Published Security3 min read
Seventeen draft CRA standards are open for comment, and they are the route to presumed conformity
Comments on the Cyber Resilience Act's candidate harmonised standards close between mid-September and mid-November 2026. The end-2027 compliance date does not move.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Seventeen draft Cyber Resilience Act standards are open for comment; the drafts went out this summer.
- The comment procedure runs until somewhere between mid-September and mid-November 2026, with the closing date varying by vertical.
- The Cyber Resilience Act states what manufacturers have to achieve and stops there, leaving manufacturers to work out the technical detail; the 17 draft standards supply that detail.
- Manufacturers who follow a Harmonised Standard get the presumption of conformity, meaning a regulator treats the product as meeting the law unless someone shows otherwise.
- A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Seventeen draft Cyber Resilience Act standards went out for comment this summer, and the procedure closes somewhere between mid-September and mid-November 2026, with the date varying by vertical [1][2]. Because the CRA states what manufacturers have to achieve and stops there [3], those seventeen documents are where the technical "how" gets settled for every firm that wants to be presumed compliant by the end of 2027 [4][5].
The mechanism is worth being precise about. A manufacturer that follows a Harmonised Standard gets the presumption of conformity, meaning a regulator treats the product as meeting the law unless someone shows otherwise [4]. The seventeen drafts are candidates for that status, not holders of it [6]. They cover the higher-risk tier of products with digital elements, including password managers, anti-virus software, smart home assistants, connected toys, and wearables [7]. If you sell in any of those categories, the text under review is the text your auditor will eventually read back to you.
Sandra Feliciano, who chairs the group responsible for the CRA at TC CYBER-EUSR, put the division of labour plainly: "The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how. The role of the Standards Developing Organisations is to detail the technical aspects of how to achieve compliance with the legislation through standards" [8].
The commenting franchise is narrow. The drafts went to 41 member organisations, including the national standardisation bodies of the European Economic Area, which can file comments in the first phase of approval [9]. Four societal partners can also comment: ANEC, ECOS, ETUC and SBS, known collectively as the Annex III Organisations [10]. That is 45 named bodies with a channel [11]. The source material describes no direct filing route for an individual vendor, which means a product security team's input travels through its national standardisation body or through one of those four partners, or not at all.
Two practical points follow. First, the scope is wider than the people writing firmware: importers, distributors, service providers, and developers of commercially available hardware and software all fall under the CRA, and all face the same end-of-2027 date [12]. Second, for many small and medium firms the CRA is a known quantity while the compliance route is not, and the questions of which standard covers the product, which tools test against it, and which funding programs pay for it have answers that are scattered [13]. A draft comment period is one of the few moments when those questions can be raised against movable wording rather than a finished document.
The arithmetic is the argument. Counting from the close of comments to the deadline leaves roughly 13 to 15 months to read the final text, build the test evidence, and ship changed product [14]. Anyone who starts reading at the deadline will be reading a text other people settled [15].
What to watch: the per-vertical closing dates, since they differ and the earliest is mid-September 2026 [2]; whether the drafts actually complete the path from candidate to Harmonised Standard [6]; and what the Annex III Organisations put on the record, because consumer, environmental, labour and small-business positions entered now are the ones that survive into the version regulators cite [10].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Seventeen draft Cyber Resilience Act standards are open for comment; the drafts went out this summer.
- [2]
The comment procedure runs until somewhere between mid-September and mid-November 2026, with the closing date varying by vertical.
- [3]
The Cyber Resilience Act states what manufacturers have to achieve and stops there, leaving manufacturers to work out the technical detail; the 17 draft standards supply that detail.
- [4]
Manufacturers who follow a Harmonised Standard get the presumption of conformity, meaning a regulator treats the product as meeting the law unless someone shows otherwise.
- [5]
A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act.
- [6]
The 17 drafts are candidates for Harmonised Standard status, not holders of it.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comAnamarija PogorelecAug 1317 draft Cyber Resilience Act standards are open for comment
Additional citations
- Help Net Security
- Sandra Feliciano, Chair, TC CYBER-EUSR, quoted by Help Net Security



