AI & TechBusinessCybersecurityNewswireTechnology

ETSI Unveils 17 Cybersecurity Standards for EU CRA Compliance

Originally published on: August 18, 2026
▼ Summary

– ETSI launched an approval process for 17 cybersecurity standards covering network, edge, security, and IoT product categories under the EU Cyber Resilience Act (CRA), which takes full effect in December 2027.
– The standards mandate minimum security features for manufacturers, including modern cryptography, secure-by-default settings, a software bill of materials (SBOM), and post-sale update capabilities.
– The standards were submitted to 41 member organizations across Europe and are under public enquiry, with stakeholder comments accepted from mid-September to mid-November 2026 depending on the vertical.
– Final versions of the standards are expected by December 2026, applying to all manufacturers, importers, distributors, service providers, and developers of commercial hardware and software sold in the EU from end of 2027.
– ETSI, along with CEN and CENELEC, organized workshops across Europe to help small and medium businesses comply with the CRA when enforced.

Europe’s technology standards are shifting into high gear as preparations intensify for the EU Cyber Resilience Act (CRA), which becomes fully enforceable in December 2027. On August 13, the European Telecommunications Standards Institute (ETSI), one of the three official standardization bodies recognized by the EU, initiated the approval process for a suite of 17 cybersecurity standards that will shape how vendors build and sell connected products across the bloc.

These draft standards, now entering formal review, define the minimum security requirements manufacturers must bake into their products to achieve CRA compliance and legally sell hardware or software in the EU once the regulation kicks in. The scope spans 17 major product categories, covering everything from network and edge devices to security tools and internet-of-things (IoT) appliances.

Among the core mandates outlined in the proposed texts are the adoption of modern cryptography, implementation of secure-by-default configurations, and the generation of a software bill of materials (SBOM), a machine-readable inventory that catalogs all software dependencies. Additionally, vendors will be required to build in post-sale update capabilities to address vulnerabilities over a product’s lifecycle.

The standards have been forwarded to 41 member organizations, including national standardization bodies across the European Economic Area and various Europe-wide industry groups. They are now under public enquiry, marking the first stage of the formal approval workflow. Interested stakeholders can submit feedback from mid-September through mid-November 2026, with exact deadlines varying by sector.

Finalized versions of all 17 cybersecurity standards are slated for release by December 2026. Once published, they will apply to every manufacturer, importer, distributor, service provider, and developer offering commercially available hardware or software products in the EU starting in late 2027.

To ease the transition, ETSI, together with the other two EU-approved bodies, the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), has rolled out a series of workshops across Europe. These sessions are designed specifically to help small and medium-sized enterprises grasp the requirements and align their operations with the CRA before enforcement begins.

(Source: Infosecurity Magazine)

Topics

eu cyber resilience act 98% cybersecurity standards 95% product categories 87% manufacturer compliance 85% european standardization bodies 83% standards approval process 82% eu market access 81% software bill of materials 80% iot security 79% secure-by-default settings 78%