Harmonised Standards and Presumption of Conformity
Harmonised standards can support CRA conformity only when their references are published in the Official Journal. Draft standards, work items, M/606 planning records, and consultation texts can help engineering work, but they do not create legal presumption by themselves.
Presumption of conformity
Products with digital elements and processes put in place by the manufacturer which are in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I covered by those standards or parts thereof.
Regulation (EU) 2024/2847, Article 27(1)
The last words matter. A standard does not cover the whole Regulation by default. It covers the Annex I requirements named by the published reference, and only for products and processes within its scope.
Harmonised standard
Voluntary technical route. It gives presumption only after its reference is published in the Official Journal.
Common specification
Commission fallback route when the conditions in Article 27(2) are met and the specification covers the requirement.
Certification scheme
A European cybersecurity certificate can support conformity for the requirements covered by the scheme.
M/606 work programme
M/606 is the Commission request to CEN, CENELEC, and ETSI. The Commission standardisation page describes 41 requested standards, split between horizontal standards and vertical, product-specific standards. CEN, CENELEC, and ETSI accepted the request on 3 April 2025.
M/606 entries 1 and 15 cover the first horizontal principle standard and the horizontal vulnerability-handling standard.
M/606 entries 16 to 41 cover important and critical product categories such as browsers, VPN products, operating systems, routers, firewalls, semiconductors, smart home products, wearables, and secure elements.
M/606 entries 2 to 14 cover further horizontal standards for product-security properties such as secure defaults, updates, access control, confidentiality, integrity, availability, attack-surface reduction, monitoring, and data removal.
Horizontal standards
Horizontal standards are meant to be useful across product categories. They set common vocabulary, risk management, product-security, and vulnerability-handling structure. Product-specific standards can then build on them.
A common vocabulary supports the horizontal and product-specific standards. It should not be treated as a product-security control standard by itself.
The current draft explains cyber-resilience principles, risk-based product cybersecurity, and lifecycle activities. It is explained separately in prEN 40000-1-2 Principles for Cyber Resilience.
M/606 asks for generic security requirements and controls for Annex I Part I product properties. Its planned role is explained in prEN 40000-1-4 Public Materials.
The current draft explains vulnerability handling for Annex I Part II. It is explained separately in prEN 40000-1-3 Vulnerability Handling.
The current public 1-2 and 1-3 documents are draft standards. They are useful for planning, but they should not be described as final EN standards or as cited harmonised standards until that status is true.
Product standards reference
Product-specific standards are now tracked in Product Standards by Category. That page maps Annex III and Annex IV categories to candidate work items and records the source status checked for the mapping.
Using standards without overclaiming
A product can use standards before citation as engineering evidence, but that is different from legal presumption of conformity. The technical documentation should show which requirements are covered by cited standards, common specifications, certification schemes, or other technical solutions.
The horizontal draft pages are explained separately: prEN 40000-1-2 Principles for Cyber Resilience and prEN 40000-1-3 Vulnerability Handling.