The European Telecommunications Standards Institute (ETSI) has launched the approval process for 17 draft standards developed in connection with the Cyber Resilience Act (CRA), with a view to supporting the implementation of the EU cybersecurity requirements applicable to products with digital elements.
The objective is for these technical specifications to be adopted as harmonised standards, thereby providing manufacturers with recognised technical benchmarks to demonstrate compliance with the relevant requirements of the CRA. The initiative is particularly significant for products with digital elements presenting a higher risk in the event of compromise, including, for example, password managers and wearable devices.
The 17 draft standards have now entered the public inquiry phase, during which ETSI member organisations and societal stakeholders may submit comments and proposed amendments. The consultation will remain open until mid-November 2026.
The launch of this approval process marks a significant step towards the development of the technical framework underpinning the implementation of the Cyber Resilience Act. Once harmonised, the standards may become one of the key operational tools available to manufacturers for documenting and demonstrating the compliance of products with digital elements with the cybersecurity requirements laid down under EU law.