EU's Cyber Resilience Act shifts from principles to standards with new draft cybersecurity rules

The European Union is translating its Cyber Resilience Act into detailed technical standards through ETSI, aiming to streamline compliance and enhance security for connected products before the 2027 enforcement deadline.

The European Union is moving its Cyber Resilience Act from broad legal principle to detailed engineering rulebook, with ETSI publishing 17 draft cybersecurity standards intended to define the minimum security features for connected products. The aim is to give manufacturers a clearer route to compliance by turning the Act’s general duties into technical requirements that product teams can actually build against.

Under the Cyber Resilience Act, devices and software sold in the EU must be designed, updated and maintained to protect users from cyber threats across the full product lifecycle. The European Commission says the regulation entered into force on 10 December 2024, while the main obligations will apply from 11 December 2027, with reporting duties starting earlier on 11 September 2026. Products that comply will carry the CE marking, and some higher-risk categories may require assessment by a notified body before they can reach the market.

The draft ETSI work is intended to support so-called harmonised standards, which translate the Act’s high-level requirements into testable technical provisions. According to specialist analysis of the CRA standards landscape, these documents are likely to sit alongside work from CEN and Cenelec and are expected to be split between horizontal rules that apply widely and vertical rules for specific product groups. In practice, that creates a conformity route for manufacturers: if a product meets the relevant harmonised standard, it can benefit from a presumption of conformity with the regulation.

For vendors, the practical consequence is a stronger security-by-design obligation pushed into the earliest stages of development, alongside ongoing duties for vulnerability handling, patching and monitoring after release. The standards are currently open to public comment, leaving a limited window for industry input before the final specifications shape product road maps. For manufacturers of connected hardware and software, the message is clear: portfolios must now be mapped against the emerging technical baseline well before the December 2027 enforcement date.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.