Technical article

Current status of standardisation for the Cyber Resilience Act

IEC 62443, EN 40000 and other product standards for compliance with CRA requirements


Share this article
Share Button LinkedinShare Button XShare Button FacebookShare Button Instagram  Share Button E-Mail

When it came to meeting the health and safety requirements of the Cyber Resilience Act, it was already clear from the draft documents that harmonised standards would play a key role here too. 

Through the ‘CRA Standards Unlocked’ webinar series, CEN and CENELEC are currently providing, for the first time, specific insights into the current state of European standardisation relating to the Cyber Resilience Act. The focus is not only on horizontal and broad vertical cybersecurity standards, but increasingly also on product-specific standards for specific product categories. 

For mechanical engineers and manufacturers of industrial products, it is gradually becoming clear how the regulatory requirements of the Cyber Resilience Act are to be technically implemented and assessed in future. 

In our technical article, we have summarised the current status of CRA standardisation based on the seminar series.

 

Roadmap for CRA standardisation

The European Commission’s standardisation mandate of February 2025 provided the first clear indication of the extent to which harmonised standards must be drawn up to meet the CRA requirements, and of the hierarchy of such future standards. 

Horizontal standards are intended to create a coherent general framework regarding security requirements and the handling of vulnerabilities, whilst vertical standards will cover security requirements for specific product categories.

This hierarchy, together with a timetable for the planned development of such documents, is summarised in the following diagram:

The deadline for the adoption of the horizontal Type A standard(s) and the Type B standards for vulnerability management is set for 30 August 2026 at the latest. Type C standards for the individual product categories must be in place by 30 October 2026; shortly before the CRA comes into force on 11 December 2027, the Type B standards for technical measures will follow (30 October 2027). 

CEN/CENELEC have been gradually presenting the relevant categories, based on the standardisation mandate, in their webinar series ‘CRA standards unlocked’ since early 2026.

 

IEC 62443 as the central CRA framework for OT products 

Particularly in the latest edition, “Understanding ACS Technical Requirements & Compliance under EN IEC 62443”, the IEC 62443 series of standards (IT security for industrial automation systems) is emerging as the key technical reference for CRA compliance in industrial settings. 

A detailed overview of the series of standards, specifically from the perspective of manufacturers of machinery and plant, can be found in our technical article ‘Machinery Regulation, Cyber Resilience Act (CRA) and IEC 62443’. 

Three parts of the IEC 62443 standard series are currently of particular focus when it comes to meeting CRA requirements: 

  • IEC 62443-4-1 on life-cycle requirements for secure product development 
  • IEC 62443-4-2 on technical security requirements for components of industrial automation systems (IACS) 
  • IEC 62443-3-3 on system requirements for IT security and security levels, although the regulatory status of this standard is currently still unclear.

The webinar series thus made it clear that EN IEC 62443-4-1 forms the basis of the entire model, which describes the manufacturer’s secure development process. The focus is on requirements such as security by design, secure coding, threat modelling, security testing, vulnerability handling and patch management. The standard therefore defines how a manufacturer must develop products securely and appropriately address vulnerabilities identified throughout the product lifecycle. 

IEC 62443-4-2 then builds on this. This standard describes the specific technical security requirements for components of industrial automation and control systems – for example, embedded devices, PLCs, HMIs, network components or industrial PCs. 

IEC 62443-3-3, on the other hand, defines ‘System Security Requirements’ and describes the security level that an entire system should achieve. This is particularly relevant for mechanical engineering firms. Modern machines today often straddle the line between product and system: they consist of multiple components and feature internal networks, remote maintenance, user management or cloud connections. As a result, the boundaries between the 4-2 product requirements and the 3-3 system requirements are becoming increasingly blurred.
 

New prEN 50770 standards set out specific requirements for OT products

In parallel with IEC 62443, a new generation of vertical CRA standards for specific OT product categories is currently being developed as the prEN 50770 series. The webinar sessions held to date have addressed the following product classes, amongst others:

  • prEN 50770-1 on firewalls / IDS / IPS 
  • prEN 50770-2 on network management systems
  • prEN 50770-3 on physical and virtual network interfaces 
  • prEN 50770-4 on VPN products 
  • prEN 50770-5 on routers / switches 
  • and prEN 50770-6 on SIEM (Security Information and Event Management)

The IEC 62443 standards thus define the generic security framework, whilst the prEN 50770 standards are intended to describe specific security profiles for particular product types. This creates, for the first time, a concrete technical framework for how CRA requirements are to be applied to OT products in future.
  

New term: ‘Core Functionality’ 

An interesting aspect of the current development of CRA standards is the focus on a product’s so-called ‘core functionality’. 

The firewall example presented in the webinar made it clear that, in future, a clearer distinction will be made between core functionality and additional functions. The actual core functionality of a firewall is to monitor network traffic and block unauthorised communication. Additional functions such as analytics, dashboards or load balancing, on the other hand, are considered separately. 

Current work points to an assessment approach whereby specific vertical standards, such as prEN 50770-1, are to apply to a product’s core function, whilst additional functionalities will continue to be assessed against the generic requirements of IEC 62443-4-2.

 

Horizontal standards: The EN 40000 series as a foundation

Alongside the IEC 62443-based OT standards and the new prEN 50770 product standards, a new horizontal CRA standardisation system is currently being developed at European level. This is likely to form the generic basis for almost all CRA-compliant products in future. 

In terms of content, it covers typical cybersecurity building blocks such as secure authentication, access control, secure communication, cryptography, secure default configurations, logging, attack detection and secure update mechanisms. Many of these requirements are based on existing work from the EN 18031 series, which was originally developed for the RED. However, the new EN 40000 series now expands on these approaches and applies them to the significantly broader scope of the CRA. 

At the heart of this is the new EN 40000 family of standards, which is currently being developed within CEN/CLC/JTC 13 WG9. The aim of this work is to translate the previously abstract requirements of the Cyber Resilience Act into a consistent technical framework for the first time. 

As things stand, EN 40000-1-2 is intended to describe the fundamental process and lifecycle activities, as well as to define which objectives must be achieved, which inputs are mandatory or optional, and what minimum outcomes are expected. The focus is on traditional security engineering activities such as risk analysis, requirements management and the selection of appropriate security controls. 

Whilst EN 40000-1-2 stipulates that risks must be assessed and appropriate security measures selected, EN 40000-1-4 subsequently provides the actual technical security controls for this purpose. These security controls are intended to have different levels of implementation or maturity. This creates a flexible and risk-based model in which not every security measure necessarily has to be implemented in exactly the same way. 

Finally, EN 40000-1-3 complements this approach by incorporating the aspects of lifecycle and vulnerability management. It describes more detailed process activities – such as security monitoring, verification, validation or release processes. At the same time, the standard is intended to define specific assessment criteria which may later be relevant for the presumption of conformity. 

A detailed overview of the planned prEN 40000-1-3 can be found in our article ‘Draft standard prEN 40000-1-3: “Dealing with (cyber) vulnerabilities”’.
 

Current situation and publication in the Official Journal of the EU

Although the IEC 62443 series of standards plays a key role in meeting the CRA requirements, based on statements made to date, it is rather unlikely that Parts -4-1, -4-2 and also -3-3 will be published. Although amendment documents are currently being drawn up for Parts -4-1 and -4-2, it is highly unlikely that these standards will be listed in the Official Journal either. 

Such a presumption of conformity is currently envisaged only for the ‘Verticals’ series of standards (EN 50770-1 to -6). These standards define ‘Security for Operational Technologies’ and, as product standards, are heavily based on the content of the IEC 62443 series; however, they are not ‘Broad Verticals’ in nature, i.e. they are not generically cross-sectoral. 

Nevertheless, the standards in the IEC 62443 series are expected to remain the central technical basis for the subsequent presumption of conformity: According to the speakers, for example, the risk analysis from IEC 62443-4-1 is defined as the approach for the various product specifications across all parts of the EN 50770 series. 

As regards the horizontal standards, only prEN 40000-1-3 (Vulnerability Handling) is currently expected to be listed; there are no current plans for Part 1-2 (Principles, product risk management, and lifecycle activities). These two standards are due to be adopted by August 2026 at the latest, whilst Part 1-4 is not scheduled until autumn 2027.
 

Conclusion and outlook

Overall, it is clear that European CRA standardisation is now moving from discussion to technical implementation. 

However, the differing positions of legislators and standards committees are getting clear: in the field of cybersecurity, the development of harmonised standards does not automatically lead to a fully concrete technical definition of security, as is the case in the field of machinery safety. 

Solutions for implementing the legal requirements are conceived differently here, which is why users must regard standards as key documents despite their not being listed in the Official Journal. 


Posted on: 6 July 2026

Author: Daniel Zacek-Gebele

Daniel Zacek-Gebele, MSc
Product manager at IBF for additional products and data manager for updating standards data on the Safexpert Live Server. Studied economics in Passau (BSc) and Stuttgart (MSc), specialising in International Business and Economics.

Email: daniel.zacek-gebele@ibf-solutions.com

 

CE-Infoservice – register now!

We will inform you free of charge by e-mail about new technical articles, important standard publications or other news from the field of mechanical and electrical equipment safety or product compliance.


Share this article
Share Button LinkedinShare Button XShare Button FacebookShare Button Instagram  Share Button E-Mail