The ETSI EN 304 xxx series standards on cyber security requirements have been submitted this summer to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area. They will be able to provide comments as part of the first phase of the approval procedure.
ETSI's societal partners ANEC (the European consumer voice in standardisation), ECOS (the European Environmental Citizens' Organisation for Standardisation), ETUC (the European Trade Union Confederation), and SBS (Small Business Standards), collectively known as the Annex III Organisations, will also be able to comment on these standards.
The approval procedure will run until mid-September to mid-November 2026, depending on the vertical.
ETSI develops global ICT standards that enable interoperability, cyber security, and sustainable, market-ready products and services. The ETSI standards related to the CRA apply to connected products with digital elements, including products exposed to a higher risk of compromise, such as password managers, anti-virus software, smart home assistants, connected toys, and wearables.
“The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how. The role of the Standards Developing Organisations is to detail the technical aspects of how to achieve compliance with the legislation through standards,” says Sandra Feliciano, Chair of the group responsible for the CRA (TC CYBER-EUSR).
Challenge is not understanding the rule but how to comply in practice
For many small and medium enterprises, the challenge is not understanding that the CRA applies to them, but knowing how to comply in practice, which standards to follow, and which tools, guidance, and funding opportunities are available to support compliance. Therefore, to help SMEs understand, prepare for, and comply with the EU Cyber Resilience Act, while translating regulatory requirements into practical guidance and tools and providing information on the ongoing standardisation process and opportunities to participate in open consultations, CEN, CENELEC, and ETSI, the three European Standards Organisations, have organised a series of workshops across Europe, the CRA Standards Unlocked EU Tour.
As the CRA applies to all products with digital elements, stakeholders including manufacturers, importers, distributors, service providers, and developers of commercially available hardware and software products will be required to comply with the CRA by the end of 2027. ETSI standards play a fundamental role in helping manufacturers demonstrate compliance with the CRA and ensure consistent implementation across the EU.





















