ETSI opens approval process for 17 standards supporting the EU Cyber Resilience Act

The European Telecommunications Standards Institute (ETSI) has submitted 17 draft standards for public review as part of the EU Cyber Resilience Act. The standards are intended to give manufacturers practical technical guidance for meeting the cybersecurity requirements that will apply to products with digital elements.

ETSI opens approval process for 17 standards supporting the EU Cyber Resilience Act

The European Telecommunications Standards Institute (ETSI) has launched the approval process for 17 draft European Standards designed to support implementation of the European Union’s Cyber Resilience Act (CRA).

The standards are currently under public enquiry, meaning that national standardisation organisations and other recognised stakeholders can review the drafts and submit comments before they are finalised. The approval process is expected to run from September to November 2026, depending on the individual standard.

The Cyber Resilience Act establishes cybersecurity requirements for products that contain digital elements, including both hardware and software. It covers a broad range of connected products, from consumer devices such as smart home assistants, connected toys and wearables to cybersecurity products such as password managers and antivirus software.

The legislation sets out what manufacturers are required to achieve, but does not provide all of the technical details needed to meet those requirements. This is where standards become important. The ETSI standards are intended to describe technical approaches that manufacturers can use when implementing the cybersecurity requirements of the CRA.

If the standards are eventually recognised as Harmonised Standards under EU law, manufacturers using them can benefit from what is known as a presumption of conformity. In practical terms, this provides a recognised way for manufacturers to demonstrate that their products meet particular requirements of the legislation.

The 17 standards form part of the ETSI EN 304 xxx series and focus on cybersecurity requirements relevant to products covered by the CRA. The draft standards have been submitted to 41 ETSI member organisations across Europe, including national standardisation bodies from the European Economic Area.

Several organisations representing broader societal interests will also be able to comment during the process. These include ANEC, which represents consumers in standardisation; ECOS, representing environmental interests; the European Trade Union Confederation (ETUC); and Small Business Standards (SBS).

The standards are particularly relevant to manufacturers and other businesses that need to prepare for the CRA. The legislation applies broadly to products with digital elements, meaning that manufacturers, importers, distributors, service providers and developers of commercially available hardware and software will need to meet its requirements as the relevant obligations take effect.

For smaller companies, translating legal requirements into concrete technical measures can be challenging. ETSI, together with the other European Standards Organisations, CEN and CENELEC, is therefore also supporting workshops across Europe through the CRA Standards Unlocked EU Tour. The initiative is intended to help small and medium-sized enterprises understand the requirements, identify relevant standards and follow the ongoing standardisation process.

The 17 draft standards are now available for public review, giving European standardisation bodies and other eligible stakeholders an opportunity to provide input before the approval process moves forward.

Go to Top