the CRA harmonised standards must be delivered to the Commission between late 2026 and 30 October 2027, depending on their type. They only provide a presumption of conformity once cited in the Official Journal, and as of October 2026 no CRA standard had been cited.
What does presumption of conformity mean under the CRA?
Presumption of conformity means that a product meeting a harmonised standard cited in the Official Journal is deemed to comply with the CRA essential requirements covered by that standard. The market surveillance authority then has to show that the product does not comply, rather than the other way round.
Is IEC 62443 a harmonised standard under the CRA?
IEC 62443 is currently not a harmonised standard under the CRA. The CENELEC versions EN IEC 62443-4-1 and -4-2 are receiving CRA amendments, and the prEN 50770 series builds OT security profiles on IEC 62443, but a presumption of conformity only arises after citation in the Official Journal.
Do I need a notified body as a PLC manufacturer?
A PLC without a dedicated security function usually falls into the CRA default class, for which self-assessment under Module A is sufficient. If the productโs core functionality appears in Annex III, such as a router or firewall, Class I or II applies and a notified body is needed, unless you apply cited harmonised standards in full for a Class I product.
What happens if the CRA standards are late?
If CRA harmonised standards are missing or inadequate, the Commission can adopt common specifications under Article 27 with the same legal effect. Manufacturers can also always demonstrate compliance with the essential requirements themselves, but for Class I products that means an assessment by a notified body.
Who writes the CRA standards?
The CRA standards are written by CEN-CLC/JTC 13 (the horizontal EN 40000 series), ETSI TC CYBER (the EN 304 6xx product standards), CLC/TC 65X (the prEN 50770 OT profiles) and CLC/TC 47X (semiconductors). Manufacturers can contribute through the mirror committees of their national standards body, such as NEN in the Netherlands.
๐ In summary
CRA harmonised standards under mandate M/606 define how you demonstrate the essential requirements of the Cyber Resilience Act; only once cited in the Official Journal do they give a presumption of conformity. As of early October 2026 no standard has been cited. OT vendors that already work to IEC 62443-4-1 and -4-2 and track the EN 40000 and prEN 50770 drafts will be best placed on 11 December 2027.
