The harmonized standards for the Cyber Resilience Act will be ready later than planned. This explains what the new deadlines mean for your CRA preparation and why you should act now.
For context
The Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to meet basic cybersecurity requirements. Harmonized standards are intended to simplify proof of conformity because their application gives rise to a presumption of conformity. For that presumption to apply, a given standard must be completed on time and listed in the EU Official Journal. It is precisely this timeliness that is now in question.
The Commission has not made a final decision. It has put a draft amendment to the standardization mandate out for consultation. That mandate was originally issued as Commission Implementing Decision C(2025)618 of 3 February 2025 to the three European standardization organizations CEN, CENELEC and ETSI. It bears the official mandate reference M/606 and specifies which standards for the CRA are to be developed and by when they must be delivered.
The draft amendment changes only one substantive point of that mandate: it replaces Annex I of the standardization mandate, i.e. the list of standards with their delivery deadlines. Annex II, which describes the substantive requirements for the standards, remains unchanged. So this is exclusively about the schedule, not the substance of the standards.
The trigger is a joint semi-annual report from CEN/CENELEC and ETSI dated 3 December 2025. In it, the standardization organizations informed the Commission of developments affecting the timetable for certain activities. After reviewing the report, the Commission considers a limited adjustment of the timetable appropriate, citing procedural and technical difficulties.
Why the draft is not yet in force
Important for practice: this draft amendment is not applicable law. The document explicitly states that it has neither been adopted nor confirmed by the European Commission. Binding remains, until adoption, the version of the mandate dated 3 February 2025 with the original deadlines.
The procedure also includes a condition: if CEN informs within one month of receipt that it does not accept the amendment, the amendment decision does not enter into force and the original version of 3 February 2025 continues to apply unchanged. So as long as neither adoption by the Commission nor the consent of the standardization organizations is certain, you should treat the new deadlines as planned but not guaranteed.
Which CRA standards are delayed specifically
The standardization mandate divides the standards into three blocks: the horizontal standards for security requirements (items 1 to 14), a separate category for vulnerability handling (item 15) and the vertical standards for individual product categories (items 16 to 41). The draft does not postpone deadlines across the board but selectively. The postponed deadlines are each moved to the last day of the next month, i.e. by about two months. A large group remains unaffected. The table below compares the original delivery deadline with the planned new deadline.
| Norm group | Original deadline | Planned new deadline |
|---|---|---|
| Horizontal secure-by-design standard (Item 1) | 30.08.2026 | 30.10.2026 |
| Standard for vulnerability handling (Vulnerability Handling, Item 15) | 30.08.2026 | 30.10.2026 |
| 26 vertical standards for individual product categories (Items 16 to 41) | 30.10.2026 | 31.12.2026 |
| 13 remaining horizontal standards (Items 2 to 14) | 30.10.2027 | unchanged |
Two standards are time-critical: the horizontal secure-by-design standard and the standard for vulnerability handling. Both were originally due at the end of August 2026 and are now scheduled for the end of October 2026. The 26 vertical standards cover individual product categories such as operating systems, routers, password managers or smart home products.
Unchanged are the 13 remaining horizontal standards, which cover further product properties such as protection against unauthorized access, data confidentiality or the availability of functions. This group therefore does not shift, even though its timing was already the tightest.
Is there still enough time until 11 December 2027?
The Cyber Resilience Act becomes fully applicable from 11 December 2027. From that date, products with digital elements placed on the EU market must meet the basic cybersecurity requirements. Harmonized standards are intended to help with that.
However, for the presumption of conformity to arise it is not enough that a standard is delivered to the Commission. The delivery deadline to the Commission is not the same as the availability of the standard. After delivery, the Commission evaluates the standard and lists it in the EU Official Journal. Only with that listing does a standard create the presumption of conformity.
This is where the unchanged deadline of the 13 horizontal standards becomes critical. Their delivery deadline remains 30 October 2027, i.e. only about six weeks before the CRA becomes fully applicable on 11 December 2027. There will be hardly any time between delivery and listing in the Official Journal in this window. It is therefore realistic that some of the harmonized standards will not be available as listed standards by the cut-off date.
For you as a manufacturer this means: you cannot rely on a complete set of harmonized standards being available on the cut-off date for you to work through. Anyone who ties their CRA preparation to the completion of the standards risks being stuck in limbo right up until 11 December 2027.
Zeitstrahl der CRA-Normfristen: Die geplante Verschiebung um zwei Monate betrifft nur einen Teil der Normen. Die 13 übrigen horizontalen Normen bleiben mit dem 30. Oktober 2027 gefährlich nah an der vollen CRA-Anwendbarkeit am 11. Dezember 2027.
What manufacturers should do now without waiting for the standards
The key message is: CRA obligations apply regardless of whether the harmonized standards are completed on time. The CRA obliges you to comply with the basic cybersecurity requirements. The standards are one way to demonstrate conformity, but not the only way.
The presumption of conformity is only an evidential simplification. If the appropriate standard is missing or you do not fully apply it, you must demonstrate compliance with the requirements by other means. For many standard products, that route leads to internal conformity assessment, where you document yourself that your product meets the requirements. The delay of the standards is therefore not a reason to postpone preparation, but a reason to set it up independently of the standards.
Concretely, you should now start the processes that the CRA requires anyway:
- Risk assessment. Systematically analyse your product’s cybersecurity risks across the entire lifecycle. This is the basis for all further requirements.
- Secure by design. Anchor cybersecurity in design, development and production so the product reaches a risk-appropriate level of security.
- Vulnerability handling. Build processes to identify, document and remediate vulnerabilities without unnecessary delay, including a software bill of materials.
- Technical documentation. Keep structured evidence with which you can demonstrate your product’s conformity.
Building these processes takes months, not weeks. Those who only start after the standards are listed in the Official Journal will be under time pressure. Those who start now can use the standards later for fine-tuning instead of starting from scratch.
Why you can already use the draft standards today
Even if the standards are not yet officially finished, the draft standards already exist and are going through the consultations in the standardization committees. These drafts already show the direction of the requirements and how the future standards will be structured.
You can align your processes with these drafts instead of waiting for the final publication. The effort is not wasted: the substantive requirements for the standards are fixed in the unchanged Annex II of the standardization mandate; only the timetable is being adjusted. Those familiar with the drafts therefore do not work into the void but toward a clearly defined target.
How to recognise a consultant who can really help now
If the standards are delayed but the CRA deadline stands, your choice of support determines how much time you gain. Assess a consultant by a factual criterion: do they participate in the standardization committees and do they have the current drafts?
The reason is simple: a consultant who only waits for the final standards does not know more than you. Someone active in the committees knows drafts, discussion statuses and foreseeable requirements first-hand and can align your processes reliably before publication.
Clarify this before commissioning with three concrete questions: In which committees does the consultant participate? Which draft standards are currently available to them? Can they name the requirements of the upcoming standards, or do they only refer to general CRA principles?
Conclusion
The CRA standards are delayed, and the European Commission has reacted with a draft that pushes the deadlines for part of the standards by about two months. This draft amendment is so far only a consultation version; binding remains the original wording of the standardization mandate. The 13 remaining horizontal standards keep their 30 October 2027 deadline, dangerously close to the full CRA applicability on 11 December 2027.
For manufacturers the postponement changes little about the core task. CRA obligations apply regardless of the standards. Those who now begin with risk assessment, secure by design, vulnerability handling and technical documentation and use the existing draft standards as guidance will be prepared by the cut-off date, whether or not the final standards are listed in time.