Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Standards and presumption of conformity

Last updated:

A harmonised standard translates CRA legal requirements into more detailed technical specifications. Use is generally voluntary. Presumption of conformity arises only to the extent that:

  1. the product or process complies with the applicable harmonised standard or part; and
  2. the reference to that standard has been published in the Official Journal of the European Union for the CRA.

A draft, public enquiry, national standard or useful international standard does not by itself create Article 27 presumption of conformity. It may still be technical evidence, but the manufacturer must explain how it covers specific CRA requirements and address remaining gaps.

What to monitor

The Commission adopted standardisation request M/606 for 41 horizontal and product-specific standards. Horizontal standards address cross-cutting requirements and processes such as vulnerability handling. Vertical standards focus on specific important and critical product categories.

Monitor status in this order:

  1. Official Journal/EUR-Lex — decisive for presumption of conformity;
  2. Commission CRA standardisation page — mandate and implementation overview;
  3. STAN4CR — working status of standardisation deliverables;
  4. CEN-CENELEC and ETSI TC CYBER — standards development and approval.

On 13 August 2026, ETSI announced public enquiry on 17 draft product-specific EN 304 xxx standards. They are intended to become harmonised standards, but public enquiry alone does not create presumption of conformity.

Practical workflow