ETSI Opens Public Enquiry on 17 Vertical CRA Standards: What "Important" Product Makers Should Do Now

TL;DR: On 13 August 2026, ETSI opened the Public Enquiry on 17 final draft vertical standards - the EN 304 series - covering specific Annex III "important" product categories under the CRA. The drafts are freely readable today. None is a harmonised standard yet, and none confers a presumption of conformity. Your immediate actions: find your vertical, read the draft, consider submitting comments via your national standardisation body before the window closes (mid-September to mid-November, depending on your category), and keep building Annex I evidence regardless.
What happened on 13 August 2026
On 13 August 2026, ETSI opened the Public Enquiry - the formal first phase of the approval procedure - on 17 vertical final draft European Standards developed to support the Cyber Resilience Act. These are the EN 304 xxx series, each written for a specific Annex III product category.
This is a formal procedural step, not a press release milestone. Public Enquiry means the drafts have been submitted to national standardisation bodies across the EEA for structured comment. It is the last stage before a standard can be ratified as an EN - and ratification is itself still not the finish line (more on that below).
The ETSI press release and the cyberresilienceact.eu draft standards tracker both confirm the details.
These are vertical standards - different from the M/606 horizontal work
If you've been following the horizontal EN 40000 series under Standardisation Request M/606, these are a separate track. The horizontal standards set the Annex I baseline requirements that apply to every product with digital elements. The vertical EN 304 series goes further: each standard is written for one specific product category listed in Annex III as "important."
Think of it this way: the horizontal standards tell every manufacturer what the floor looks like. The vertical standards tell manufacturers of VPNs, password managers, or connected toys what the category-specific ceiling looks like on top of that floor.
We covered the horizontal M/606 status in our earlier post. This post is specifically about the 17 vertical drafts now under Public Enquiry.
Which products do the 17 drafts cover?
The 17 final draft standards under Public Enquiry cover the following Annex III product categories:
| Standard | Product Category | Annex III Class |
|---|---|---|
| EN 304 617 | Browsers | Class I |
| EN 304 618 | Password managers | Class I |
| EN 304 619 | Antivirus / antimalware software | Class I |
| EN 304 620 | Virtual Private Networks (VPNs) | Class I |
| EN 304 621 | Network Management Systems (NMS) | Class I |
| EN 304 622 | Security Information and Event Management (SIEM) | Class I |
| EN 304 623 | Boot managers | Class I |
| EN 304 624 | PKI and digital certificate issuance software | Class I |
| EN 304 625 | Physical and virtual network interfaces | Class I |
| EN 304 626 | Operating systems | Class I |
| EN 304 627 | Routers, modems, and switches | Class I |
| EN 304 631 | Smart home general-purpose virtual assistants | Class I |
| EN 304 632 | Smart home products with security functionalities (door locks, cameras, baby monitors, alarms) | Class I |
| EN 304 633 | Internet-connected toys | Class I |
| EN 304 634 | Personal wearable products | Class I |
| EN 304 635 | Hypervisors and container runtimes | Class I |
| EN 304 636 | Firewalls, IDS and IPS | Class II |
If your product appears in this list, there is now a final draft standard written specifically for it. Reading it is free and takes priority over everything else in this post.
Not sure whether your product falls into Annex III at all? The cyberresilienceact.eu draft standards tracker includes a classification finder. If your product lands in the default tier, none of these vertical standards applies to you - the horizontal Annex I baseline work is what matters instead.
What "Public Enquiry" actually means - and what it doesn't
Public Enquiry is the first phase of ETSI's formal approval procedure. Here is what that means in plain terms:
- The drafts are final drafts, not finished standards. The wording can still change. Do not treat any clause as locked.
- They are not harmonised standards. No CRA standard has yet been cited in the Official Journal of the EU, so none of the EN 304 drafts currently confers the Article 27 presumption of conformity. That step - citation in the Official Journal - comes after ratification, and the Commission has not confirmed a timetable for it.
- No notified bodies are listed in NANDO yet for CRA conformity assessment. The infrastructure for third-party certification is still being built.
- The drafts are freely readable. Anyone can download them from the ETSI open area. You do not need to be an ETSI member to read them.
The path from here to a harmonised standard that actually triggers presumption of conformity runs: Public Enquiry -> national body votes -> ratification as EN -> Commission citation in the Official Journal. The final versions of the 17 standards are expected to be available by December 2026. Citation in the Official Journal would follow after that, on a timeline the Commission has not yet set.
Reading a draft standard is useful preparation. Relying on it as if it were a harmonised standard is not. The presumption of conformity under Article 27 is not available until a standard's reference appears in the Official Journal — and that has not happened for any CRA standard yet.
The comment window: what it is and how to use it
The comment window runs from mid-September to mid-November 2026, with the exact closing date varying by vertical. Different product categories have different deadlines - check the specific closing date for your standard, not a generic date.
An individual manufacturer is not on the list of bodies that can file comments directly. The route is through your national standardisation body (the NSB in your country - DIN in Germany, BSI in the UK, AFNOR in France, and so on) or through ETSI membership. ETSI's societal partners - ANEC, ECOS, ETUC, and SBS - can also comment, which puts consumer, environmental, labour, and small-business perspectives on the record.
If you have a substantive technical concern about how a requirement is framed for your product category, now is the time to raise it. Once the standard is ratified, the wording is fixed until the next revision cycle.
If you don't know how to submit through your NSB, ETSI has indicated you can email cybersupport@etsi.org for guidance.
What to do right now - a practical sequence
Use the widget below to find your vertical and check the comment deadline, then work through this sequence:
Step 1 - Confirm your classification. Verify that your product is in Annex III and identify whether it is Class I or Class II. Your conformity assessment route depends on this, regardless of what the standards say.
Step 2 - Read the relevant vertical draft. Download the PDF from the ETSI open area (docbox.etsi.org/CYBER/EUSR/Open). Focus on the normative requirements and the Annex I mapping table, which shows how the vertical requirements relate to the baseline Annex I obligations.
Step 3 - Gap-assess against your current Annex I evidence. The vertical draft will likely surface category-specific requirements you haven't yet documented. Map them against your existing technical file evidence now, while the standard can still change in response to comments.
Step 4 - Decide whether to comment. If you find a requirement that is technically unworkable, ambiguous, or inconsistent with how your product category actually operates, contact your national standardisation body. This is the last practical opportunity to influence the wording before ratification.
Step 5 - Do not wait for the final standard to build evidence. The Annex I requirements in the CRA itself are fixed law. The standard, once harmonised, will provide a presumption of conformity - but you need to comply with Annex I regardless of whether a standard exists. Build your technical documentation against the regulation now.
One deadline that is not affected by any of this
The vulnerability and incident reporting obligations under Article 14 apply from 11 September 2026 - that is weeks away, not months. The standards process has no bearing on that deadline. If you have not yet confirmed your reporting setup, that takes priority over everything in this post.
Full CRA compliance - including conformity assessment and CE marking - is required by 11 December 2027.
The bottom line
Seventeen vertical final draft standards are now publicly readable and open for comment. If your product is in Annex III, there is a draft written specifically for it. Read it. Consider whether you have comments worth submitting through your national body before the window closes. And keep building your Annex I evidence - the standard, when it eventually becomes harmonised, will make conformity easier to demonstrate, but it will not change what the law already requires.
We'll track the comment window deadlines and any wording changes as the approval procedure progresses.
Related reading

How to Generate Your First CRA-Ready SBOM: A Practical Tool Guide
Pick a format, run a generator, store the file. A hands-on guide to generating a CRA-compliant SBOM this week using cdxgen, Syft, Trivy, and Tern.

CRA vs. US Cyber Trust Mark: A Manufacturer's Side-by-Side Guide
Selling connected products in both the EU and US? Here's how the mandatory CRA compares to the voluntary Cyber Trust Mark - and where your compliance work overlaps.

How to Turn Your ENISA Maturity Score Into a CRA Action Plan
ENISA's free July 2026 SME Cyber Resilience Maturity Assessment Model gives you a score - but a score alone won't get you compliant. Here's how to translate each domain result into sequenced CRA work.