FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Harmonised Standards

Do CRA harmonised standards replace the manufacturer's cybersecurity risk assessment?

No. The cybersecurity risk assessment remains the starting point for deciding which CRA essential requirements are relevant to the product.

The Commission FAQ says that even when a harmonised standard is used, the manufacturer remains responsible for assessing product risks, selecting suitable standards or other specifications, and checking whether the standard covers all relevant risks.

Citations
Cyber Resilience Act

Article 13(2) and Annex VII require the manufacturer's cybersecurity risk assessment and its inclusion in technical documentation.

CRA Harmonised Standards

What if a CRA harmonised standard covers only part of the product or only part of the requirements?

Then only that part benefits from presumption of conformity.

For the remaining requirements or risks, the manufacturer must use other technical specifications or solutions, explain them in the technical documentation, and show why those solutions meet the applicable CRA requirements.

Citations
Blue Guide 2022

Blue Guide section 4.1.2.3 confirms that partial application gives presumption only to the covered extent.

CRA Harmonised Standards

What did the CRA standardisation request M/606 ask CEN, CENELEC, and ETSI to develop?

The Commission says M/606 requests a set of harmonised standards in support of CRA compliance, with both horizontal and vertical standards.

Horizontal standards are intended to provide a common framework, methodology, taxonomy, and processes such as vulnerability handling. Vertical standards are product-specific and focus on risks tied to particular intended purposes and reasonably foreseeable uses, especially for important and critical product categories in CRA Annexes III and IV.

Citations
CRA Harmonised Standards

Does the CRA standardisation request itself create presumption of conformity?

No. M/606 starts and frames the standards-development work; it is not the same as an OJ-published harmonised standard.

Even after an ESO adopts a European standard, Article 27(6) requires the Commission to assess it before publishing its reference in the Official Journal. Until the relevant reference is published, the standard does not create CRA presumption of conformity.

Citations
Cyber Resilience Act

Article 27(6) requires Commission assessment before OJ publication of a harmonised standard reference.

Blue Guide 2022

Blue Guide section 4.1.2.3 says OJEU publication starts the presumption and is not automatic.

CRA Harmonised Standards

What is the current CRA standards timing, and when can a team claim presumption of conformity?

The Commission's CRA implementation roadmap schedules the first horizontal and product-specific standardisation deliverables for Q3 2026 and further deliverables by 30 October 2027. Those roadmap dates are planning milestones, not legal dates on which a presumption automatically begins.

A team should claim CRA presumption of conformity only after checking the current Official Journal citation for the exact standard, version, restrictions, and Annex I coverage being relied on. Adoption by a standards organisation, publication by a standards body, or mention in the M/606 work programme is not enough without the Commission's OJ reference.

Citations
Cyber Resilience Act

Article 27(1) makes Official Journal publication of a harmonised-standard reference the condition for CRA presumption of conformity and limits the presumption to covered requirements.

CRA Harmonised Standards

What happens under the CRA if no relevant harmonised standard exists yet?

The product can still be compliant, but the manufacturer must demonstrate conformity by other means.

The absence of a harmonised standard can also affect route selection. For important products of class I, if relevant harmonised standards, common specifications, or qualifying certification schemes do not exist, Article 32(2) requires a third-party conformity assessment route for the corresponding essential cybersecurity requirements.

Citations
Cyber Resilience Act

Article 32(2) sets the class I route consequence when relevant harmonised standards, common specifications, or schemes do not exist or are not applied.

Blue Guide 2022

Blue Guide section 4.1.3 explains that manufacturers may use other means but must demonstrate conformity themselves.

CRA Harmonised Standards

When can the Commission adopt CRA common specifications?

Only in the fallback situations set out in Article 27.

The Commission may adopt common specifications after it has requested harmonised standards and the request was not accepted, the standards were not delivered on time, or the standards do not comply with the request. Article 27 also requires that no relevant OJ-published harmonised-standard reference exists and no such reference is expected within a reasonable period.

Citations
Cyber Resilience Act

Article 27(2)-(4) defines the conditions and consultation steps for common specifications.

CRA Harmonised Standards

Are CRA common specifications a general mandatory substitute for harmonised standards?

No. Common specifications are an exceptional fallback tool, not the normal first-line standardisation route.

If common specifications are adopted and applied, they can create presumption of conformity for the CRA requirements they cover. If a manufacturer does not apply them, Annex VII still requires the technical documentation to describe the alternative solutions and relevant technical specifications used.

Citations
Cyber Resilience Act

Article 27(2) and 27(5) define common specifications as fallback implementing acts that can create presumption for covered requirements; Annex VII point 5 requires the manufacturer to document alternative solutions when common specifications are not applied.

CRA Harmonised Standards

Do CRA common specifications stay in place once a relevant harmonised standard is published?

Not for the overlapping essential cybersecurity requirements.

When the reference of a harmonised standard is published in the Official Journal, Article 27(6) requires the Commission to repeal the common specifications, or parts of them, that cover the same CRA requirements.

Citations
Cyber Resilience Act

Article 27(6) requires repeal of overlapping common specifications after OJ publication of the relevant harmonised standard reference.

CRA Harmonised Standards

Can a manufacturer rely on non-harmonised standards or its own technical specifications instead?

Yes, but that route does not carry the same presumption.

The Blue Guide says manufacturers may use other standards, non-OJ European standards, international standards, other technical specifications, or their own specifications. The practical consequence is a heavier evidence burden: the technical file must show in more detail how those choices meet the CRA requirements.

Citations
Blue Guide 2022

Blue Guide section 4.1.3 lists other possibilities and explains the additional demonstration burden.

Cyber Resilience Act

Annex VII point 5 requires a list of other relevant technical specifications when harmonised standards or common specifications are not applied.

CRA Harmonised Standards

How do European cybersecurity certification schemes interact with CRA presumption of conformity?

They can create presumption of conformity only for the CRA requirements covered by the certificate or EU statement of conformity.

Article 27(8) gives this limited presumption for products and manufacturer processes covered by a European cybersecurity certification scheme under Regulation (EU) 2019/881. Article 27(9) separately lets the Commission specify schemes that can be used to demonstrate CRA conformity; where such a scheme issues a European cybersecurity certificate at assurance level at least substantial, the manufacturer does not have to carry out a separate third-party CRA conformity assessment for the corresponding requirements.

Citations
Cyber Resilience Act

Article 27(8)-(9) defines certification-scheme presumption and the assurance-level effect for corresponding third-party CRA assessment duties.

CRA Harmonised Standards

Does any EU cybersecurity certificate automatically replace CRA conformity assessment?

No. The certificate must be under a relevant European cybersecurity certification scheme, must cover the corresponding CRA requirements, and Article 27(9) requires the Commission to specify which schemes can be used to demonstrate CRA conformity.

A certificate or EU statement of conformity that covers only some requirements gives evidence only for those requirements. It does not prove unrelated CRA requirements, unsupported product functions, vulnerability-handling processes, or technical documentation completeness.

Citations
Cyber Resilience Act

Article 27(8)-(9) limits certificate effect to covered requirements and Commission-specified schemes; Annex VII point 5 still requires the technical documentation to identify the schemes and parts applied.

CRA Harmonised Standards

Can important or critical CRA products be compliant without harmonised standards?

Yes, because harmonised standards are voluntary. But for important and critical products, route selection may change.

For important products of class I, Article 32(2) moves the corresponding requirements into Module B plus C or Module H if the manufacturer has not applied, has applied only in part, or cannot use relevant harmonised standards, common specifications, or qualifying certification schemes at assurance level at least substantial. Class II and critical products have their own third-party or certification routes under Article 32.

Citations
Cyber Resilience Act

Article 32(2)-(4) sets conformity assessment routes for class I, class II, and critical products.

CRA Harmonised Standards

Can a manufacturer integrate important or critical components that were not designed using harmonised standards?

Yes. The Commission FAQ says manufacturers may integrate important or critical components that were not designed in accordance with harmonised standards, whether or not such standards are available.

That does not remove the integrator's CRA work. The manufacturer of the final product still needs to assess component risks, decide whether the final product itself has the core functionality of an important or critical category, and keep technical documentation showing how the final product meets the CRA requirements.

Citations
CRA Harmonised Standards

What must CRA technical documentation say about harmonised standards, common specifications, and certification schemes?

It must identify the conformity tools applied in full or in part, and it must identify the gaps.

Annex VII requires a list of applied OJ-published harmonised standards, Article 27 common specifications, and European cybersecurity certification schemes. If they are partly applied, the documentation must specify which parts. If they are not applied, it must describe the solutions adopted to meet the CRA requirements and list other relevant technical specifications.

Citations
Cyber Resilience Act

Article 31 and Annex VII point 5 require current technical documentation covering the standards, common specifications, certification schemes, parts applied, alternative solutions, and other technical specifications used to demonstrate conformity.

Page 13 of 58