← Back to CRA Insights
CRA harmonised standards

CRA Harmonised Standards and the Presumption of Conformity: Where Things Stand in 2026

Generated image

The standards are arriving - just not quite yet. The European standardisation bodies are targeting delivery of the first CRA harmonised standards in the second half of 2026, with vertical product-specific standards close behind. But as of mid-2026, no CRA harmonised standard has been cited in the Official Journal of the European Union, which means the Article 27 presumption of conformity is not yet available for any product category. Full application of Regulation (EU) 2024/2847 is 11 December 2027. That gives manufacturers roughly 17 months - and the standards they will want to rely on may only land in the Official Journal a matter of months before that deadline.

This post explains what the presumption of conformity actually is, what the 41 standards under standardisation mandate M/606 cover, how the EN 18031 series relates, and - most practically - what you should be doing while the citations are still pending.

General guidance, not legal advice. This post explains the regulatory framework in plain English. The right compliance route for your specific product depends on its category, intended use, and technical architecture. For formal conformity assessment decisions, consult a qualified expert or notified body.


Key points

  • The presumption of conformity (Article 27) means a product that conforms to a cited harmonised standard is presumed to meet the corresponding CRA essential requirements in Annex I. It is a legal shortcut - not the only route to compliance.
  • The presumption only activates once the standard's reference is published in the Official Journal. A draft standard, however mature, does not trigger it.
  • CEN, CENELEC, and ETSI accepted Standardisation Request M/606 on 3 April 2025, committing to deliver around 41 harmonised standards for the CRA.
  • The ESOs are targeting the two core horizontal standards by 30 August 2026, vertical standards by 30 October 2026, and remaining horizontals by 30 October 2027 - but these are ESO targets, not binding CRA deadlines, and slippage is possible.
  • EN 18031 is a harmonised standard for the Radio Equipment Directive (RED), not the CRA. It is a useful working baseline for wireless product makers, but it is not sufficient on its own for CRA conformity.
  • While standards are in draft, you can still comply - by mapping your evidence directly to Annex I.

What "presumption of conformity" means (and why you want it)

The CRA follows the EU's New Legislative Framework model. The Regulation itself sets essential requirements - outcome-based obligations written in legal language (Annex I). It does not specify exactly how to build a secure product. That translation work is left to harmonised standards.

Article 27 of the CRA states that products conforming to a harmonised standard whose reference has been published in the Official Journal of the EU shall be presumed to meet the essential cybersecurity requirements in Annex I that those standards cover. In plain English: implement the standard correctly, and you get a legal presumption that you have met the law.

That presumption matters for two reasons.

First, it simplifies your evidence burden. Instead of constructing a bespoke argument that your product meets each Annex I requirement, you can point to your conformity with the standard. The standard has already done the mapping.

Second, it unlocks self-assessment for many products. For Default (unclassified) products, the standard conformity assessment route is Module A - internal production control, no notified body required. Harmonised standards make that self-assessment route far more defensible. (For a full explanation of the assessment routes and when a notified body is mandatory, see our guide to conformity assessment.)

star Important

The presumption of conformity is not the only route to compliance. You can demonstrate conformity with Annex I directly — through your own technical documentation, risk assessment, and evidence — without relying on any standard. The standard is a tool that makes the job easier and the evidence more robust, not a prerequisite for building a compliant product.

There is one further nuance worth knowing: harmonised standards may be cited with restrictions. Where a standard contains restricted clauses - provisions that do not fully satisfy the essential requirements - the presumption of conformity applies only to the unrestricted parts. A product triggering a restricted clause needs additional evidence or notified body involvement for that element.


The 41 standards under mandate M/606

The European Commission's standardisation request M/606 was formally accepted by CEN, CENELEC, and ETSI in April 2025. It covers around 41 standards, split into two broad families.

Horizontal standards are product-agnostic. They set the common framework, methodology, and taxonomy that applies to every product with digital elements. The core horizontal work is led by CEN and CENELEC, primarily through CEN-CLC/JTC 13 Working Group 9, and is organised under the EN 40000 series:

  • EN 40000-1-1 - Vocabulary
  • EN 40000-1-2 - Cyber resilience principles
  • EN 40000-1-3 - Vulnerability handling
  • EN 40000-1-4 - Generic security requirements (the broadest and most technically demanding part)

As of mid-2026, the first three parts (vocabulary, principles, vulnerability handling) have completed public enquiry and are under approval. The fourth part - generic security requirements (prEN 40000-1-4) - is still under drafting, with a target delivery date of 30 October 2027.

Vertical standards are product-specific. They cover the particular risks of one product type - routers, antivirus software, smart home devices, browsers, and so on. ETSI is leading this work through its EUSR group, using the EN 304 6xx numbering series. ETSI has released interim drafts for 18 product categories for public consultation; these are freely accessible on the ETSI Open Area.

M/606 Standards: Structure at a Glance
TypeSeries / NumberingLead BodyScopeESO Target Date
Horizontal (core)EN 40000-1-1 to -1-3CEN/CENELEC (JTC 13 WG 9)All products with digital elements30 Aug 2026
Vertical (product-specific)EN 304 6xxETSI EUSR18 named product categories (Annex III/IV)30 Oct 2026
Horizontal (generic security requirements)EN 40000-1-4CEN/CENELEC (JTC 13 WG 9)All products with digital elements30 Oct 2027
info Note

All dates in the table above are ESO delivery targets from the M/606 acceptance, not binding CRA deadlines. Ratification as a final EN and the separate Official Journal citation are additional steps after delivery. The Commission has not confirmed OJ citation dates. Treat these as planning anchors, not guarantees.


Where EN 18031 fits

The EN 18031 series - EN 18031-1, -2, and -3 - is a harmonised standard for the Radio Equipment Directive (RED), not the CRA. It was developed to support the cybersecurity requirements activated by Delegated Regulation (EU) 2022/30 under the RED. EN 18031 references were published in the Official Journal on 28 January 2025, and compliance with the RED cybersecurity requirements became mandatory for radio equipment on 1 August 2025.

CEN-CENELEC has explicitly noted that the EN 18031 series establishes a foundation for the development of CRA harmonised standards. In practical terms, several CRA horizontal standards build on EN 18031's structure and controls, adding requirements to cover the broader CRA scope - products that are not radio equipment, wired devices, pure software, and so on.

What this means for you depends on your product:

  • If your product is radio equipment (Wi-Fi, Bluetooth, cellular, etc.), you should already be compliant with EN 18031 under the RED. That work is directly reusable as a baseline for CRA compliance - but it is not sufficient on its own. The CRA adds obligations EN 18031 does not cover: vulnerability disclosure processes, SBOM requirements, support period commitments, and more.
  • If your product is not radio equipment, EN 18031 is still a useful technical reference for understanding the direction of CRA horizontal standards - but it carries no legal weight for your CRA conformity assessment.

The key point: EN 18031 is a stepping stone, not a destination. It is a RED standard. Using it for CRA purposes is a practical shortcut for wireless product makers, not a compliance route in its own right.

For a detailed comparison of what the RED cybersecurity requirements cover versus what the CRA adds, see our guide RED Cybersecurity Done - What Does the CRA Add?.


The 2026-2027 timeline (and why it might slip)

Here is the honest picture of where things stand, as of mid-2026.

The ESOs are targeting delivery of the two core horizontal standards (secure development and vulnerability handling) by 30 August 2026. Vertical standards for the product categories listed in Annexes III and IV are targeted by 30 October 2026. The remaining horizontal standard - EN 40000-1-4, covering generic security requirements - is targeted by 30 October 2027, roughly six weeks before full CRA application.

There is a further step after delivery that is easy to overlook: Official Journal citation. Even once a standard is ratified as a final EN, the Commission must assess it and publish its reference in the OJ before the presumption of conformity activates. The Commission has not confirmed OJ citation dates. Based on the EC's own FAQ, the first harmonised standards are expected to be published in the Official Journal around Q2 2027 - meaning the window between OJ citation and the December 2027 deadline could be tight.

Why might it slip? Standards development at this scale is complex. Public enquiry feedback must be resolved, national bodies must vote, and the Commission's assessment adds further time. The EN 40000-1-4 generic security requirements standard - arguably the most important for most manufacturers - is still under drafting as of mid-2026. Any delay there pushes the OJ citation further out.

The practical implication: do not build your compliance plan around having cited standards available well in advance of December 2027. Plan as if you may need to demonstrate conformity directly against Annex I, and treat the standards as a welcome simplification when they arrive.


What to do while the standards are still in draft

The absence of cited standards does not prevent compliance. Here is a concrete sequence.

1
Map your product to Annex I now

Work through both parts of Annex I — Part I (security properties) and Part II (vulnerability-handling processes) — and document how your product and processes address each requirement. This is the direct-conformity route and it is valid regardless of whether standards exist. See our technical documentation guide for what to record.

2
Use draft standards as a working baseline

The EN 40000 drafts and ETSI's EN 304 6xx vertical drafts are publicly available. They are not yet citeable for presumption-of-conformity purposes, but they are the best available signal of where the final requirements will land. Use them to stress-test your Annex I mapping and identify gaps. Flag in your documentation that you are referencing a draft, not a cited standard.

3
Treat EN 18031 as a head start (wireless products only)

If your product is radio equipment and you have completed EN 18031 compliance, extract that technical work and map it to the CRA Annex I requirements it covers. Identify the delta — the CRA obligations EN 18031 does not address — and document your approach to those gaps.

4
Keep your technical documentation update-ready

Structure your technical file so that the section referencing standards can be updated cleanly once OJ citations are published. You do not want to rebuild the whole document — just swap in the standard reference and confirm your conformity against the final (not draft) text. See our technical documentation guide.

5
Watch the Official Journal and the Commission's standardisation page

The Commission's CRA standardisation page is the authoritative source for citation notices. Set up an alert. The moment a standard's reference is published in the OJ, the presumption of conformity activates for products that conform to it — and your documentation should be ready to reflect that.

6
Check your product class

The standards that matter most for your product depend on whether it is Default, Important (Class I or II), or Critical. Vertical standards under EN 304 6xx are specifically targeted at Important and Critical categories. If you have not yet confirmed your product class, use our product class guide or the deadlines page for the full timeline.

lightbulb Tip

Subscribe to The CRA Brief — our free newsletter tracks every Official Journal citation, draft publication, and Commission guidance update as it happens. When the first CRA harmonised standards are cited, you will want to know the same day.


Settled vs. still developing

It helps to be clear about what is fixed and what is not.

Settled:

  • The legal text of Regulation (EU) 2024/2847 and its Annex I essential requirements.
  • The Article 27 presumption-of-conformity mechanism - the legal rule is in place; it is just waiting for standards to cite.
  • M/606 was accepted by CEN, CENELEC, and ETSI on 3 April 2025, covering around 41 standards.
  • EN 18031 is cited in the OJ as a RED harmonised standard (since January 2025) and is mandatory for radio equipment (since August 2025). Its status as a RED standard is settled.
  • The full CRA application date of 11 December 2027 is fixed.

Still developing:

  • Which specific standards will be cited in the OJ, and when - the Commission has not confirmed citation dates.
  • The final text of EN 40000-1-4 (generic security requirements) - still under drafting as of mid-2026.
  • Whether any standards will be cited with restrictions, and what those restrictions will cover.
  • The exact scope of vertical standards for specific product categories - drafts are available but not final.

Where to go next