Independent information resource Product security · EU CRA
CRA standards, guidance and rulemaking / 11

CRA and ETSI EN 303 645

Understand how ETSI EN 303 645 can support CRA readiness for consumer IoT products, where its baseline provisions overlap with Annex I and why the current standard should not be treated as automatic CRA presumption of conformity.

IN BRIEF

Consumer IoT manufacturers with EN 303 645 evidence have a useful starting point for CRA mapping, but the CRA is broader. Product-specific risk assessment, full Annex I coverage, support-period duties, CRA reporting, Annex II user information, technical documentation and the applicable conformity route still need to be addressed. The legal status of any future CRA harmonised standard must be confirmed through the Official Journal.

01 / 06

EN 303 645 Provides a Consumer IoT Cybersecurity Baseline

ETSI describes EN 303 645 as a baseline cybersecurity standard for consumer Internet of Things devices. The current V3.1.3 edition was published in September 2024. It uses high-level, outcome-focused provisions intended to support manufacturers and other stakeholders securing connected consumer products and associated services.

  • Consumer IoT focus.
  • Outcome-focused security provisions.
  • Device and associated-service context.
  • Baseline product-security practices.
02 / 06

Several EN 303 645 Areas Overlap With CRA Product Security

Consumer IoT controls concerning credential security, vulnerability handling, software updates, secure communications, data protection, attack-surface reduction and resilience can provide useful evidence for corresponding CRA concerns. The mapping should remain requirement-specific because terminology and scope differ and the CRA contains additional legal obligations beyond the technical baseline.

  • Credential security.
  • Vulnerability disclosure.
  • Software updates.
  • Secure communications.
  • Attack-surface reduction.
  • Resilience.
03 / 06

A European Standard Is Not Automatically a CRA Harmonised Standard

The fact that EN 303 645 is a European Standard does not by itself mean it creates CRA Article 27 presumption of conformity. That legal effect requires the relevant harmonised-standard reference to be published in the Official Journal for covered CRA requirements. ETSI's current work item information for EN 303 645 V3.1.3 identifies its harmonised-standard field as No, so companies should avoid presenting current EN 303 645 use as automatic CRA harmonised conformity.

  • Track European Standard status.
  • Track CRA harmonised status separately.
  • Check Official Journal references.
  • Avoid unsupported presumption-of-conformity claims.
04 / 06

Use EN 303 645 as Evidence, Not as a Whole-CRA Shortcut

A manufacturer can reuse EN 303 645 design decisions, test results, vulnerability-disclosure processes and update evidence where they support CRA requirements. The CRA mapping should identify what the existing evidence covers and what remains outside the standard's consumer-IoT baseline, including regulatory reporting, support-period determination, user information and conformity documentation.

  • Reuse product-security evidence.
  • Map evidence to Annex I.
  • Identify regulatory gaps.
  • Add CRA-specific documentation.
05 / 06

Consumer IoT Products Still Need Product-Specific CRA Risk Assessment

Article 13 requires a cybersecurity risk assessment for the specific product. EN 303 645 can inform controls and good practice, but the manufacturer still needs to assess intended purpose, reasonably foreseeable use, product architecture, cloud or mobile dependencies, threats and residual risks for the actual product placed on the market.

  • Product architecture.
  • Cloud dependencies.
  • Mobile application dependencies.
  • Threats and misuse.
  • Residual risks.
06 / 06

Monitor the CRA Standardisation Programme for IoT-Specific Developments

The Commission CRA standardisation request includes product-specific work for important and critical categories as well as horizontal standards. Consumer IoT manufacturers should monitor whether new CRA harmonised standards build on, replace or coexist with EN 303 645 evidence. Any change in legal status should trigger a mapping and conformity-route review rather than an assumption that existing certification automatically transfers.

  • Monitor Commission CRA standardisation.
  • Monitor ETSI work items.
  • Check Official Journal references.
  • Reassess mappings when new standards appear.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.