UPDATE — the Cyber Resilience Act's conformity route entered formal approval this week: ETSI put 17 draft product-category standards out for Public Enquiry, and the procedure runs past the regulation's first reporting deadline
UPDATE · originally covered The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software (2026-08-02)
a prior weekly recorded the European Commission publishing its first official Cyber Resilience Act application guidance — the interpretive half of the problem, answering which products are in scope and what counts as a substantial modification. This week supplies a delta on the other half, the technical route to demonstrating compliance, and it comes with a timetable worth noting.
On 13 August ETSI announced "the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry", submitted this summer to 41 member organisations across Europe including the national standardisation bodies of the European Economic Area. The purpose is stated plainly: these standards "aim to become Harmonised Standards, giving manufacturers a recognised way to demonstrate compliance with the legislation, the so-called 'presumption of conformity'". The chair of the responsible technical committee frames the gap they fill in a sentence that also explains why their absence matters — "The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how" (ETSI, 2026-08-13), reported independently the following day (Help Net Security, 2026-08-14).
The EN 304 series categories are not consumer-peripheral, which is what makes this a procurement item rather than a compliance-desk one. Alongside browsers, password managers, antivirus software, smart-home virtual assistants, smart-home security products, connected toys and wearables, the drafts cover VPNs, network management systems, SIEM, boot managers, PKI certificate-issuance software, network interfaces, operating systems, routers, modems and switches, virtualization and container platforms, and firewalls — most of a public-sector security stack (ETSI TC CYBER-EUSR open document store, 2026-08-13). The press release itself names only the consumer-facing subset; the full vertical list comes from the draft filenames in ETSI's own open document store, which the release links. The timing is the constraint: ETSI states "The approval procedure will run until mid-September to mid-November 2026, depending on the vertical", and that window opens at or after the CRA's first hard operational date, the reporting obligations beginning on 11 September 2026 that this pipeline already tracks. So for the coming months there is no harmonised standard a supplier can point to, and conformity has to be demonstrated against the regulation's essential requirements directly, or through third-party conformity assessment for the critical categories.
ETSI is pleased to announce the availability of the 17 vertical final draft standards developed in the framework of the EU Cyber Resilience Act (CRA) and currently under Public Enquiry.
The approval procedure will run until mid-September to mid-November 2026, depending on the vertical.
The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how.
Update chain
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.