A static CRA compliance programme can become outdated even when the Regulation itself has not changed. Companies need a living update process that monitors the Official Journal, Commission CRA implementation and standardisation pages, ENISA operational guidance, delegated acts, implementing acts and relevant standards work. Each update should be assessed for the products, controls, documentation and conformity routes it actually affects.
CRA Implementation Continues After the Regulation Was Adopted
Regulation (EU) 2024/2847 establishes the legal framework, but important implementation detail continues to develop. Article 27 creates the framework for harmonised standards and common specifications. Articles 61 and 62 establish procedures for delegated and implementing acts. Other provisions empower the Commission to update product categories, adopt technical descriptions and support implementation through guidance. ENISA also has operational roles, especially around reporting and vulnerability information.
- Monitor binding secondary legislation.
- Monitor harmonised standards and Official Journal references.
- Monitor Commission guidance.
- Monitor ENISA operational guidance.
- Assess each update against the affected product portfolio.
Harmonised Standards Can Create Presumption of Conformity
Article 27 provides that products and manufacturer processes conforming to harmonised standards, or parts of them, whose references have been published in the Official Journal of the European Union are presumed to conform with the Annex I essential cybersecurity requirements covered by those standards or parts. The presumption is limited to the requirements actually covered. A useful cybersecurity standard does not automatically receive this legal effect merely because it is widely recognised.
- Check whether the standard reference is published in the Official Journal.
- Identify which Annex I requirements the standard covers.
- Record whether the standard is applied fully or partly.
- Do not assume one standard covers the complete CRA.
The Commission Has Requested 41 CRA Standardisation Deliverables
The Commission's CRA standardisation page states that standardisation request M/606 contains 41 standards in support of the CRA. The work includes horizontal standards and product-specific standards. Horizontal work is intended to support common approaches such as vulnerability handling, while vertical standards are intended to address particular product categories and risks. The Commission implementation timeline identifies first standardisation deliverables in Q3 2026 and further deliverables by 30 October 2027.
- Track horizontal standards.
- Track product-specific standards.
- Watch important and critical product categories closely.
- Treat development milestones separately from Official Journal citation.
Common Specifications Are an Exceptional Fallback Mechanism
Article 27 allows the Commission to adopt implementing acts establishing common specifications when specified conditions concerning harmonised standards are met, such as a request not being accepted, a requested standard not being delivered in time or a standard not complying with the request, together with the absence of an applicable Official Journal reference expected within a reasonable period. Common specifications can also create presumption of conformity for the Annex I requirements they cover.
- Do not treat common specifications as the default route.
- Check the implementing act and the requirements it covers.
- Monitor replacement by later harmonised standards.
- Update technical documentation when the applicable basis changes.
Guidance Helps Interpret Implementation but Does Not Rewrite the CRA
Commission and ENISA publications can be important operational sources, but they should be classified correctly inside a compliance programme. Guidance can explain implementation, reporting, terminology or expected evidence. It does not have the same legal status as the Regulation or a binding delegated or implementing act. Teams should therefore record both the legal requirement and the guidance used to interpret or operationalise it.
- Separate legal requirements from explanatory guidance.
- Record the guidance version and publication date.
- Review guidance when processes or documentation change.
- Escalate conflicts to the controlling legal text.
Delegated Acts and Implementing Acts Serve Different Functions
The CRA gives the Commission different kinds of rulemaking power. Delegated acts can supplement or amend specified non-essential elements where the Regulation grants that power, such as updating categories in Annex III or Annex IV. Implementing acts are used where uniform conditions for implementation are needed, including technical descriptions and possible common specifications. Compliance teams should identify the enabling CRA article before treating a new act as relevant to a product.
- Identify whether the measure is delegated or implementing.
- Identify the CRA article granting the power.
- Check transitional periods and application dates.
- Map the change to affected products and documentation.
Product Classification Is Not Permanently Frozen
Article 7 empowers the Commission to amend Annex III by adding categories, moving categories between class I and class II or withdrawing categories, subject to the criteria in Article 7. Article 8 also gives powers concerning Annex IV critical products. Manufacturers should therefore treat classification as a maintained compliance fact rather than a one-time decision that can never change.
- Record the current product classification basis.
- Monitor delegated acts affecting Annex III and Annex IV.
- Review conformity routes after classification changes.
- Track transitional periods before new assessment requirements apply.
Existing Cybersecurity Standards Still Need Requirement-Level Mapping
ISO, IEC and ETSI standards can provide valuable management, development, vulnerability-handling and technical control frameworks. Their usefulness does not automatically make them harmonised standards under Article 27. A manufacturer should map relevant clauses and evidence to CRA requirements, identify gaps and then separately determine whether an Official Journal cited harmonised standard, common specification or certification scheme creates a formal presumption of conformity.
- Map standard clauses to CRA requirements.
- Identify uncovered Annex I requirements.
- Reuse valid technical and process evidence.
- Keep legal status separate from technical usefulness.
Maintain a CRA Regulatory Update Register
A practical monitoring process should record the source, publication date, legal status, affected CRA provision, affected products, internal owner, required action and implementation deadline for each material update. This turns CRA monitoring from passive news reading into a controlled change-management process. The register should include closed assessments as well as open actions so the company can show why a published update did or did not require a product change.
- Source and publication date.
- Legal status.
- Affected CRA provision.
- Affected products.
- Owner and action.
- Deadline and closure evidence.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.