Treoir neamhspleách ar Rialachán (AE) 2024/2847 · Stádas: i bhfeidhm
Is aistriúchán uathoibríoch (IS) é an leathanach seo agus níor athbhreithnigh duine é.
Guidance · Draft standards

What the 17 draft CRA product standards require

On 13 August 2026, ETSI opened the Public Enquiry on 17 draft European Standards written for the Cyber Resilience Act. They are freely readable now. Find your product category below and see what the draft for it actually asks for, without reading 17 PDFs.

Status at last check, 17 August 2026

None of these documents is a harmonised standard. No CRA standard has yet been cited in the Official Journal of the EU, so none of them currently confers the presumption of conformity under Article 27. They are final drafts in the first phase of approval, and the wording will change. The comment procedure runs until mid-September to mid-November 2026, depending on the vertical.

The requirement titles below are the ones each draft prints in its own contents. Everything around them, the scope summaries, the notes and the mapping onto Annex I, is our reading. No ETSI requirement text is reproduced. Read the source PDF for your category before making a design decision.

Important products · Annex III Class I
Important products · Annex III Class II

Not sure which one is yours, or whether you are in Annex III at all? The classification finder will place your product. If it comes out in the default tier, none of these verticals applies to you: you will rely on the horizontal standards, which are still in development.

Reading the set

Four things worth knowing

1. There is no single template

Most drafts follow a common spine, clause 5.2 to 5.15, mapping one to one onto Annex I Part I. Several do not. The PKI draft has no appropriate-level-of-cybersecurity clause and renames the rest. The operating systems draft uses technical requirements decomposed into mitigations and bound by security profiles. The hypervisor and container draft is organised by product component. The routers and firewalls drafts are far more condensed than the others. Requirement identifiers follow at least six incompatible conventions across the set, and three drafts, browsers, antivirus and, in part, password managers, give their requirements no titles at all: the identifier is the whole heading.

2. Requirement counts vary enormously

The boot managers draft carries roughly a hundred numbered requirements, 24 of them on integrity protection alone. The SIEM draft carries around two dozen in total and delegates heavily to the operational environment. Both are drafted against the same fourteen essential requirements. If your product could plausibly fall under two categories, the choice of standard is not a formality.

3. Some categories still have no ETSI draft

The 17 drafts cover Annex III Class I items 2 to 12 and 16 to 19, and Class II items 1 and 2. Not covered by this set:

  • Class I item 1, identity management and privileged access management, which sits with CEN under prEN 40000-10
  • Class I items 13, 14 and 15, microprocessors, microcontrollers and ASICs or FPGAs with security-related functionalities
  • Class II items 3 and 4, tamper-resistant microprocessors and microcontrollers

Default-tier products, the great majority of products with digital elements, are not covered by any of these verticals at all. They will rely on the horizontal standards, which are still in development.

4. Commenting runs through your national body

The drafts went to 41 member organisations, including the national standardisation bodies of the European Economic Area, plus the four societal partners ANEC, ECOS, ETUC and SBS. An individual manufacturer is not on that list: the route for a comment on the record is your national standardisation body or ETSI membership. The window closes mid-September to mid-November 2026, depending on the vertical. Reading the drafts costs nothing and is open to anyone.