ETSI Draft Standards Close the Gap to CRA Compliance
By Michela Menting |
26 Aug 2026 |
IN-8257
Log In to unlock this content.
You have x unlocks remaining.
This content falls outside of your subscription, but you may view up to five pieces of premium content outside of your subscription each month
You have x unlocks remaining.
By Michela Menting |
26 Aug 2026 |
IN-8257
NEWSA Practical Compliance Pathway for Manufacturers |
On August 13, 2026, the European Telecommunication Standards Institute (ETSI) announced a public consultation into 17 draft European standards (ETSI EN 304 series standards on cybersecurity requirements) that are being proposed to support the implementation of the European Union (EU) Cyber Resilience Act (CRA). The goal is to enable Original Equipment Manufacturers (OEMs) to claim “presumption of conformity” with the CRA. The drafts span a whole gamut of technology (boot managers, Virtual Private Networks (VPNs), Public Key Infrastructure (PKI) certificate issuance) and end products (Internet connected toys, routers, modems and switches, personal wearables, etc.), so it should provide a comprehensive pool of effective technical documentation. Once the Public Enquiry period is over and formal approval has been granted (expected 4Q 2026), the harmonized standards will effectively serve as a blueprint for translating the CTA’s broad legal requirements into product-specific cybersecurity obligations.
IMPACTFrom Uncertain Obligations to Actionable Planning |
The CRA is a laudable effort, aiming to integrate digital security at the core of connected products. But as a piece of regulation, it can only ever serve as a high-level legal obligation. It cannot actually dictate the specific technical undertakings required to achieve conformity. This has proven to be problematic for OEMs that need to make critical decisions on how to engineer, test, and document the requirements in order to evidence compliance. OEMs have been delaying decision-making and implementation around the CRA. The standards are, therefore, an excellent start to providing a more technical baseline and actionable framework for OEMs to sink their teeth into. This will not only reduce uncertainty around design and support, but crucially, also help OEMs to start actually planning for effective compliance.
The draft standards are an important milestone as OEMs have traditionally lacked the level of product security governance that is now required by an instrument like the CRA. They set OEMs on the path to operationalizing compliance, not just across product security but also across organizational and process aspects, including coordinating with their supply chain. But it will be important to understand that these are drafts that are likely to evolve over the next few months. OEMs should remain attentive to the process.
Reporting obligations are set to begin next month, with full CRA compliance expected by December 2027. The standards will help OEMs address the “how” of the CRA’s implementation, but even formalized, only represent the rails for compliance. They cannot serve as a catch-all for every execution challenge. OEMs will still need to address complex issues such as legacy product designs, third-party security assurances, and lifecycle management. The key will be to build flexible security-by-design processes that can be repeatedly implemented across product lines.
RECOMMENDATIONSAn Opportunity to Shape Compliance |
Of particular interest is ETSI’s openness to engage with external stakeholders. Both the Public Enquiry and the CRA Standards Unlocked - EU Tour (in tandem with CEN and CENELEC) provide an opportunity for OEMs not just to understand the standardization and compliance process, but to actually participate in it. There is an open window when feedback is being actively sought by ETSI and its partners. OEMs should leverage the open consultation period to share any relevant comments from their design, test alignment controls, and benchmarking exercise they undertake in relation to the draft standards. This is especially important when OEMs uncover practical implementation issues or discover incompatibilities that may affect compliance.
For OEMs, the drafts should be used to kick-start a number of processes: product-mapping against the relevant draft standards, initiating software supply chain visibility (especially around Software Bill of Materials (SBOM) requirements), and planning cross-functional CRA governance programs across the various business units and teams within organizations. The standards are a credible benchmark for conformity assessment and the feedback mechanism currently open with ETSI’s Public Enquiry will be invaluable down the line for attaining market trust in CRA compliance. OEMs should start becoming actively involved in it now to ensure an optimal go-to-market strategy next year.
Written by Michela Menting
Michela Menting leads ABI Research’s coverage of digital security, IoT, and space technologies. She delivers end-to-end research, closely analyzing technology trends, growth opportunities, and industry-specific implementations in end markets, including enterprise, government, financial, telecommunications, industrial, and IoT. She has extensive experience and industry insight into the latest solutions in digital security technologies, from trusted silicon and hardware to secure applications and infrastructures.
Related Service
- Competitive & Market Intelligence
- Executive & C-Suite
- Marketing
- Product Strategy
- Startup Leader & Founder
- Users & Implementers
Job Role
- Telco & Communications
- Hyperscalers
- Industrial & Manufacturing
- Semiconductor
- Supply Chain
- Industry & Trade Organizations
Industry
Services
Spotlights
5G, Cloud & Networks
- 5G Devices, Smartphones & Wearables
- 5G, 6G & Open RAN
- Data Centers
- Enterprise Connectivity
- Space Technologies & Innovation
- Telco AI
AI & Robotics
Automotive
Bluetooth, Wi-Fi & Short Range Wireless
Cyber & Digital Security
- Citizen Digital Identity
- Digital Payment Technologies
- eSIM & SIM Solutions
- Quantum Safe Technologies
- Trusted Device Solutions