ETSI has launched the approval process for 17 draft European cybersecurity standards intended to support implementation of the EU Cyber Resilience Act (CRA), expanding the compliance framework that will apply to commercial hardware and software sold in the EU. The drafts cover major product categories including network and edge devices, security products, and IoT appliances, and are designed to translate the CRA’s legal requirements into technical controls manufacturers and other suppliers can implement.
The proposed standards call for baseline measures such as modern cryptography, secure-by-default configurations, software bills of materials (SBOMs), and the ability to deliver security updates after sale. The drafts have entered public enquiry through late 2026, with final versions expected by December 2026 ahead of the CRA’s full application in December 2027; the resulting obligations are expected to affect manufacturers, importers, distributors, service providers, and developers placing connected products on the EU market.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
ETSI launched the approval process for 17 key cybersecurity standards tied to the EU Cyber Resilience Act and submitted the drafts to 41 member organizations across Europe. The standards entered the public enquiry phase as the first step of the approval procedure.
On August 13, ETSI made available 17 draft European cybersecurity standards intended to support implementation of the EU Cyber Resilience Act. The drafts cover major product categories such as network and edge devices, security products, and IoT appliances, and define baseline requirements including modern cryptography, secure-by-default settings, SBOMs, and post-sale update capabilities.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceinfosecurity-magazine.com
Open sourceetsi.org
Open sourcedocbox.etsi.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.