ETSI EN 304: The Standards Behind the CRA
ETSI TC Cyber Working Group EUSR is developing 18 product-specific (βverticalβ) standards that define the technical requirements for CRA compliance. Understanding these standards is critical for manufacturers.
The 18 Standards
Important Products β Class I (Self-Assessment Possible)
| Standard | Product Category |
|---|---|
| EN 304 617 | Browsers |
| EN 304 618 | Password Managers |
| EN 304 620 | Virtual Private Networks (VPNs) |
| EN 304 621 | Network Management Systems (NMS) |
| EN 304 623 | Boot Managers |
| EN 304 625 | Physical and Virtual Network Interfaces |
| EN 304 626 | Operating Systems (OS) |
| EN 304 627 | Routers, modems, and switches |
| EN 304 631 | Smart home general purpose virtual assistants |
| EN 304 632 | Smart home products with security functionalities |
| EN 304 633 | Internet connected toys |
| EN 304 634 | Personal wearable products |
Important Products β Class II (Third-Party Assessment May Be Required)
| Standard | Product Category |
|---|---|
| EN 304 619 | Antivirus software |
| EN 304 622 | Security Information and Management Systems (SIEM) |
| EN 304 624 | PKI and digital certificate issuance software |
| EN 304 635 | Hypervisors and container runtime systems |
| EN 304 636 | Firewalls, IDS/IPS |
Critical Products
| Standard | Product Category |
|---|---|
| EN 304 642 | Network functions of telecommunications systems |
Standard Development Process
ETSI TC Cyber WG EUSR
β drafts standards
Public Consultation
β industry feedback
Final Draft
β ETSI approval
Published Standard
β referenced in EU Official Journal
Harmonized Standard (presumption of conformity)Working Groups Involved
- ETSI TC Cyber WG EUSR β leads 18 product standards
- CEN/TC 13 β additional horizontal standards
- CLC/TC 65X WG 14 β industrial automation aspects
- CLC/TC 45X WG 3 β additional electrical safety
How Standards Map to CRA Requirements
Each EN 304 standard addresses:
- Security properties β specific to the product category
- Vulnerability handling β aligned with CRA Article 11
- Technical documentation β what must be documented
- Testing methods β how to verify compliance
- SBOM requirements β component documentation specifics
Timeline
- 2024-2025: Initial drafts published for public comment
- 2025-2026: Standards finalized and published
- 2026: Standards referenced as harmonized standards
- 2027: Full CRA enforcement (standards provide presumption of conformity)
What If No Harmonized Standard Exists?
If ETSI standards arenβt ready by enforcement date, manufacturers can:
- Apply common specifications adopted by the European Commission
- Conduct their own risk assessment against CRA essential requirements
- Use third-party assessment to demonstrate conformity
Staying Current
- Follow ETSI TC Cyber: etsi.org/committee/cyber
- CRA text: EU Official Journal
- ENISA guidance: enisa.europa.eu
Need guidance navigating ETSI standards for CRA compliance? I help organizations map their products to the right standards. Get in touch.
