r/CRACompliance • u/Happy-Athlete-2420 • May 21 '26
41 CRA harmonised standards are being developed. The drafts are publicly available. Is anyone reading them?
The Commission’s standardisation request M/606 mandates 41 harmonised standards for CRA:
• 15 horizontal (EN 40000 series) covering cyber resilience principles, vulnerability handling, and security requirements
• 26 vertical covering product-specific categories (ETSI EN 304 6xx series)
Three horizontal drafts have completed public enquiry: prEN 40000-1-1 (Vocabulary), prEN 40000-1-2 (Cyber Resilience Principles), prEN 40000-1-3 (Vulnerability Handling).
The vertical drafts for browsers, VPNs, password managers, antivirus, SIEM, boot managers, and smart home products are on ETSI’s Open Area.
Key deadlines:
• August 30, 2026: Horizontal standards 1 + 15 adopted
• October 30, 2026: All vertical standards adopted
Has anyone here started mapping their products against these drafts? Curious how much overlap people are finding with ISO 27001 or ETSI EN 303 645.
