The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 key cybersecurity standards that vendors will need to meet in order to comply with the EU Cyber Resilience Act (CRA). The move marks a significant step in preparations for December 2027, when full CRA compliance becomes mandatory across the EU and for all organisations selling products into the bloc.

What is the EU Cyber Resilience Act?

The Cyber Resilience Act is the EU's landmark legislation establishing binding cybersecurity requirements for hardware and software products placed on the European market. It moves beyond voluntary guidance to make cybersecurity a legal condition of market access — applying to manufacturers, importers, distributors, service providers, and developers of any commercially available product sold in the EU, regardless of where those organisations are based.

Full compliance is required from the end of 2027, giving the industry a defined runway to meet the new requirements.

What do the 17 new standards cover?

The 17 standards being developed through ETSI's approval process will translate the CRA's legal obligations into concrete technical requirements. As Sandra Feliciano, Chair of the group responsible for the CRA, explains: "The Cyber Resilience Act lays down what manufacturers, and the market need to achieve, but it does not tell you how. The role of the Standards Developing Organisations is to detail the technical aspects of how to achieve compliance with the legislation through standards."

ETSI is one of only three bodies officially recognised by the European Union as a European Standards Organisation (ESO). It is an independent, not-for-profit organisation dedicated to ICT standardisation, with over 900 member organisations from more than 60 countries across five continents.

Who does the CRA apply to?

The CRA's reach is deliberately broad. It applies not only to European companies but to any manufacturer, importer, distributor, service provider or developer of commercially available hardware or software products sold in the EU — wherever they are based. This gives the legislation a significant extraterritorial dimension: a US software vendor, an Asian hardware manufacturer, or a global cloud provider all fall within scope if they sell into EU markets.

The EU's growing regulatory framework for digital security

The CRA sits within a rapidly expanding body of EU digital regulation. Alongside it, the EU AI Act — adopted in May 2024 and entering into force on 1 August 2024 — establishes harmonised rules for AI systems across most sectors, with phased compliance obligations extending through 2030. The AI Act defines an AI system as:

"a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."

The definition is intentionally wide, capturing a broad range of systems that organisations may not immediately recognise as falling under AI regulation. Exemptions exist for military use, national security, research, and non-professional AI applications.

Global implications of EU regulation

Like the EU's General Data Protection Regulation (GDPR) before it, both the CRA and the AI Act carry global significance. Because the rules apply to any organisation supplying goods or services to EU member states, non-European companies face the same compliance requirements as European ones. Organisations that choose to remain in EU markets will need to invest in meeting these standards — or risk being locked out of one of the world's largest trading blocs.

For technology vendors worldwide, the message is clear: the window to prepare is open, and December 2027 is approaching fast.