Meet the Authors

Key Takeaways What you need to know
  1. ETSI has opened the approval process for 17 draft standards supporting implementation of the EU Cyber Resilience Act.

  2. Cyber Resilience Act vulnerability and incident reporting requirements begin September 11, 2026, ahead of the regulation's main obligations in December 2027.

  3. The ETSI drafts aim to become harmonized standards that can provide manufacturers with a recognized route toward demonstrating CRA conformity.

European Telecommunications Standards Institute (ETSI) has announced the availability of 17 vertical final draft standards developed under the EU’s Cyber Resilience Act, opening a formal approval process that will run into 2026. The standards, submitted this summer to 41 member organizations across Europe, including the national standardization bodies of the European Economic Area, are currently under public review.

They are intended to become harmonized standards, giving manufacturers a recognized route to demonstrate compliance, described in the regulation as a presumption of conformity. The announcement lands as the Cyber Resilience Act’s own compliance clock continues to run, with reporting obligations set to begin on September 11, 2026, and the main obligations applying from December 11, 2027.

Inside the EU Cyber Resilience Act’s Compliance Timeline

The Cyber Resilience Act entered into force on December 10, 2024. Its main obligations apply from December 11, 2027, but reporting duties begin earlier, on September 11, 2026, giving manufacturers a narrower window than the headline date suggests. The regulation introduces mandatory cybersecurity requirements covering every phase of a product’s life for products with digital elements.

Explore related questions

Manufacturers must also manage vulnerabilities after a product reaches the market. Any actively exploited vulnerability or severe security incident must be reported, and these notifications will flow through the CRA Single Reporting Platform, which the EU Agency for Cybersecurity (ENISA) is responsible for establishing and which is scheduled to become operational by September 11, 2026. A computer security incident response team (CSIRT) that receives an initial notification is then generally responsible for disseminating it to CSIRTs in other member states where the product has been made available, creating a coordinated reporting chain across the bloc.

Compliance itself is not a single path. Most products can use a self-assessment procedure, known as the internal control procedure under module A, while important and critical products face stricter conformity requirements. Depending on the product category and whether harmonized standards or other specifications are applied, manufacturers may need third-party conformity assessment through a notified body.

A European cybersecurity certification is also available as a conformity route where applicable. Organizations building or extending connected digital products, including embedded components and edge devices, will need to determine whether their offerings fall within the CRA’s definition of products with digital elements before these obligations take effect.

ETSI’s 17 Draft Standards and the Path to ‘Presumption of Conformity’

The 17 draft standards ETSI has released sit within the ETSI EN 304 xxx series and are built specifically around the Cyber Resilience Act’s requirements. Their purpose is narrow but consequential: if finalized as harmonized standards, they will give manufacturers a documented way to show they meet the regulation’s essential cybersecurity requirements without building a case from scratch. The approval procedure covering these drafts will run until mid-September to mid-November 2026, with the exact timing depending on the vertical in question.

The standards apply broadly to connected products with digital elements, but ETSI has flagged a set of higher-risk categories for particular attention, including password managers, smart home assistants, and wearables. Products in these categories carry outsized consequences for consumers if a security failure occurs. The 17 final draft standards remain publicly available for review during the public review period, giving manufacturers and standards bodies a chance to weigh in before the texts are finalized.

The timing is tight. Because the approval procedure extends into late 2026, manufacturers cannot simply wait for finalized harmonized standards before beginning compliance work; the September 2026 reporting deadline arrives before some verticals will have settled standards to reference. The reporting requirements apply independently of whether those standards have completed the harmonization process.

Enterprise software vendors and their customers who commercially supply connected components as products, whether IoT devices or edge hardware, face the same question as any other manufacturer under the CRA: whether their offering counts as a product with digital elements, and if so, which conformity path fits their risk profile. Structured, phased approaches to risk assessment and documentation are common across enterprise technology rollouts more broadly, and organizations facing CRA obligations may find similar staging useful as they prepare.

What This Means for SAPinsiders

  • Compliance timelines are shorter than they appear. Reporting obligations begin in September 2026, well before the 2027 main applicability date, and before some ETSI harmonized standards are finalized. Teams managing connected products should treat risk assessment and documentation as immediate priorities, not 2027 deliverables.
  • Vendor CRA readiness will factor into procurement. Buyers evaluating software or connected hardware vendors may increasingly ask about conformity assessment status and alignment with emerging ETSI standards. Procurement and vendor management teams should build these questions into evaluation criteria now.
  • Incident reporting needs new governance before September 11. Security and governance teams must build processes to detect, triage, and report exploited vulnerabilities through the ENISA reporting platform ahead of the September 2026 deadline. Waiting until standards finalize risks leaving these workflows unbuilt when obligations begin.