The European Union is translating broad cybersecurity requirements into concrete technical rules. ETSI has released 17 finalized draft standards covering browsers, operating systems, VPNs, antivirus software, routers, password managers, and other digital products. Manufacturers must now factor these emerging requirements into their preparations ahead of the Cyber Resilience Act’s full entry into force on December 11, 2027.
Not Yet Final: Understanding the Approval Timeline
These 17 documents are not yet finalized standards. ETSI has submitted them to the national standardization bodies of 41 European countries and launched a formal Public Enquiry procedure. Depending on the specific standard, this current phase will run through roughly mid-September or mid-November 2026. National organizations will be able to submit comments and propose revisions during this window.
Once approved, the documents must clear one further critical milestone: the European Commission must publish references to the standards in the Official Journal of the EU. Only after that publication does a European standard achieve harmonized status, granting manufacturers what is known as a presumption of conformity with Cyber Resilience Act requirements.
For this reason, framing the situation as “manufacturers are obligated to follow 17 standards” would be inaccurate. What is legally mandatory is compliance with the Cyber Resilience Act itself. Harmonized standards simply offer manufacturers a pre-recognized technical pathway for demonstrating that compliance. A company remains free to pursue an alternative approach, but doing so requires independently proving that its product satisfies CRA requirements.
17 Product Categories Now Covered
The new documents span 17 distinct product and technology groups. The list includes browsers, password managers, antivirus software, VPNs, network management systems, SIEM platforms, bootloaders, PKI software and digital certificate issuance tools, physical and virtual network interfaces, operating systems, routers, modems and switches, general-purpose home voice assistants, smart home security systems, internet-connected toys, wearable devices, hypervisors and container runtime environments, as well as firewalls and intrusion detection and prevention systems.
These 17 documents represent only a portion of a considerably larger initiative. The European Commission has commissioned development of 41 standards in total to support the CRA. These include horizontal documents establishing general requirements alongside vertical standards tailored to specific product types. The EN 304 xxx series that ETSI has released belongs specifically to the product-focused category.
Familiar Security Practices, New Legal Weight
Many of the requirements outlined will be well known to security professionals, but the CRA transforms decades-old recommendations into legally binding obligations. Products must ship with secure default configurations, protect data using modern cryptographic methods, restrict unauthorized access, and enable remediation of discovered vulnerabilities through security updates.
For eligible products, the CRA mandates automatic installation of security updates by default, paired with a clear mechanism allowing users to opt out of automatic installation or temporarily defer an update. Manufacturers must distribute fixes for known security issues without undue delay, and generally at no cost.
Support Periods and the Software Bill of Materials
A separate requirement concerns support duration. Manufacturers must define in advance the period during which they will patch vulnerabilities and issue security updates. In most cases, this period cannot be shorter than five years, with exceptions available for products whose expected service life is inherently shorter than five years from the outset.
The CRA also introduces a mandatory Software Bill of Materials (SBOM). Manufacturers must maintain a machine-readable inventory of software components, covering at minimum the primary dependencies. Importantly, the law does not require manufacturers to automatically publish the SBOM or hand it to every purchaser – the document forms part of the technical documentation and is provided to regulatory authorities upon request.
Incident Reporting Obligations Begin September 2026
Another notable element of the CRA takes effect well ahead of the December 2027 deadline. Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents. An initial notification must be submitted within 24 hours of the manufacturer becoming aware of the issue. More detailed information regarding an actively exploited vulnerability must follow within 72 hours, and a final report – once a fix becomes available – must be submitted no later than 14 days afterward.
Critically, this obligation to report actively exploited vulnerabilities also applies to products that entered the market before December 11, 2027. As a result, the CRA’s first practical enforcement mechanism effectively begins operating this autumn, in 2026.
Scope, CE Marking, and Penalties
The core requirements of the Cyber Resilience Act apply to commercial hardware and software products containing digital elements that connect, directly or indirectly, to other devices or networks. Certain sectors – including specific medical, automotive, and aviation products – remain governed by their own separate European regulatory regimes.
Once a product subject to the CRA successfully completes conformity assessment, it must receive CE marking. For conventional hardware devices, this mark is placed directly on the product or its packaging; for software, marking may instead appear within the declaration of conformity or on a website associated with the software.
The consequences for non-compliance are substantial. Failure to meet core cybersecurity requirements and manufacturer obligations under the CRA can result in administrative fines of up to EUR 15 million or up to 2.5% of a company’s worldwide annual turnover from the preceding financial year – whichever figure is greater.
What This Means for Manufacturers
The publication of ETSI’s 17 draft standards gives manufacturers a far more concrete picture of how European regulators intend the CRA to be implemented in practice. For many of these requirements, nothing here amounts to a revolution: secure default configurations, timely updates, modern cryptography, dependency management, and vulnerability handling have been discussed within the industry for decades. What has changed is that the ability to legally sell digital products within the EU market will soon hinge directly on these long-standing practices.
All currently available ETSI draft standards can be reviewed through the public ETSI catalog.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.