ETSI advances EU Cyber Resilience Act compliance with public review of 17 draft standards

ETSI has moved 17 draft standards into public review amid the EU’s Cyber Resilience Act, signalling a decisive step towards harmonised cybersecurity compliance for connected devices, with the process extending into 2026.

ETSI has moved 17 draft standards into public review as part of the European Union’s Cyber Resilience Act, starting a formal approval process that is expected to continue into 2026. According to SAPinsider, the drafts were circulated this summer to 41 member organisations across Europe, including national standardisation bodies in the European Economic Area, and are intended to become harmonised standards that can give manufacturers a recognised route to demonstrate compliance through a presumption of conformity.

The timing matters because the Act is already in force. The European Commission says the Cyber Resilience Act entered into force on 10 December 2024, with reporting obligations due to start on 11 September 2026 and the main requirements applying from 11 December 2027. The Commission also says the rules cover products with digital elements and require CE marking, while national market surveillance authorities will be responsible for enforcement.

SAPinsider reports that the ETSI drafts sit in the EN 304 xxx series and are designed around the Act’s essential cybersecurity requirements. The approval window for the different verticals is said to run from mid-September to mid-November 2026, depending on the product category. The standards are publicly available during review, giving manufacturers and standards bodies time to comment before finalisation.

The narrow timetable means companies cannot wait for the harmonised texts before starting preparation. Under the Act, manufacturers will still need to assess whether their products fall within scope, determine the relevant conformity route and prepare for vulnerability reporting once the September 2026 deadline arrives. ETSI has highlighted higher-risk categories such as password managers, smart home assistants and wearables, while the broader scope also covers connected hardware, embedded components and edge devices.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.