Harmonized standards for the CRA EN 40000, ETSI and EN 50770

Which harmonized standards apply to the CRA? An overview of the EN 40000 series, ETSI EN 304 6xx and EN 50770: structure, status and what they mean for manufacturers.

For manufacturers there will not be a single “CRA standard” but rather a landscape of standards made up of several series: the horizontal EN‑40000 series for all products with digital elements, product‑specific ETSI standards for IT and consumer products, and the EN‑50770 series for OT products based on IEC 62443. This article explains which standards series are currently in preparation, how they interact and what manufacturers should already prepare before any listing in the Official Journal.

The presumption of conformity is the real lever behind harmonized standards. If a product with digital elements and the procedures defined by the manufacturer comply with a harmonized standard whose reference is published in the Official Journal, conformity with the essential requirements from Annex I is presumed, insofar as the standard covers those requirements.

As long as such a standard is missing, the Commission can adopt common specifications by implementing act. Compliance with those specifications can likewise satisfy the essential requirements. For manufacturers this means: the standards route is the preferred but not the only path to a presumption of conformity.

Important: the CRA applies regardless of whether standards are harmonized in time. If a listed standard is missing, only the convenient proof route via the presumption of conformity is unavailable. The requirements remain binding and must still be demonstrated by the manufacturer with their own technical and organizational evidence.

What is the standardization work for the CRA?

Standardization is progressing in three strands, driven by the European standards organizations CEN, CENELEC and ETSI. One horizontal strand applies to all products with digital elements; two vertical strands address specific product groups: one for IT and consumer products and one for operational technology (OT).

Strand Standards series Addressed products Basis
Horizontal EN 40000 series All products with digital elements Basic requirements
Vertical IT/consumer ETSI EN 304 6xx IT and consumer products Product specific
Vertical OT EN 50770 series OT products based on IEC 62443

All three series are still under development and currently exist only as drafts. Concrete harmonization or listing dates have not yet been set.

Horizontal standards EN 40000 series

The EN‑40000 series is the horizontal base. It is intended to apply to all products with digital elements, regardless of product category. Four parts form the normative core, supplemented by an informative Technical Report. See EN‑40000‑Reihe for a deeper classification.

Part Function
EN 40000-1-1 Terms and definitions for the entire series
EN 40000-1-2 Principles for cyber resilience
EN 40000-1-3 Vulnerability handling
EN 40000-1-4 Generic security requirements
EN TR 40000-1-5 Threats and protection objectives (informative)

For manufacturers the most relevant parts are likely EN 40000‑1‑2, EN 40000‑1‑3 and EN 40000‑1‑4: principles and processes, vulnerability handling and generic security requirements will probably be central areas for evidence.

Vertical standards for IT and consumer products ETSI EN 304 6xx

A vertical series under the label ETSI EN 304 6xx is being developed for IT and consumer products. It addresses individual product types with their own product‑specific requirements. Product types listed in the status overview include browsers, password managers, VPN solutions, SIEM systems, operating systems, and routers and switches.

The drafts in this series are still at an early stage. They already show the planned structure and initial product‑specific directions but should not yet be treated as a stable basis for requirements. See ETSI‑Normenentwürfe zum CRA for an overview of the first ETSI draft standards for the CRA.

Vertical standards for OT EN 50770 series

The EN‑50770 series is being developed for operational technology. It is particularly relevant for machine builders, automation vendors and suppliers of industrial components. The series defines security profiles for OT products, explicitly based on IEC 62443. The individual parts cover product groups such as VPN solutions, network management systems, SIEM systems, physical and virtual network interfaces, routers and switches, as well as firewalls, intrusion detection and intrusion prevention systems.

This OT strand is supported by annex adaptations (prAA) of selected IEC 62443 parts: IEC 62443‑3‑3 (system requirements), IEC 62443‑4‑1 (secure product development process) and IEC 62443‑4‑2 (technical component requirements). These serve as supporting standards for the vertical OT standards. The EN‑50770 series is also currently a draft.

How far along is your product with the CRA?

The CRA‑Readiness‑Check shows in a few minutes which Annex I requirements you already meet and where gaps remain.

How do IEC 62443 and EN 18031 fit in?

IEC 62443 is the established family of standards for the security of industrial automation and control systems and forms the basis of the OT strand. Formally it is still open what role IEC 62443 will take within the CRA harmonization framework. In practice it remains a central reference point for OT manufacturers because the EN‑50770 series explicitly builds on IEC 62443. See IEC 62443 für den CRA for the broader context.

EN 18031 provides another reference point. It is already used as a source of terminology in the current CRA draft standards. For manufacturers whose products communicate wirelessly, it thus offers a potential reference point for the later transition from the Radio Equipment Directive to the CRA. The role EN 18031 will play in that transition depends on the CRA standards that are still pending. Details are available in EN 18031 and in the Radio Equipment Directive article. For connected consumer products there is also the ETSI EN 303 645 cybersecurity standard.

What does the current status mean for manufacturers?

As long as no CRA standard is listed in the Official Journal of the European Union, the presumption of conformity via harmonized standards does not apply. That does not mean manufacturers should wait. The essential requirements from Annex I of the Cyber Resilience Act remain binding and must be demonstrated as part of the conformity assessment.

The current draft standards already indicate the direction the later evidence will take. Manufacturers can therefore already check which standards strand is relevant for their products and which existing evidence can be used. Crucial is not only which standard will later be harmonized, but how the evidence can be credibly provided until then.

A pragmatic approach for manufacturers is therefore:

  • Classify the product as a product with digital elements under the CRA
  • Check the product class: standard product, important product or critical product
  • Determine the appropriate standards series: horizontal, IT/consumer‑specific or OT‑specific
  • Evaluate existing evidence from IEC 62443, EN 18031, ETSI EN 303 645 or internal development processes
  • Derive gaps relative to Annex I, vulnerability handling and technical documentation
  • Decide how evidence will be provided until harmonized standards are listed

The most common pitfall is waiting for final standards. The CRA’s entry into force does not depend on whether harmonized standards are already listed. Those who only build vulnerability handling, a secure development process, technical documentation and product evidence later will lose the time needed to establish exactly those structures.

Conclusion and outlook

The CRA standards landscape is organized along three strands: horizontally via the EN‑40000 series, vertically via the ETSI EN 304 6xx series for IT and consumer products, and via the EN‑50770 series for OT. None of the three series has been finalized and listing in the Official Journal is still pending. The message for manufacturers is clear: the direction is set, evidence is based on Annex I until listing, and building the underlying processes is worthwhile now. The overall framework of the Cyber Resilience Act is summarized on the CRA overview page.

Which standard applies to your product?

We can tell you which of the three series applies to your products and how to provide evidence until one is listed in the Official Journal.