What are harmonised standards, common specifications, and European cybersecurity certification schemes under the CRA?
They are technical conformity tools for showing how a product with digital elements and the manufacturer's processes meet the CRA's essential cybersecurity requirements.
Harmonised standards are European standards requested and assessed through the EU standardisation system. Common specifications are Commission implementing acts that can be used only as an exceptional fallback where the Article 27 conditions are met. European cybersecurity certification schemes can support CRA conformity only to the extent the relevant certificate or EU statement of conformity covers the CRA requirements.
Article 27 establishes the CRA legal effects for harmonised standards, common specifications, and European cybersecurity certification schemes.
The Commission explains that CRA harmonised standards translate essential cybersecurity requirements into technical specifications.