Standards & alignment

Built on the standards that govern the CRA

The Cyber Resilience Act sits on a stack of European standards and bodies. Here is how the platform maps to each one, with an honest note on which confer presumption of conformity and which are supporting references.

CEN / CENELEC

EN 40000 series

The horizontal harmonised standards CEN and CENELEC are drafting for the CRA. Part-by-part overview plus full clause mapping for vulnerability handling, so you are ready for presumption of conformity once the references are cited in the Official Journal.

Draft harmonised standardsDoes not confer CRA presumption
ETSI

EN 304 6xx vertical standards

The 18 product-specific CRA standards ETSI is drafting under M/606, one per Annex III category, from browsers and password managers to firewalls and hypervisors. Includes the Annex III and Annex IV points ETSI does not cover and the CENELEC operational-technology and semiconductor alternatives.

Draft vertical standardsDoes not confer CRA presumption
ENISA

ENISA, the EUVD & Article 14

How the platform aligns with ENISA's Single Reporting Platform, the European Vulnerability Database, and national CSIRTs. Includes a live EUVD feed.

Regulatory infrastructureNot a conformity standard
ETSI

ETSI EN 303 645

The consumer-IoT security baseline that accredited labs test against. All 13 provisions mapped to CRA Annex I evidence.

Supporting standardDoes not confer CRA presumption
ISO/IEC · IEC

ISO/IEC 27001 & IEC 62443

The ISMS and industrial-security standards manufacturers most often already hold, mapped to CRA process and product requirements.

Supporting standardsDoes not confer CRA presumption
NIST / OSCAL

OSCAL catalog

The CRA vulnerability-handling requirements expressed as a machine-readable OSCAL catalog for automated compliance tooling.

Machine-readable catalogNot a conformity standard
CRA Article 32

Notified bodies & testing labs

Directory of EU conformity-assessment bodies and cybersecurity testing laboratories, filterable by country and standard. Verify designation in NANDO.

Ecosystem directoryNot a conformity standard

One platform across the whole standards stack

Threat modelling, SBOM tracking, vulnerability handling, Article 14 reporting, and technical-file assembly, all mapped to the standards above.

Get Started for Free