CRA harmonised standards — OJEU tracker (July 2026)
Live status of harmonised standards under the Cyber Resilience Act: standardisation request M/606, EN 40000 series, expected OJEU listings 2027.
By Vladimír Vician
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets essential cybersecurity requirements in Annex I, and like other EU New Legislative Framework regulations it is designed to be operationalised through harmonised European standards. Article 27 of the CRA grants a presumption of conformity to products that comply with harmonised standards (or parts of them) whose references have been published in the Official Journal of the European Union. That is the legal value of an OJEU citation — it converts a technical document into a regulatory shortcut.
The Commission's CRA standardisation page confirms that standardisation request M/606 (Commission Implementing Decision C(2025) 618) was adopted in early 2025 and formally accepted by CEN, CENELEC and ETSI on 3 April 2025. M/606 covers approximately 41 deliverables across horizontal and vertical scope. As of the cut-off date of this article (July 2026), none of those deliverables has yet been cited in the OJEU.
What "harmonised standard under CRA" actually means
A harmonised standard becomes a CRA harmonised standard only when its reference is published in the OJEU under Regulation (EU) 2024/2847. Until that publication, even a finalised EN draft has the legal status of a technical document — useful evidence, but no automatic presumption of conformity with Annex I.
The mechanism is identical to other NLF regulations: see the Commission's overview of harmonised standards and our companion article on how to find harmonised standards in the OJ for the search workflow.
Standardisation request M/606 — what it covers
The Commission divided the work into two streams, both visible on the STAN4CR project portal run by the ESOs:
| Stream | Lead body | Scope | CRA reference |
|---|---|---|---|
| Horizontal — EN 40000 series | CEN-CENELEC JTC 13 | Vocabulary, cyber-resilience principles, vulnerability handling, generic security requirements | Annex I Part I + Part II (all products with digital elements) |
| Vertical — product-specific | ETSI (dedicated EUSR group) plus CEN-CENELEC TCs | ~18 product categories drawn from Annex III (important) and Annex IV (critical) | Annex I applied per category |
The horizontal EN 40000 family is intended to be the workhorse: a manufacturer of an arbitrary product with digital elements should, in principle, be able to apply EN 40000 parts to claim presumption of conformity against Annex I once they are listed.
Status as of July 2026
Information drawn from the STAN4CR work programme and ESO updates, cross-checked against the Commission CRA standardisation page:
- prEN 40000-1-1 (Vocabulary) — public enquiry completed, in approval stage.
- prEN 40000-1-2 (Cyber resilience principles) — public enquiry completed, in approval stage.
- prEN 40000-1-3 (Vulnerability handling) — public enquiry completed, in approval stage.
- prEN 40000-1-4 (Generic security requirements) — drafting; public enquiry expected mid-2026 into late 2026.
- Vertical standards (~18 product categories) — drafts released for public consultation on the ETSI Open Area; adoption work continuing.
No reference to a CRA harmonised standard has appeared in the C-series of the Official Journal as of the date of this article.
Publicly stated expectations from STAN4CR and the ESOs target adoption of deliverables through late 2026 and the early months of 2027, with first OJEU citations realistically arriving in 2027 — before the CRA's main applicability date of 11 December 2027 (Article 71), but with very little buffer. See our CRA timeline article for the full applicability schedule.
One email at launch · cancel any time
What this means for conformity assessment today
Two practical consequences flow from "no OJEU citations yet":
- No presumption of conformity is available. A manufacturer cannot self-declare CRA compliance by writing "applied prEN 40000-1-2" in a Declaration of Conformity and stopping there. The DoC list of standards (per CRA Annex V) is reserved for harmonised standards already cited in the OJEU — see our sample DoC walkthrough.
- State-of-the-art evidence is the route. CRA Annex I requires that essential requirements are met "taking into account the state of the art". Until harmonised standards exist, the technical file (see Technical File 101 and our IoT technical file template) must show that each Annex I bullet has been met through documented design choices, risk assessment, and recognised technical inputs. Useful — but not legally privileged — inputs include ETSI EN 303 645 for consumer IoT, ISO/IEC 27001 and 27034, IEC 62443 series, NIST SSDF (SP 800-218), and the draft EN 40000 parts themselves.
For products that are also connected radio equipment, the Radio Equipment Directive delegated act (Commission Delegated Regulation (EU) 2022/30) already has its own harmonised standards path — see the RED EN 18031 walkthrough and the RED/CRA overlap article. EN 18031 is not, however, a CRA harmonised standard; do not confuse the two regulatory tracks.
Common mistakes
- Citing draft prEN numbers in the DoC. A "prEN" prefix means the document is a draft, not an adopted EN. It is never a valid OJEU citation. See our updating a DoC after amendment guide.
- Assuming EN 18031 covers CRA. EN 18031 parts 1, 2 and 3 are harmonised under the RED delegated act, not the CRA. They overlap on some Annex I requirements but do not give CRA presumption. Read our EN 18031 parts comparison for the boundary.
- Waiting for standards before starting. With first OJEU citations realistically arriving in 2027 and CRA applying in December 2027, manufacturers who wait will have weeks, not months. Build the technical file now against Annex I as explained here.
- Treating STAN4CR public drafts as legally binding. They are technically authoritative but legally informational. Until the OJ citation, they are evidence, not presumption.
How Cenitia helps
Cenitia continuously watches the CRA-relevant pages of the Official Journal of the EU and the STAN4CR work programme. When a harmonised standard is cited under Regulation (EU) 2024/2847, every technical file and Declaration of Conformity touching the affected Annex I requirements is automatically flagged for review, with a delta showing which clauses now offer presumption of conformity and which previously cited evidence can be retired.
Until citations exist, Cenitia builds the Annex I evidence map for you — linking each essential requirement to documented design decisions, risk-assessment outputs and recognised technical inputs, so the moment OJEU citations land you can swap state-of-the-art evidence for harmonised-standard references without rewriting the technical file.
One email at launch · cancel any time
Frequently asked questions
Are there any CRA harmonised standards in the OJEU yet?
No. As of July 2026 the Official Journal of the European Union contains no harmonised standards cited under Regulation (EU) 2024/2847 (the Cyber Resilience Act). Drafts of the horizontal EN 40000 series and ~18 vertical product-category standards are in public enquiry but have not yet been adopted and cited. First OJEU citations are publicly forecast for 2027.
What is standardisation request M/606?
M/606 is the Commission Implementing Decision (C(2025) 618) asking CEN, CENELEC and ETSI to draft a set of approximately 41 harmonised standards supporting the CRA — covering Annex I Part I (essential cybersecurity requirements) and Annex I Part II (vulnerability handling), plus product-specific vertical standards for Annex III/IV categories. The three ESOs formally accepted it on 3 April 2025.
Can I claim presumption of conformity today without a listed standard?
No. CRA Article 27 only grants presumption of conformity for products that comply with harmonised standards (or parts thereof) whose references have been published in the Official Journal. Until OJEU citation happens, applying a draft EN 40000 part does not give the legal presumption — it is technical state-of-the-art evidence only.
What should manufacturers do until standards are listed?
Demonstrate Annex I compliance directly through a documented risk assessment, technical state-of-the-art evidence, and traceable design decisions. The technical file must show that each essential requirement in Annex I has been met, supported by recognised inputs such as ETSI EN 303 645, ISO/IEC 27001/27034, NIST SP 800-218 (SSDF), or relevant sector standards — even though none of those carry CRA presumption today.
What is the EN 40000 series?
EN 40000 is the horizontal CRA standards family being drafted by CEN-CENELEC JTC 13. Public-facing work in 2026 covers parts on vocabulary, cyber-resilience principles, vulnerability handling and generic security requirements. The series is intended to be the primary horizontal route to presumption of conformity once cited in the OJEU.
Where can I track the live status?
Two authoritative pages: the Commission's CRA standardisation policy page on the Shaping Europe's Digital Future portal, and the STAN4CR project run by the European standardisation organisations. The Commission's OJEU page for Regulation (EU) 2024/2847 is the only definitive source for what is legally cited.
Related from the Library
- CRA Annex I essential requirements explained — the requirements the standards aim to operationalise
- EN 18031 parts 1, 2 and 3 compared — the parallel RED harmonised standards
- How to find harmonised standards in the OJ — the search workflow
- CRA timeline and reporting obligations — applicability dates that constrain the standards timeline
- CRA December 2027 readiness — what to ship even if standards arrive late
Further reading
- Regulation (EU) 2024/2847 — Cyber Resilience Act, EUR-Lex — primary legal text
- Cyber Resilience Act — Standardisation, European Commission — Commission policy page including M/606 reference
- STAN4CR project portal — live work programme run by CEN-CENELEC-ETSI
- CEN-CENELEC announcement of M/606 acceptance, April 2025 — formal acceptance of the request
- Harmonised standards — single-market overview — Commission overview of the harmonised-standards mechanism
- Cyber Resilience Act summary, Shaping Europe's Digital Future — Commission summary of the regulation
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
Are there any CRA harmonised standards in the OJEU yet?
No. As of July 2026 the Official Journal of the European Union contains no harmonised standards cited under Regulation (EU) 2024/2847 (the Cyber Resilience Act). Drafts of the horizontal EN 40000 series and ~18 vertical product-category standards are in public enquiry but have not yet been adopted and cited. First OJEU citations are publicly forecast for 2027.
What is standardisation request M/606?
M/606 is the Commission Implementing Decision (C(2025) 618) asking CEN, CENELEC and ETSI to draft a set of approximately 41 harmonised standards supporting the CRA — covering Annex I Part I (essential cybersecurity requirements) and Annex I Part II (vulnerability handling), plus product-specific vertical standards for Annex III/IV categories. The three ESOs formally accepted it on 3 April 2025.
Can I claim presumption of conformity today without a listed standard?
No. CRA Article 27 only grants presumption of conformity for products that comply with harmonised standards (or parts thereof) whose references have been published in the Official Journal. Until OJEU citation happens, applying a draft EN 40000 part does not give the legal presumption — it is technical state-of-the-art evidence only.
What should manufacturers do until standards are listed?
Demonstrate Annex I compliance directly through a documented risk assessment, technical state-of-the-art evidence, and traceable design decisions. The technical file must show that each essential requirement in Annex I has been met, supported by recognised inputs such as ETSI EN 303 645, ISO/IEC 27001/27034, NIST SP 800-218 (SSDF), or relevant sector standards — even though none of those carry CRA presumption today.
What is the EN 40000 series?
EN 40000 is the horizontal CRA standards family being drafted by CEN-CENELEC JTC 13. Public-facing work in 2026 covers parts on vocabulary, cyber-resilience principles, vulnerability handling and generic security requirements. The series is intended to be the primary horizontal route to presumption of conformity once cited in the OJEU.
Where can I track the live status?
Two authoritative pages: the Commission's CRA standardisation policy page on the Shaping Europe's Digital Future portal, and the STAN4CR project run by the European standardisation organisations. The Commission's OJEU page for Regulation (EU) 2024/2847 is the only definitive source for what is legally cited.
Continue reading
Related guides
guide
CRA enforcement countdown — T-365d, T-180d, T-90d
Operational countdown to the CRA general application date of 11 December 2027. Concrete checkpoints at T-12m, T-6m, T-3m and T-0 for hardware manufacturers.
8 min read
tutorial
How to check NANDO for Notified Bodies
Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.
5 min read
tutorial
How to find harmonised standards in the Official Journal
Tutorial: locate the current list of harmonised standards giving presumption of conformity in the OJEU, verify references, and read excluded clauses.
6 min read
tutorial
How to navigate EUR-Lex — find the consolidated version
Tutorial on EUR-Lex search, ELI URIs, CELEX numbers, and how to find the current consolidated version of an EU regulation plus subscribe to updates.
5 min read
Put this into practice
Free tools & references
- CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.