How this CRA standards mapping is structured

This CRA standards mapping presents the different Cyber Resilience Act standards in a structured, table-based format, making it easier to navigate an otherwise complex and evolving landscape.
The mapping is organised by product category — Horizontal, Important Class I, Important Class II, and Critical— and each entry shows the key information for a specific topic, including the related standard or draft, the working group responsible for it, its current status and links to supporting materials such as drafts or webinars. As many CRA standards are still under development or consultation, this structure helps provide a clear and up-to-date view of how the standardization process is progressing.

How to use this CRA standards mapping in practice

This Cyber Resilience Act standards mapping is designed to be quickly consulted while working on CRA compliance. It allows you to identify which standards are relevant to your product, understand their current level of maturity, and directly access additional information such as draft specifications or expert webinars. Because many standards are still evolving, the mapping helps you follow their development and anticipate future requirements instead of waiting for final harmonized versions.

 

CRA Horizontals Standards 

Topic ID Topic Key standard(s) Working group(s) Relevant links and webinars
1 Principles for CyberResilience (Horizontal)

prEN 40000-1-2

prEN 40000-1-1

CEN-CLC/JTC13 WG 9, PT1 Webinar 'Standards supporting the Cyber Resilience Act'

Horizontal baseline: cybersecurity principles + lifecycle risk-management activities for CRA-aligned products; uses shared vocabulary from prEN 40000-1-1.

Status: Public Enquiry closed → finalisation/approval

2–14 Generic Security Requirements (Horizontal) prEN 40000-1-4 (Generic Security Requirements) CEN-CLC/JTC13 WG 9, PT2

Webinar 'Standards supporting the Cyber Resilience Act'
Webinar 'Unlocking CRA Security Controls'
Webinar 'Generic Security Requirements'

Catalog of security requirements/controls manufacturers select & justify based on risk-management principles; intended as a common horizontal baseline and normative reference for vertical standards.

Status: In development.

15 Vulnerability handling (Horizontal) – PT3 prEN 40000-1-3 (Vulnerability Handling) CEN-CLC/JTC13 WG 9, PT3 Webinar 'Standards supporting the Cyber Resilience Act'

Defines vulnerability-handling and disclosure requirements across the product lifecycle (e.g., intake/triage, coordinated disclosure, fixes/updates and communications).

Status: Public Enquiry closed → finalisation/approval

Standards for Important Class I Category

Topic ID Topic Key standard(s) Working group(s) Relevant links and webinars
16 Identity management systems and privileged access management (PAM) software/hardware, incl. authentication & access control readers (incl. biometric readers) prEN40000-10 CEN/TC 224 WG17 Webinar CRA 'Requirements for identity management systems'
Status: In Development
17a / 17b Standalone (17b) and embedded browsers (17a) EN 304 617 ETSI CYBER EUSR Draft ETSI EN 304 617

ETSI EUSR mature draft for browsers (standalone & embedded).

Status: Public Enquiry / approval process

18 Password managers EN 304 618 ETSI CYBER EUSR Draft ETSI EN 304 618

ETSI EUSR mature draft for password managers.

Status: Public Enquiry / approval process.

19 Software that searches for, removes, or quarantines malicious software EN 304 619 ETSI CYBER EUSR Draft ETSI EN 304 619

ETSI EUSR mature draft for antivirus/antimalware products.

Status: Public Enquiry / approval process.

20a / 20b Products with digital elements with the function of virtual private network (VPN)

EN 304 620

prEN 50770-4

ETSI CYBER EUSR (20a) 

CLC/TC 65X WG3 (20b)

Draft ETSI EN 304 620
Webinar 'CRA Standards Unlocked: from EN IEC 62443 to CRA'

ETSI EUSR mature draft for VPN products. CENELEC T65X: OT mapping based on 62443 series (WI 81652- Vertical: prEN 50XXX-4).

Status:  EN 304 620 - VPN Public enquiry | prEN 50770-4 OT VPN In development.

21a / 21b Network management systems

EN 304 621

prEN 50770-2

ETSI CYBER EUSR (21a)

CLC/TC 65X WG3 (21b)

Draft ETSI EN 304 621

ETSI EUSR mature draft for network management systems. CENELEC T65X: OT mapping based on 62443 series (WI 81654- Vertical: prEN 50XXX-6).

Status: EN 304 621 Public Enquiry | prEN 50770-2 Under development

22a / 22b Security information and event management (SIEM) systems

EN 304 622

prEN 50770-6

ETSI CYBER EUSR (22a) 

CLC/TC 65X WG3 (22b)

Draft ETSI EN 304 622
Webinar 'CRA Standards Unlocked: from EN IEC 62443 to CRA'

ETSI EUSR mature draft for SIEM systems. CENELEC T65X: OT mapping based on 62443 series (WI 81651- Vertical: prEN 50XXX-3).

Status: EN 304 622 Public Enquiry |  prEN 50770-6 In development

23 Boot managers EN 304 623 ETSI CYBER EUSR Draft ETSI EN 304 623

ETSI EUSR mature draft for boot managers.

Status: Public Enquiry / approval process

24 Public key infrastructure (PKI) and digital certificate issuance software EN 304 624 ETSI CYBER EUSR Draft ETSI EN 304 624

ETSI EUSR mature draft for PKI & certificate issuance software.

Status: Public Enquiry / approval process

25 Physical and virtual network interfaces

EN 304 625

prEN 50770-3

ETSI CYBER EUSR

CENELEC T65X

Draft ETSI EN 304 625

ETSI EUSR mature draft for network interfaces. CENELEC T65X: OT mapping based on 62443 series (WI 81653- Vertical: prEN 50XXX-5).

Status: EN 304 625 Public Enquiry |  prEN 50770-3 In development

26 Operating systems EN 304 626 ETSI CYBER EUSR Draft ETSI EN 304 626

ETSI EUSR mature draft for operating systems.

Status: Public Enquiry / approval process

27 Routers, modems intended for internet connection, and switches

EN 304 627

prEN 50770-5

ETSI CYBER EUSR

CENELEC T65X

Draft ETSI EN 304 627

ETSI EUSR mature draft for routers/modems/switches. CENELEC T65X: OT mapping based on 62443 series (WI 81650- Vertical: prEN 50XXX-2).

Status: EN 304 627 Public Enquiry |  prEN 50770-5 In development

EN 304 627 Guide for CRA Compliance

28 Microprocessors with security-related functionalities EN50765 CLC/TC 47X WG 1 SEMI Presentation

Referenced in SEMI presentation (Sept 17, 2025).

Status: Public Enquiry closed

29 Microcontrollers with security-related functionalities EN50765 CLC/TC 47X WG 1 SEMI Presentation

Referenced in SEMI presentation (Sept 17, 2025).

Status: Public Enquiry closed

30 ASIC and FPGA with security-related functionalities EN50767 CLC/TC 47X WG 4 SEMI Presentation

Referenced in SEMI presentation (Sept 17, 2025).

Status: In development.

31 Smart home general purpose virtual assistants EN 304 631 ETSI CYBER-EUSR Draft ETSI EN 304 631

ETSI EUSR mature draft for Smart home general purpose virtual assistants

Status: ETSI approval process

32 Smart home products with security functionalities (e.g., smart door locks, security cameras, baby monitors, alarm systems) EN 304 632 ETSI CYBER-EUSR Draft ETSI EN 304 632

ETSI EUSR mature draft for Smart home products with security functionalities

Status: ETSI approval process

33 Internet connected toys (Directive 2009/48/EC) with social interaction or location tracking EN 304 633 ETSI CYBER-EUSR Draft ETSI EN 304 633
ETSI EUSR mature draft for Internet Connected toys.
Status: ETSI approval process
34 Personal wearable products (non-MDR/IVDR) incl. children’s wearables with health monitoring purpose EN 304 634 ETSI CYBER-EUSR Draft ETSI EN 304 634

ETSI EUSR interim draft for Personal wearable products.

Status: Public Enquiry / approval process

Standards for Important Class II Category

Topic ID Topic Key standard(s) Working group(s) Relevant links and webinars
35 Hypervisors and container runtime systems that support virtualised execution of OS and similar environments EN 304 635 ETSI CYBER-EUSR Draft ETSI EN 304 635

ETSI docbox mature draft for virtualisation/container runtime.

Status: Public Enquiry / approval process

36a / 36b Firewalls, intrusion detection and prevention systems

EN 304 636

EN 62443-5-XX (reference listed)

ETSI CYBER EUSR (36a) 

CLC/TC 65X WG 3 (36b)

Draft ETSI EN 304 636
Webinar 'CRA Standards Unlocked: from EN IEC 62443 to CRA'

ETSI docbox mature draft for firewalls; additional reference to IEC/EN 62443-5-XX listed. CENELEC T65X: OT mapping based on 62443 series (WI 81649- Vertical: prEN 50XXX-1).

Status: Approval process / EC assessment

37 Tamper-resistant microprocessors EN 50766; SESIP (EN 17927:2023); Under consideration: Common Criteria (EN 18045-3:2022); FiT CEM CLC/TC 47X WG 2 SEMI Presentation

References SESIP and potential Common Criteria/FiT CEM; SEMI presentation link provided.

Status: Public Enquiry closed

38 Tamper-resistant microcontrollers EN 50766; SESIP (EN 17927:2023); Under consideration: Common Criteria (EN 18045-3:2022); FiT CEM CLC/TC 47X WG 2 SEMI Presentation

References SESIP and potential Common Criteria/FiT CEM; SEMI presentation link provided.

Status: Public Enquiry closed

Standards for Critical Category

Topic ID Topic Key standard(s) Working group(s) Relevant links and webinars
39 Hardware devices with security boxes  prEN 40000-11 CEN/TC 224 WG17 Webinar 'CRA Standards Unlocked: HWSB '

Draft standard under comments from the commision (until w7 of 2026). Public enquiry (PE) expected to start last week of March and expecting approval end 2026. Common Criteria EUCC using PPs listed in SOGIS Website.

Status: In development

40 Smart meter gateways within smart metering systems   CLC/TC JTC13 WG6

Webinar 'CRA Standards Unlocked: Smart Meters' Part 1 

Webinar 'CRA Standards Unlocked: Smart Meters' Part 2

Common Criteria EUCC using Protection Profile for Smart Meter Gateways (BSI-CC-PP-0073)

Status: In development

41a / 41b Smartcards or similar devices, including secure elements EN 50764 (Common Criteria) CLC/TC 47X WG 3 CEN/TC 224 WG17 Webinar 'CRA Standards Unlocked'
Presentation 'CRA Standards Unlocked'

References Common Criteria EUCC, and SOGIS PPs. Based on Common Criteria (EN 18045-3:2022) + use case dependent Protection Profile: • PP0084 • PP0117 • PP099 • PP0104 • PP TPM

Status: Public Enquiry Closed

 

How Applus+ Laboratories can support CRA standards mapping and compliance preparation

Applus+ Laboratories helps manufacturers make sense of the evolving CRA standards mapping by combining regulatory insight with practical cybersecurity expertise. We continuously monitor the development of Cyber Resilience Act standards, including drafts and working groups, to help you understand what is relevant for your products and how requirements are taking shape. Beyond the mapping, we support you in translating these standards into concrete actions, ensuring your preparation is aligned with the latest developments and ready for future Cyber Resilience Act compliance.

 

Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.

Cookie settings panel