On 13 August 2026, ETSI Opened the Public Enquiry on 17 Draft CRA Product Standards
On 13 August 2026, ETSI announced from Sophia Antipolis that 17 vertical final draft standards written for the Cyber Resilience Act are now under Public Enquiry. These are the product-specific documents that are meant to tell a manufacturer of a password manager, a router or a connected toy what the CRA's essential requirements actually mean for that product. Until now the vertical work had been visible only through informal consultations. It has now entered the formal approval procedure, and the drafts are public.
No Cyber Resilience Act harmonised standard has yet been cited in the Official Journal of the EU, so none of these documents currently confers the presumption of conformity under Article 27. The 17 texts are final drafts in the first phase of approval. ETSI says the procedure runs until mid-September to mid-November 2026, with the closing date varying by vertical. Delivery to the Commission, assessment and a formal citation decision all come after that.
What is actually on the table
The documents belong to the ETSI EN 304 xxx series, numbered EN 304 617 to EN 304 627 and EN 304 631 to EN 304 636. Between them they cover Annex III Class I items 2 to 12 and 16 to 19, plus Class II items 1 and 2: browsers, password managers, antivirus, VPNs, network management systems, SIEM, boot managers, PKI and certificate issuance software, network interfaces, operating systems, routers and modems and switches, smart home virtual assistants, smart home security products, connected toys, personal wearables, hypervisors and container runtimes, and firewalls with intrusion detection and prevention.
Several Annex III categories are nu in this set: identity and access management, which sits with CEN, and the semiconductor entries. Nor is the default tier, which is most products with digital elements and which will rely on the horizontal standards instead. Our Instrumentul de clasificare will tell you which tier you are in, and we have mapped all 17 drafts against the Annex I essential requirements so you can see what your category is being asked for.
They are not one document in seventeen colours
It is tempting to assume the verticals share a template, so that reading one tells you about the rest. They do not. Most follow a common spine, clause 5.2 to 5.15, mapping one to one onto Annex I Part I. But the PKI draft has no appropriate-level-of-cybersecurity clause at all, the operating systems draft uses technical requirements decomposed into mitigations and bound by security profiles, and the hypervisor and container draft is organised by product component rather than by requirement. The counts diverge just as sharply: the boot managers draft carries roughly a hundred numbered requirements, 24 on integrity protection alone, while the SIEM draft carries around two dozen in total and delegates heavily to the operational environment. If your product could plausibly land in two categories, that choice is not a formality.
Who gets to comment
The drafts went to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. Four societal partners can also file comments: ANEC for consumers, ECOS on environment, ETUC for trade unions and SBS for small business.
An individual manufacturer is not on that list. If you want a comment on the record, the route is through your national standardisation body or through ETSI membership, and the window is measured in weeks rather than months. The texts themselves are freely readable, which is the more important point for most companies: you can see the requirements now, without waiting for the final version.
Why weeks matter for a 2027 deadline
The CRA's substantive obligations apply from 11 decembrie 2027, which sounds like plenty of time. It is not, and the reason is the sequence. A standard only unlocks the Article 27 presumption of conformity once its reference is cited in the Official Journal, and that citation comes after the enquiry closes, after comments are resolved, after delivery to the Commission and after assessment. In early July 2026 the Commission published a draft amendment moving the delivery deadline for the vertical standards to 31 December 2026. A Public Enquiry that closes as late as mid-November leaves very little room between the two.
The practical consequence is that you will be designing against drafts for some time, and the gap between a draft requirement and the final wording is a risk you carry yourself. Reading the draft for your category now is the cheapest way to shrink it.
What this does not change
Nothing here moves the 11 septembrie 2026 reporting date. From that day, manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform, on a 24 hour, 72 hour and final report cycle that runs from awareness. Standardisation and reporting are separate tracks with separate clocks, and the nearer one is four weeks away. Our ghid de raportare sets out the deadlines, and situația actuală tracks the milestones.
ETSI, CEN and CENELEC are also running a workshop series, the CRA Standards Unlocked EU Tour, aimed at smaller companies that know the CRA applies to them but not how to comply. For a company with one product and no standards team, that is probably a better use of a day than reading 17 drafts.
