Harmonised Standard
A Harmonised Standard is a European standard developed by a recognised standards body (CEN, CENELEC, or ETSI) under a mandate from the European Commission that confers a presumption of conformity with specific EU legislation. Once its reference is published in the Official Journal, manufacturers whose products comply with it are presumed to satisfy the corresponding CRA essential requirements without further proof. No CRA harmonised standard has been published in the Official Journal yet, so that presumption is currently unavailable for every product category.
A Harmonised Standard is a European standard developed by a recognised standards body (CEN, CENELEC, or ETSI) under a mandate from the European Commission that confers a presumption of conformity with specific EU legislation. Once its reference is published in the Official Journal, manufacturers whose products comply with it are presumed to satisfy the corresponding CRA essential requirements without further proof. No CRA harmonised standard has been published in the Official Journal yet, so that presumption is currently unavailable for every product category.
CRA RegulatoryWhat Is a Harmonised Standard?
A Harmonised Standard is a technical standard developed by one of the three European Standards Organisations - CEN, CENELEC, or ETSI - following a mandate issued by the European Commission. Once the standard is published in the Official Journal of the EU (OJEU), any product that complies with it benefits from a legal presumption of conformity with the EU legislation the standard supports. This presumption-of-conformity mechanism is central to the New Legislative Framework (NLF) that underpins most EU product regulation, including the Cyber Resilience Act. Harmonised Standards provide manufacturers with a concrete technical pathway to compliance, translating the CRA's high-level essential requirements into specific, testable technical specifications.
Harmonised Standards and CRA Compliance
For the CRA, ETSI and CEN-CENELEC are the primary bodies tasked with developing relevant harmonised standards. Work is ongoing to develop standards that map to the Annex I essential cybersecurity requirements, covering areas such as secure by design, vulnerability handling, cryptographic requirements, and update mechanisms. Until a harmonised standard is published in the OJEU for a specific CRA requirement, manufacturers must demonstrate compliance through other means - such as applying common technical specifications issued by the Commission, engaging a Notified Body, or documenting their own technical approach. Manufacturers should monitor ETSI's CRA-related work items (including extensions to EN 303 645) and CEN-CENELEC's work programme for emerging standards relevant to their product category.
Horizontal and Vertical CRA Standards
Standardisation request M/606 asked CEN, CENELEC and ETSI for 41 standards, and they split into two families that a manufacturer needs to track separately.
Horizontal standards apply to every product with digital elements and express the essential requirements in general terms. This is the prEN 40000 series from CEN-CENELEC JTC 13, covering vocabulary, principles for cyber resilience, vulnerability handling, and a catalogue of generic security requirements.
Vertical standards cover a single Annex III product category each. Most sit with ETSI TC CYBER as the EN 304 6xx series, where the deliverable number is 304 600 plus the M/606 line item - so browsers are EN 304 617 and firewalls are EN 304 636. Nine Annex III and Annex IV points fall outside that series: identity management and privileged access management at CEN/TC 224, the semiconductor categories at CENELEC CLC/TC 47X, smart meter gateways at CEN-CLC/JTC 13 WG 6, and smartcards including secure elements across both. Separately, CENELEC CLC/TC 65X is drafting the prEN 50770 series on IEC 62443 foundations for operational-technology versions of six of the same product types.
A manufacturer of an important product will likely need both families: the horizontal standards for the general requirements and vulnerability handling, and the vertical standard for what its specific product type has to do. Neither family is cited in the Official Journal, so neither confers a presumption of conformity today.
Presumption of Conformity: What It Means in Practice
When a manufacturer applies a harmonised standard whose reference has been published in the OJEU, they gain a legal presumption that their product satisfies the CRA essential requirements covered by that standard. This shifts the burden of proof: instead of having to demonstrate compliance from first principles, the manufacturer simply needs to document that the harmonised standard has been applied. This significantly simplifies the conformity assessment process - for default-class and some Class I products, full conformity can be demonstrated through self-declaration based on harmonised standard compliance alone, without third-party involvement. However, if a manufacturer departs from any part of the standard, they must provide alternative technical justification for the requirements covered by that part.
Currently Relevant Standards for CRA
Two families are being drafted specifically for the CRA. Both are drafts, and neither confers a presumption of conformity until its reference appears in the Official Journal:
- prEN 40000 series - the horizontal standards from CEN-CENELEC JTC 13, covering vocabulary, cyber resilience principles, vulnerability handling and generic security requirements across all products with digital elements.
- EN 304 6xx series - the vertical standards from ETSI TC CYBER, one per Annex III product category, with parallel CENELEC deliverables for the semiconductor, smartcard, identity and metering categories.
Alongside them, several established standards provide useful reference points and produce evidence that carries into a CRA technical file:
- ETSI EN 303 645 - Cyber Security for Consumer Internet of Things, widely considered the current best-practice baseline for IoT products. It predates the CRA and is separate from ETSI's EN 304 work.
- IEC 62443 series - Industrial automation and control system security, relevant for Important Class products in industrial sectors and the basis for the prEN 50770 operational-technology deliverables.
- ISO/IEC 27001 - Information security management, relevant to organisational security processes underlying vulnerability handling.
- ISO/IEC 29147 and ISO/IEC 30111 - Vulnerability disclosure and handling standards that map directly to CRA Article 13 obligations.
Manufacturers should track the ETSI TC CYBER and CEN-CENELEC JTC 13 work programmes for new CRA mandated standards, and check the Official Journal directly for citations rather than working from any status list.
CVD Portal makes Harmonised Standard compliance straightforward.
Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
Are there harmonised standards for the CRA available yet?+
Not yet. CRA-specific harmonised standards are under development by CEN, CENELEC and ETSI under standardisation request M/606, and drafts exist for every Annex III category, but no reference has been published in the OJEU for any CRA requirement. In the interim, manufacturers may use existing cybersecurity standards (such as ETSI EN 303 645 for consumer IoT) as a compliance baseline and document their approach thoroughly.
Is compliance with a harmonised standard mandatory?+
No. Harmonised standards are voluntary. Manufacturers are free to achieve CRA compliance by other means - for example, by applying common technical specifications issued by the Commission, or by working with a Notified Body. However, applying a harmonised standard is usually the most straightforward and cost-effective path to compliance, particularly for default-class and Class I products that can self-certify.
What happens if a harmonised standard only partially covers the CRA requirements?+
If a harmonised standard covers only some of the CRA's essential requirements, the manufacturer benefits from presumption of conformity only for those requirements covered by the standard. For the remaining requirements, the manufacturer must use alternative means to demonstrate compliance. The declaration of conformity must clearly identify which standards were applied and which requirements they address.
Related terms
Sector checklists covering Harmonised Standard
Browse the full CRA Compliance Checklist
See how Harmonised Standard fits into your complete CRA compliance programme.