CRA norms delayed what manufacturers must do now

Harmonized standards for the Cyber Resilience Act will be ready later than planned, increasing pressure on manufacturers. This explains the planned deadline changes and what you should do now.

For context The Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to meet basic cybersecurity requirements. Harmonized standards are intended to simplify demonstrating compliance because using them creates a presumption of conformity. For that presumption to apply, each standard must be completed on time and listed in the EU Official Journal. That timeliness is exactly where the problem lies.

The Commission has not made a final decision. It published a draft amendment to the standardization mandate for consultation. That mandate was originally issued as Commission Implementing Decision C(2025)618 of 3 February 2025 to the three European standardization bodies CEN, CENELEC and ETSI. It carries the official mandate number M/606 and specifies which standards will be developed for the CRA and when they must be delivered.

The draft amendment changes only one substantive point in that mandate: it replaces Annex I of the standardization mandate, i.e., the list of standards with their delivery deadlines. Annex II, which describes the substantive requirements for the standards, remains unchanged. So the change concerns the timetable only, not the substance of the standards.

The trigger was a joint half-year report from CEN/CENELEC and ETSI dated 3 December 2025. In that report the standardization bodies informed the Commission about developments that affect the schedule of certain activities. After reviewing the report, the Commission considers a limited timetable adjustment to be appropriate, citing procedural and technical difficulties.

Why the draft is not yet in force

Important for practice: this draft amendment is not law. The document explicitly states that it has neither been adopted nor confirmed by the European Commission. Until adoption, the original mandate of 3 February 2025 with its initial deadlines remains binding.

The procedure also contains a condition: if CEN notifies within one month of receipt that it does not accept the amendment, the amendment will not take effect and the original version of 3 February 2025 will continue to apply unchanged. As long as neither the Commission’s adoption nor the consent of the standardization organizations is certain, you should treat the new deadlines as planned but not guaranteed.

Which CRA standards are delayed specifically?

The standardization mandate divides the standards into three blocks: the horizontal standards for security requirements (items 1 to 14), a separate category for vulnerability handling (item 15) and the vertical standards for individual product categories (items 16 to 41). The draft does not shift deadlines across the board but targets specific items. The postponed deadlines are moved to the last day of the next month, i.e., by roughly two months. A large group remains unaffected. The table below compares the original delivery deadlines with the proposed new deadlines.

Standard group Original deadline Planned new deadline
Horizontal secure‑by‑design standard (Item 1) 30.08.2026 30.10.2026
Standard on vulnerability handling (Item 15) 30.08.2026 30.10.2026
26 vertical standards for individual product categories (Items 16 to 41) 30.10.2026 31.12.2026
13 remaining horizontal standards (Items 2 to 14) 30.10.2027 unchanged

Two standards are time‑critical: the horizontal secure‑by‑design standard and the vulnerability handling standard. Both were originally due by the end of August 2026 and are now due by the end of October 2026. The 26 vertical standards cover individual product categories such as operating systems, routers, password managers or smart‑home products.

The 13 remaining horizontal standards remain unchanged; they address other product properties such as protection against unauthorized access, data confidentiality or availability of functions. This group therefore does not move, even though its deadlines were already tight.

Timechart of CRA standard deadlines: The planned two‑month shift affects only part of the standards. The 13 remaining horizontal standards remain dangerously close to the CRA’s full applicability on 11 December 2027.

Is there enough time until 11 December 2027?

The Cyber Resilience Act applies in full from 11 December 2027. From that date products with digital elements must meet the basic cybersecurity requirements when they are placed on the EU market. The harmonized standards are meant to help with that.

But a standard being delivered to the Commission is not the same as it being available. After delivery, the Commission evaluates it and it must be listed in the EU Official Journal. Only with that listing does a standard give rise to the presumption of conformity.

This is where the unchanged deadline for the 13 horizontal standards becomes critical. Their delivery deadline remains 30 October 2027, only about six weeks before the CRA fully applies on 11 December 2027. There will be very little time between delivery and listing in the Official Journal. It is therefore realistic that some harmonized standards will not be listed by the key date.

For you as a manufacturer this means: you cannot rely on a complete set of harmonized standards being available on the key date to work from. If you tie your CRA preparation to the completion of the standards, you risk waiting until shortly before 11 December 2027.

What manufacturers should do now without waiting for the standards

The decisive message is: CRA obligations apply regardless of whether the harmonized standards are completed on time. The CRA obliges you to meet the basic cybersecurity requirements. The standards are one route to demonstrate conformity, but not the only one.

The presumption of conformity is only an evidentiary convenience. If the appropriate standard is missing or you do not fully apply it, you must demonstrate compliance by other means. For many standard products that route will be internal conformity assessment, where you document yourself that your product meets the requirements. The delay of the standards is therefore no reason to postpone preparation; if anything, it is a reason to set it up independently of the standards.

Specifically, you should start the processes that the CRA requires anyway:

  • Risk assessment. Analyze the cybersecurity risks of your product across its entire lifecycle. This is the basis for all further requirements.
  • Secure by design. Embed security in design, development and production so that the product achieves a risk‑appropriate security level.
  • Vulnerability handling. Build processes to identify, document and remediate vulnerabilities without undue delay, including a software bill of materials.
  • Technical documentation. Keep structured evidence to demonstrate your product’s conformity.

Building these processes takes months, not weeks. If you only start after the Official Journal listing of the standards, you will be under time pressure. If you start now, you can use the standards later for fine tuning rather than starting from scratch.

Why you can already use the draft standards today

Even if the standards are not yet final, draft versions already exist and are going through balloting in the standardization committees. These drafts already indicate the direction of the requirements and how the future standards will be structured.

You can align your processes to these drafts instead of waiting for the final publication. The effort is not wasted: the substantive requirements for the standards are fixed in the unchanged Annex II of the standardization mandate; only the timetable changes. If you know the drafts, you are not working blindly but toward a clearly defined target.

How to recognize a consultant who can really help now

When standards are delayed but the CRA deadline stands, the support you choose determines how much time advantage you gain. Assess a consultant by a factual criterion: do they participate in the standardization committees and do they have the current drafts?

The reason is simple: a consultant who only waits for the final standards does not know more than you. A consultant active in the committees has direct access to drafts, discussion statuses and foreseeable requirements and can align your processes reliably before publication.

Clarify this before hiring with three concrete questions: In which committees does the consultant participate? Which draft standards do they currently have? Can they name the requirements of the upcoming standards, or do they only refer to general CRA principles?

Conclusion

CRA standards are delayed, and the European Commission has responded with a draft amendment that moves deadlines for part of the standards by roughly two months. That draft is currently only a consultation; the original mandate remains binding until adoption. The 13 remaining horizontal standards keep their 30 October 2027 deadline, dangerously close to the CRA’s full applicability on 11 December 2027.

For manufacturers the delay changes little about the core task. CRA obligations apply regardless of the standards. Those who start now with risk assessment, secure by design, vulnerability handling and technical documentation and use the available draft standards as guidance will be prepared by the key date, whether or not the final standards are listed in time.