ETSI EN 304: The Standards Behind the CRA
ETSI TC Cyber Working Group EUSR is developing 18 product-specific (“vertical”) standards that define the technical requirements for CRA compliance. Understanding these standards is critical for manufacturers.
The 18 Standards
Important Products — Class I (Self-Assessment Possible)
| Standard | Product Category |
|---|---|
| EN 304 617 | Browsers |
| EN 304 618 | Password Managers |
| EN 304 620 | Virtual Private Networks (VPNs) |
| EN 304 621 | Network Management Systems (NMS) |
| EN 304 623 | Boot Managers |
| EN 304 625 | Physical and Virtual Network Interfaces |
| EN 304 626 | Operating Systems (OS) |
| EN 304 627 | Routers, modems, and switches |
| EN 304 631 | Smart home general purpose virtual assistants |
| EN 304 632 | Smart home products with security functionalities |
| EN 304 633 | Internet connected toys |
| EN 304 634 | Personal wearable products |
Important Products — Class II (Third-Party Assessment May Be Required)
| Standard | Product Category |
|---|---|
| EN 304 619 | Antivirus software |
| EN 304 622 | Security Information and Management Systems (SIEM) |
| EN 304 624 | PKI and digital certificate issuance software |
| EN 304 635 | Hypervisors and container runtime systems |
| EN 304 636 | Firewalls, IDS/IPS |
Critical Products
| Standard | Product Category |
|---|---|
| EN 304 642 | Network functions of telecommunications systems |
Standard Development Process
ETSI TC Cyber WG EUSR
↓ drafts standards
Public Consultation
↓ industry feedback
Final Draft
↓ ETSI approval
Published Standard
↓ referenced in EU Official Journal
Harmonized Standard (presumption of conformity)Working Groups Involved
- ETSI TC Cyber WG EUSR — leads 18 product standards
- CEN/TC 13 — additional horizontal standards
- CLC/TC 65X WG 14 — industrial automation aspects
- CLC/TC 45X WG 3 — additional electrical safety
How Standards Map to CRA Requirements
Each EN 304 standard addresses:
- Security properties — specific to the product category
- Vulnerability handling — aligned with CRA Article 11
- Technical documentation — what must be documented
- Testing methods — how to verify compliance
- SBOM requirements — component documentation specifics
Timeline
- 2024-2025: Initial drafts published for public comment
- 2025-2026: Standards finalized and published
- 2026: Standards referenced as harmonized standards
- 2027: Full CRA enforcement (standards provide presumption of conformity)
What If No Harmonized Standard Exists?
If ETSI standards aren’t ready by enforcement date, manufacturers can:
- Apply common specifications adopted by the European Commission
- Conduct their own risk assessment against CRA essential requirements
- Use third-party assessment to demonstrate conformity
Staying Current
- Follow ETSI TC Cyber: etsi.org/committee/cyber
- CRA text: EU Official Journal
- ENISA guidance: enisa.europa.eu
Need guidance navigating ETSI standards for CRA compliance? I help organizations map their products to the right standards. Get in touch.