Független útmutató az (EU) 2024/2847 rendelethez · Állapot: hatályban
Ez az oldal automatikus (mesterséges intelligenciával készült) fordítás, amelyet ember nem ellenőrzött. A blogbejegyzések csak angol nyelven érhetők el.
← All news
CRA-betekintések30 July 2026

The Commission's Draft Amendment Pushes the CRA's 2026 Harmonised-Standard Deadlines Back by Two Months

The Commission's Draft Amendment Pushes the CRA's 2026 Harmonised-Standard Deadlines Back by Two Months

The single most important piece of missing machinery under the Cyber Resilience Act is the set of harmonizált szabványok that will tell a manufacturer, in concrete terms, how to meet the Annex I essential requirements. In early July 2026, the European Commission published a draft amendment to the CRA standardisation request (mandate M/606) that pushes the 2026 drafting deadlines for those standards back by two months. The obligations and the application dates in the regulation itself do not change. What moves is the timetable the standards bodies have to hit, and with it the point at which manufacturers finally get a stable technical target to build against.

What actually changed

Under the original standardisation request, issued to CEN, CENELEC and ETSI in early 2025, the horizontal Type A standards and the Type B standards for vulnerability management were due by 2026. augusztus 30., and the product-specific Type C standards by 30 October 2026. The draft amendment moves the A and B vulnerability-management standards to 31 October 2026 and the C standards to 31 December 2026. These are the dates by which the European standardisation organisations must deliver the drafts to the Commission. They are not the dates on which the standards become usable: a standard only unlocks the Article 27 presumption of conformity once its reference is cited in the Official Journal of the EU, which happens after delivery, assessment and a formal citation decision.

Why a two-month slip is not a small thing

The CRA's substantive obligations apply from 11 December 2027. That looks comfortably far off, but the standards have to be finalised, cited, and then actually implemented by manufacturers well before it, and the citation step alone has historically taken months. Every slip at the drafting stage compresses the window manufacturers have to test products against a finished standard, generate the technical documentation, and, where needed, book a notified body. It also lengthens the period in which in-scope companies are preparing against drafts rather than citable text. For a Class I important product, this is not academic: under Article 32(2), the light self-assessment route is only open where the manufacturer applies harmonised standards, common specifications or a European cybersecurity certification scheme covering the essential requirements. No cited standard means no clean self-assessment path, and a likely detour through a notified body. Our classification tool és CE marking and conformity guide show which route each tier triggers.

The standards behind the dates

The horizontal work sits in the EN 40000 series, developed in CEN/CLC/JTC 13 WG9 and building on the EN 18031 work originally produced for the Radio Equipment Directive. Of that family, the vulnerability-handling part, prEN 40000-1-3, is currently the one expected to be cited, while the broader principles and generic-security-controls parts are on a longer track, with one part not scheduled until autumn 2027. In parallel, a set of vertical OT product standards, the prEN 50770 series, covers categories that map directly onto CRA Annex III: firewalls and IDS/IPS, network management systems, VPN products, and routers and switches. Those verticals lean heavily on the IEC 62443 framework, though several IEC parts are themselves unlikely to be cited in the Official Journal. The practical takeaway is that the standards landscape is real and advancing, but still fluid, and the amendment is a formal acknowledgement that the original 2026 pace was too fast.

Status at publication, 30 July 2026

The two-month postponement is still a draft amendment. The corresponding implementing decision has not yet been published in the Official Journal, so the new 31 October and 31 December 2026 dates are proposed, not yet legally fixed. Separately, and more importantly for anyone preparing now, no CRA harmonised standard has yet been cited in the Official Journal for any product category. Until a reference is cited, the Article 27 presumption of conformity is unavailable, and the Article 32(2) self-assessment route for Class I products cannot be relied on. Manufacturers should track the Official Journal citation, not the drafting deadline, as the date that actually matters.

What manufacturers should do now

The deadline shift changes the calendar, not the direction of travel, so the sensible preparation is unchanged. Confirm your product's classification first, since that decides the conformity route regardless of when standards land. Build against the drafts that already exist, especially prEN 40000-1-3 for vulnerability handling and the relevant prEN 50770 vertical, since the finished standards will not diverge wildly from mature drafts. Keep the work that is standard-agnostic moving: risk assessment, a machine-readable SBOM, technical documentation and a working vulnerability-handling process are required whichever route a product ultimately takes, and our free analysis tooling can generate and screen an SBOM to support it. And remember that the standards timeline is decoupled from the reporting timeline: the duty to report actively exploited vulnerabilities within 24 hours still begins on 2026. szeptember 11., unaffected by any standards slip, as our Article 14 reporting guide sets out. The megfelelőségi mátrix maps each of these duties to its article reference so nothing waits on a standard that has not arrived.

Published 30 July 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.