Key Takeaways
- The EU Cyber Resilience Act (CRA) will become fully enforceable in December 2027, affecting all hardware and software placed on the EU market.
- ETSI has released draft cybersecurity standards for 17 product categories that manufacturers must meet to achieve CRA compliance.
- The standards mandate modern cryptography, secure‑by‑default configurations, a software bill of materials (SBOM), and reliable post‑sale update mechanisms.
- Draft documents have been submitted to 41 European member organizations and are now under public enquiry, with stakeholder comments accepted until mid‑September to mid‑November 2026, depending on the sector.
- Final versions of the 17 standards are expected by December 2026, giving industry roughly one year to adapt before the CRA deadline.
- Compliance obligations extend to manufacturers, importers, distributors, service providers, and developers of commercially available products sold in the EU.
- ETSI, together with CEN and CENELEC, is organizing workshops across Europe to help small and medium‑sized enterprises (SMEs) meet the new requirements.
- Recent surveys indicate that two‑thirds of the open‑source community remain unaware of the CRA, highlighting a significant awareness gap that must be addressed.
Overview of the EU Cyber Resilience Act Timeline
The European Union’s Cyber Resilience Act (CRA) establishes a harmonized cybersecurity framework for products with digital elements sold within the EU. After a transitional period, the regulation will reach full application in December 2027, at which point non‑compliant goods will be barred from the market. The CRA imposes obligations on economic operators throughout the supply chain, requiring them to ensure that products are designed, produced, and maintained with a baseline level of cybersecurity. This timeline gives manufacturers roughly three years from the standards’ finalization to adjust their processes, obtain conformity assessments, and update documentation before the enforcement date. Understanding this schedule is critical for strategic planning, resource allocation, and risk management across industries that rely on networked devices, edge computing hardware, and IoT appliances.
ETSI’s Role and the Approval Process for Cybersecurity Standards
As one of the three EU‑recognized standardization bodies, the European Telecommunications Standards Institute (ETSI) leads the development of the technical specifications that will define CRA compliance. ETSI launched an approval process for 17 key cybersecurity standards, translating the high‑level legal requirements of the CRA into concrete, testable criteria. The institute’s work involves drafting, reviewing, and harmonizing these standards with input from industry experts, national standardization bodies, and other stakeholders. Once the drafts are mature, they are submitted to the broader European standardization system for formal adoption, ensuring that the resulting documents possess the authority needed for regulatory conformity assessment. ETSI’s coordination with CEN and CENELEC guarantees that the standards cover both telecommunications‑focused and broader electrotechnical domains, providing a comprehensive baseline for product security.
The Seventeen Product Categories Covered
The draft standards address 17 major product groups that span the breadth of today’s connected ecosystem. These categories include network infrastructure equipment (routers, switches, firewalls), edge computing gateways, security solutions (antivirus, intrusion detection systems), and a wide array of Internet‑of‑Things (IoT) appliances such as smart home devices, industrial sensors, and wearable technology. By encompassing both hardware and software components, the framework aims to close security gaps that could be exploited at any layer of the product stack. Each category receives tailored requirements that reflect its specific risk profile while maintaining a common set of baseline controls. This sector‑specific approach allows manufacturers to focus on the most relevant threats without being burdened by unnecessary or irrelevant provisions.
Core Security Requirements Mandated by the Draft Standards
At the heart of the proposed standards are several non‑negotiable security features that manufacturers must implement. Modern cryptography—using algorithms approved by EU authorities and resistant to known attacks—is required for data at rest and in transit. Secure‑by‑default settings ensure that devices ship with the strongest feasible configuration, minimizing the need for end‑users to harden systems manually. A software bill of materials (SBOM) must be provided in a machine‑readable format, enabling rapid vulnerability identification and supply‑chain transparency. Finally, the standards demand robust post‑sale update capabilities, including authenticated over‑the‑air (OTA) patches and a clear lifecycle management plan, so that known flaws can be remedied throughout the product’s operational life. Together, these controls create a defense‑in‑depth posture that aligns with the CRA’s objective of reducing cyber risk across the EU market.
Submission to Member Organizations and Public Consultation Process
The draft standards have been forwarded to 41 member organizations across Europe, which include the national standardization bodies of the European Economic Area as well as Europe‑wide industry and standards groups. This broad distribution initiates the first phase of ETSI’s approval procedure: a public enquiry period during which interested parties can review the documents and submit feedback. The consultation is designed to capture technical concerns, practical implementation challenges, and potential conflicts with existing regulations. By engaging a diverse set of stakeholders early in the process, ETSI aims to refine the standards so that they are both technically sound and commercially feasible, reducing the likelihood of costly revisions after formal adoption.
Stakeholder Comment Period and Expected Finalization
Stakeholders are invited to comment on the draft standards until mid‑September to mid‑November 2026, with the exact deadline varying according to the specific vertical or product sector. This staggered timeline allows sectors with more complex supply chains—such as automotive IoT or medical devices—to allocate sufficient time for thorough analysis. After the comment period closes, ETSI will review all submissions, incorporate justified changes, and prepare the final versions of the 17 standards. The institute anticipates publishing the completed documents by December 2026, providing manufacturers with a clear, stable target for compliance efforts well ahead of the CRA’s December 2027 enforcement date.
Implications for Manufacturers, Importers, Distributors, and Developers
Once the standards are finalized, they will apply to all economic operators that place commercially available hardware or software products on the EU market. This includes manufacturers who design and produce the goods, importers who bring non‑EU products into the region, distributors who channel them to end‑users, and developers who supply software components or updates. Non‑compliance will result in market access restrictions, potential fines, and reputational damage. Consequently, firms must begin gap analyses now, adjust their development lifecycles to incorporate SBOM generation, secure default configurations, and update mechanisms, and secure conformity assessment services from accredited bodies. Early action not only mitigates regulatory risk but can also yield competitive advantages by signaling a strong commitment to cybersecurity to customers and partners.
Support Initiatives for SMEs: Workshops Across Europe
Recognizing that small and medium‑sized enterprises (SMEs) may lack the resources to navigate the new regulatory landscape, ETSI, together with CEN and CENELEC, has organized a series of workshops throughout Europe. These events aim to demystify the CRA requirements, explain how the 17 standards translate into practical actions, and provide guidance on conformity assessment pathways. Participants receive hands‑on assistance with drafting SBOMs, configuring secure defaults, and planning update strategies. By lowering the knowledge barrier, the workshops help ensure that SMEs can achieve compliance without disproportionate cost, fostering a more inclusive and secure digital single market.
Awareness Gaps in the Open‑Source Community
Despite the extensive outreach, a recent survey revealed that approximately two‑thirds of the open‑source community remain unaware of the Cyber Resilience Act and its impending obligations. This lack of awareness poses a significant risk, given that many open‑source components are embedded in commercial products covered by the CRA. Projects that do not adopt SBOM practices, maintain secure default configurations, or provide timely updates could inadvertently cause their downstream users to fall afoul of the regulation. Addressing this gap will require targeted communication, perhaps through developer forums, license compliance tools, and collaborations with open‑source foundations to embed CRA‑relevant requirements into contribution guidelines and release processes.
Conclusion: Preparing for the 2027 Deadline
The EU Cyber Resilience Act represents a decisive step toward elevating the baseline security of digital products sold in Europe. ETSI’s ongoing work to develop and finalize 17 sector‑specific cybersecurity standards provides the concrete roadmap that manufacturers and their partners need to follow. With draft documents already under public consultation, a clear timeline for stakeholder input, and final versions slated for release by the end of 2026, industry now has a predictable window to adapt. Leveraging support mechanisms such as European‑wide workshops and proactively engaging the open‑source ecosystem will be essential to close awareness gaps and ensure a smooth transition. By acting now, companies can not only meet the forthcoming legal obligations but also build stronger, more resilient products that inspire confidence across the EU market.

