Technical article

Current status of standardisation for the Cyber Resilience Act

IEC 62443, EN 40000 and other product standards for compliance with CRA requirements


Share this article
Share Button LinkedinShare Button XShare Button FacebookShare Button Instagram  Share Button E-Mail

When it came to meeting the health and safety requirements of the Cyber Resilience Act, it was already clear from the draft documents that harmonised standards would play a key role here too. 

Through the ‘CRA Standards Unlocked’ webinar series, CEN and CENELEC are currently providing, for the first time, specific insights into the current state of European standardisation relating to the Cyber Resilience Act. The focus is not only on horizontal and broad vertical cybersecurity standards, but increasingly also on product-specific standards for specific product categories. 

For mechanical engineers and manufacturers of industrial products, it is gradually becoming clear how the regulatory requirements of the Cyber Resilience Act are to be technically implemented and assessed in future. 

In our technical article, we have summarised the current status of CRA standardisation based on the seminar series.

 

Roadmap for CRA standardisation

The European Commission’s standardisation mandate of February 2025 provided the first clear indication of the extent to which harmonised standards must be drawn up to meet the CRA requirements, and of the hierarchy of such future standards. 

Horizontal standards are intended to create a coherent general framework regarding security requirements and the handling of vulnerabilities, whilst vertical standards will cover security requirements for specific product categories.

This hierarchy, together with a timetable for the planned development of such documents, is summarised in the following diagram:

The deadline for the adoption of the horizontal Type A standard(s) and the Type B standards for vulnerability management is set for 30 August 2026 at the latest. Type C standards for the individual product categories must be in place by 30 October 2026; shortly before the CRA comes into force on 11 December 2027, the Type B standards for technical measures will follow (30 October 2027). 

However, in early July 2026, the Commission published a draft amendment to the CRA standardisation request, in which the deadline for drawing up the standards in 2026 is to be postponed by two months. Accordingly, the C standards are scheduled to be finalised by 31 December 2026, whilst the A and B standards for vulnerability management are scheduled to be finalised by 31 October 2026. The corresponding implementing decision has yet to be published in the Official Journal.

CEN/CENELEC have been gradually presenting the relevant categories, based on the standardisation mandate, in their webinar series ‘CRA standards unlocked’ since early 2026.

 

IEC 62443 as the central CRA framework for OT products 

Particularly in the latest edition, “Understanding ACS Technical Requirements & Compliance under EN IEC 62443”, the IEC 62443 series of standards (IT security for industrial automation systems) is emerging as the key technical reference for CRA compliance in industrial settings. 

A detailed overview of the series of standards, specifically from the perspective of manufacturers of machinery and plant, can be found in our technical article ‘Machinery Regulation, Cyber Resilience Act (CRA) and IEC 62443’. 

Three parts of the IEC 62443 standard series are currently of particular focus when it comes to meeting CRA requirements: 

  • IEC 62443-4-1 on life-cycle requirements for secure product development 
  • IEC 62443-4-2 on technical security requirements for components of industrial automation systems (IACS) 
  • IEC 62443-3-3 on system requirements for IT security and security levels, although the regulatory status of this standard is currently still unclear.

The webinar series thus made it clear that EN IEC 62443-4-1 forms the basis of the entire model, which describes the manufacturer’s secure development process. The focus is on requirements such as security by design, secure coding, threat modelling, security testing, vulnerability handling and patch management. The standard therefore defines how a manufacturer must develop products securely and appropriately address vulnerabilities identified throughout the product lifecycle. 

IEC 62443-4-2 then builds on this. This standard describes the specific technical security requirements for components of industrial automation and control systems – for example, embedded devices, PLCs, HMIs, network components or industrial PCs. 

IEC 62443-3-3, on the other hand, defines ‘System Security Requirements’ and describes the security level that an entire system should achieve. This is particularly relevant for mechanical engineering firms. Modern machines today often straddle the line between product and system: they consist of multiple components and feature internal networks, remote maintenance, user management or cloud connections. As a result, the boundaries between the 4-2 product requirements and the 3-3 system requirements are becoming increasingly blurred.
 

Horizontal standards: The EN 40000 series as a foundation

Alongside the product-specific standardisation activities, horizontal standards form an essential basis for implementing the Cyber Resilience Act. They provide product-independent guidance on key CRA requirements and are intended to support manufacturers in implementing the essential cybersecurity requirements.

The EN 40000 series plays a central role in this context. It comprises several horizontal standards addressing different aspects of the CRA and is generally intended to apply independently of a specific product category.

In terms of content, the standards cover typical cybersecurity building blocks such as secure authentication, access control, secure communication, cryptography, secure default configurations, logging, attack detection and secure update mechanisms. Many of these requirements are based on existing work from the EN 18031 series, which was originally developed for the RED. However, the new EN 40000 series expands on these approaches and applies them to the significantly broader scope of the CRA.

At the heart of this is the new EN 40000 family of standards, which is currently being developed within CEN/CLC/JTC 13 WG9. The aim of this work is to translate the previously abstract requirements of the Cyber Resilience Act into a consistent technical framework for the first time.

As things stand, EN 40000-1-2 is intended to describe the fundamental process and lifecycle activities, as well as to define which objectives must be achieved, which inputs are mandatory or optional, and what minimum outcomes are expected. The focus is on traditional security engineering activities such as risk analysis, requirements management and the selection of appropriate security controls. 

Whilst EN 40000-1-2 stipulates that risks must be assessed and appropriate security measures selected, EN 40000-1-4 subsequently provides the actual technical security controls for this purpose. These security controls are intended to have different levels of implementation or maturity. This creates a flexible and risk-based model in which not every security measure necessarily has to be implemented in exactly the same way. 

Finally, EN 40000-1-3 complements this approach by incorporating the aspects of lifecycle and vulnerability management. It describes more detailed process activities – such as security monitoring, verification, validation or release processes. At the same time, the standard is intended to define specific assessment criteria which may later be relevant for the presumption of conformity. 

A detailed overview of the planned prEN 40000-1-3 can be found in our article ‘Draft standard prEN 40000-1-3: “Dealing with (cyber) vulnerabilities”’.
 

Vertical standards: Product-specific implementation of CRA requirements
 

New prEN 50770 standards set out specific requirements for OT products

In parallel with IEC 62443, a new generation of vertical CRA standards for specific OT product categories is currently being developed as the prEN 50770 series. The webinar sessions held to date have addressed the following product classes, amongst others:

  • prEN 50770-1 on firewalls / IDS / IPS 
  • prEN 50770-2 on network management systems
  • prEN 50770-3 on physical and virtual network interfaces 
  • prEN 50770-4 on VPN products 
  • prEN 50770-5 on routers / switches 
  • and prEN 50770-6 on SIEM (Security Information and Event Management)

The IEC 62443 standards thus define the generic security framework, whilst the prEN 50770 standards are intended to describe specific security profiles for particular product types. This creates, for the first time, a concrete technical framework for how CRA requirements are to be applied to OT products in future.

An interesting aspect of the current development of CRA standards is the focus on a product’s so-called ‘core functionality’. 

The firewall example presented in the webinar made it clear that, in future, a clearer distinction will be made between core functionality and additional functions. The actual core functionality of a firewall is to monitor network traffic and block unauthorised communication. Additional functions such as analytics, dashboards or load balancing, on the other hand, are considered separately. 

Current work points to an assessment approach whereby specific vertical standards, such as prEN 50770-1, are to apply to a product’s core function, whilst additional functionalities will continue to be assessed against the generic requirements of IEC 62443-4-2.


Vertical ETSI standards: 17 CRA draft standards published

These standardisation activities are now being complemented by further product-specific standards developed by ETSI. In August 2026, ETSI published 17 final draft European standards developed in the context of the Cyber Resilience Act. The standards in the EN 304 xxx series are currently undergoing the European Public Enquiry and approval process and are intended to become harmonised standards supporting the implementation of the CRA.

The drafts address specific product groups and functions, including browsers, password managers, operating systems, firewalls and intrusion detection and prevention systems, routers, modems and switches, VPN products, PKI software, anti-virus software and SIEM systems.

The ETSI drafts therefore provide further insight into how the general requirements of the CRA are being translated into requirements for specific product groups. They focus in particular on the essential cybersecurity requirements set out in Part I of Annex I to the CRA. Once referenced as harmonised standards in the Official Journal of the European Union, their application may provide a presumption of conformity for the respective requirements covered by the standards.

The 17 ETSI draft standards are currently publicly available and can be accessed via the ETSI document portal.
 

Current situation and publication in the Official Journal of the EU

Although the IEC 62443 series of standards plays a key role in meeting the CRA requirements, based on statements made to date, it appears unlikely that Parts -4-1, -4-2 and -3-3 will be referenced in the Official Journal of the European Union. Amendment documents are currently being developed for Parts -4-1 and -4-2; however, according to the current state of discussions, these documents are also unlikely to be listed in the Official Journal.

Instead, a presumption of conformity is expected to be provided in particular through harmonised standards being developed specifically for the CRA. These include product-specific (“vertical”) standards. In addition to the prEN 50770 series, ETSI is now also developing corresponding vertical standards for a wide range of product groups.

The standards of the prEN 50770 series define “Security for Operational Technologies” and, as product standards, are heavily based on the content of the IEC 62443 series. However, they are not “Broad Verticals” in nature, i.e. they are not generic cross-sector standards. The vertical standards being developed by ETSI, by contrast, address further specific product groups such as browsers, password managers, operating systems and PKI software.

Nevertheless, the IEC 62443 series is expected to remain a central technical basis for the future presumption of conformity in the OT domain. According to the speakers, for example, the risk analysis methodology from IEC 62443-4-1 is defined as the approach to be used for the different product-specific requirements across all parts of the EN 50770 series.

As regards the horizontal standards, only prEN 40000-1-3 (Vulnerability Handling) is currently expected to be referenced in the Official Journal; there are currently no plans for Part 1-2 (Principles, product risk management, and lifecycle activities) to be referenced.
 

Conclusion and outlook

Overall, it is clear that European CRA standardisation is now moving from discussion to technical implementation. 

However, the differing positions of legislators and standards committees are getting clear: in the field of cybersecurity, the development of harmonised standards does not automatically lead to a fully concrete technical definition of security, as is the case in the field of machinery safety. 

Solutions for implementing the legal requirements are conceived differently here, which is why users must regard standards as key documents despite their not being listed in the Official Journal. 


Posted on: 30 September 2026 (last amendment)

Author: Daniel Zacek-Gebele

Daniel Zacek-Gebele, MSc
Product manager at IBF for additional products and data manager for updating standards data on the Safexpert Live Server. Studied economics in Passau (BSc) and Stuttgart (MSc), specialising in International Business and Economics.

Email: daniel.zacek-gebele@ibf-solutions.com

 

CE-Infoservice – register now!

We will inform you free of charge by e-mail about new technical articles, important standard publications or other news from the field of mechanical and electrical equipment safety or product compliance.


Share this article
Share Button LinkedinShare Button XShare Button FacebookShare Button Instagram  Share Button E-Mail