The European Telecommunications Standards Institute (ETSI) has initiated the approval process for 17 cybersecurity standards that will govern product sales in the European Union under the Cyber Resilience Act (CRA). Released on August 13, these draft standards establish minimum security requirements for manufacturers across 17 major product categories, including network and edge devices, security solutions, and internet-of-things (IoT) appliances. The standards will become mandatory when the CRA takes full effect in December 2027.
ETSI, one of three official standards organizations recognized by the EU alongside the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), developed these standards to prepare European technology vendors for the upcoming regulatory requirements. The CRA represents a significant shift in how the EU regulates cybersecurity for commercial products, establishing baseline security expectations across the single market.
The proposed standards mandate several technical requirements that manufacturers must implement to achieve CRA compliance. These include modern cryptographic protocols, secure-by-default configurations, software bills of materials (SBOMs) that provide machine-readable inventories of software dependencies, and mechanisms for delivering post-sale security updates. These requirements aim to address common security vulnerabilities that have plagued commercial products and create a more secure technology ecosystem across Europe.
The standards have been submitted to 41 member organizations across Europe, including national standardization bodies from the European Economic Area and Europe-wide industry organizations. They are currently under public enquiry as part of the first phase of the approval procedure. Stakeholders can submit comments through mid-September to mid-November 2026, depending on the specific product vertical. Final versions of the 17 standards are expected to be published by December 2026.
The standards will apply to all manufacturers, importers, distributors, service providers, and developers of commercially available hardware and software products sold in the EU from the end of 2027. To support compliance efforts, ETSI, CEN, and CENELEC have organized workshops across Europe specifically targeting small and medium businesses that may need additional guidance to meet the new requirements. Organizations selling products in the EU market should review the draft standards relevant to their product categories and prepare implementation plans to ensure compliance before the December 2027 deadline.
Source: https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/


