Independent information resource Product security · EU CRA
CRA standards, guidance and rulemaking / 02

How to Monitor New CRA Harmonised Standards

A practical monitoring workflow for new Cyber Resilience Act harmonised standards, Official Journal references, Commission standardisation milestones, product-specific standards and internal compliance impact assessments.

IN BRIEF

Standards monitoring is most useful when it is tied to product ownership. The company should know which product families depend on which standards, who owns the assessment, what evidence must change and when the new or revised basis becomes effective. A standards watchlist without product mapping creates awareness but not compliance control.

01 / 08

Monitor Both Standards Development and Legal Status

The Commission's CRA standardisation page is useful for understanding the programme of horizontal and product-specific work. The Official Journal is the legal checkpoint for Article 27 presumption of conformity. Monitoring only one layer can create false confidence. Development pages can show what is coming, while Official Journal references show when a harmonised standard has the legal status relevant to the presumption for covered requirements.

  • Monitor development status.
  • Monitor Official Journal references.
  • Record standard version and date.
  • Record covered CRA requirements.
02 / 08

Use the Commission CRA Standardisation Page as a Programme View

The Commission CRA standardisation page describes standardisation request M/606, the 41 requested standards and the distinction between horizontal and product-specific deliverables. It also points to standards-development resources. Compliance teams can use this page to understand the programme and prioritise standards likely to affect their products, while remembering that development information is not the same as an Official Journal reference.

  • Track M/606 programme changes.
  • Identify horizontal standards relevant across products.
  • Identify product-specific standards relevant to Annex III or IV categories.
  • Record anticipated milestones.
03 / 08

Use the CRA Implementation Timeline for Major Milestones

The Commission implementation timeline identifies first standardisation deliverables in Q3 2026 and more deliverables by 30 October 2027. These milestones are useful planning signals, not substitutes for checking the status of individual standards. A company should use timeline dates to schedule review capacity and then confirm the actual standard, version and legal status when the deliverable appears.

  • Use milestones for planning.
  • Confirm each deliverable individually.
  • Do not assume all standards arrive on one date.
  • Update the monitoring register as milestones change.
04 / 08

Track Standards by Product Family

A manufacturer with several product families should not maintain one undifferentiated standards list. Each standard should be mapped to products, relevant Annex I requirements, product classification and conformity route. This makes it possible to identify quickly which products need review when a reference is published, amended or replaced.

  • Product family.
  • Standard and version.
  • Relevant CRA requirement.
  • Classification and conformity route.
  • Internal owner.
05 / 08

Distinguish a New Standard From a Revised Standard

A revised harmonised standard can be as important as a new one because products may already rely on an older version. Monitoring should capture amendments, corrigenda, replacement versions and any transition arrangements associated with Official Journal references. The company should assess whether existing technical evidence remains valid or whether testing, documentation or design needs to change.

  • Track old and new versions.
  • Identify transition information.
  • Assess evidence reuse.
  • Plan retesting where necessary.
06 / 08

Trigger an Impact Assessment When a Relevant Reference Appears

A standards update should create a controlled assessment rather than an email notification that disappears. The assessment should identify the affected products, the Annex I requirements covered, whether the company intends to apply the standard fully or partly, effects on conformity assessment, changes to technical documentation and any implementation deadline or transition period.

  • Affected products.
  • Covered requirements.
  • Application decision.
  • Conformity-route impact.
  • Documentation changes.
  • Deadline and owner.
07 / 08

Keep Evidence of Standards Decisions

Not every new standard will require a product change. A product may be outside its scope, use another valid conformity route or already meet the covered requirements through other evidence. The monitoring record should preserve that conclusion and its reasoning. This allows future reviewers to distinguish an intentionally assessed update from an update that was simply missed.

  • Record applicability decision.
  • Record the technical and legal basis.
  • Record required actions or no-action conclusion.
  • Retain closure evidence.
08 / 08

Assign Ownership for Continued Standards Monitoring

Standards monitoring can sit across product security, compliance, legal, engineering and standards specialists. The important point is to assign accountable ownership. One team should maintain the watch process, while product owners remain responsible for assessing and implementing changes for their products. Without this handoff, a central standards team can identify changes that never reach the engineering backlog.

  • Name the monitoring owner.
  • Name product impact owners.
  • Define escalation for high-impact changes.
  • Review open actions periodically.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.