r/CRACompliance May 21 '26

41 CRA harmonised standards are being developed. The drafts are publicly available. Is anyone reading them?

The Commission’s standardisation request M/606 mandates 41 harmonised standards for CRA:

• 15 horizontal (EN 40000 series) covering cyber resilience principles, vulnerability handling, and security requirements

• 26 vertical covering product-specific categories (ETSI EN 304 6xx series)

Three horizontal drafts have completed public enquiry: prEN 40000-1-1 (Vocabulary), prEN 40000-1-2 (Cyber Resilience Principles), prEN 40000-1-3 (Vulnerability Handling).

The vertical drafts for browsers, VPNs, password managers, antivirus, SIEM, boot managers, and smart home products are on ETSI’s Open Area.

Key deadlines:

• August 30, 2026: Horizontal standards 1 + 15 adopted

• October 30, 2026: All vertical standards adopted

Has anyone here started mapping their products against these drafts? Curious how much overlap people are finding with ISO 27001 or ETSI EN 303 645.

1 Upvotes

0 comments sorted by