Seventeen: that is the number at the center of a coordinated European effort to translate the Cyber Resilience Act into technical reality for vendors and buyers across the continent.
The 17 draft standards and the product categories they cover
The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 key cybersecurity standards, and the final draft standards, made available on August 13, cover 17 major product categories spanning network and edge devices, security solutions and internet-of-things (IoT) appliances. The drafts are intended to set the baseline technical requirements manufacturers must meet to be compliant with the EU Cyber Resilience Act (CRA) when it takes full effect in December 2027.
Minimum-security features spelled out in the proposals
Several of these proposed standards mandate modern cryptography, secure-by-default settings, a software bill of materials (SBOM) – a machine-readable inventory of software dependencies – and post-sale update capabilities. Collectively, the drafts set out a list of minimum-security features manufacturers must implement to be CRA-compliant, allowing for the sale of their products in the EU from December 2027.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleApproval procedure: 41 member organisations, public enquiry, and the timetable
The draft standards have been submitted to 41 member organisations across Europe, including the national standardisation bodies of the European Economic Area and Europe-wide industry and standards organisations, and are currently under public enquiry as part of the first phase of the approval procedure. Stakeholders are invited to issue comments during this enquiry period; the window for comments runs from mid-September to mid-November 2026 depending on the vertical. ETSI expects the final versions of these 17 cybersecurity standards to be available by December 2026.
Who the standards will apply to from the end of 2027
When the CRA is enforced at the end of 2027, the standards will apply to all manufacturers, importers, distributors, service providers and developers of commercially available hardware and software products sold in the EU. The ETSI drafts are therefore explicitly aimed at shaping the technical obligations that these named categories of actors must meet in order to lawfully commercialise their products inside the EU market after CRA enforcement.
What this means for manufacturers, small and medium businesses, and developers
- Manufacturers: They must plan to implement minimal-security features called out in the drafts — including modern cryptography, secure-by-default configurations, SBOMs and post-sale update mechanisms — if they wish to sell products in the EU from December 2027.
- Small and medium businesses (SMBs): ETSI and the two other EU-approved standardisation bodies have organised outreach to this group; ETSI, together with the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), have organised a series of workshops across Europe to help European small and medium businesses to comply to the CRA when it’s enforced.
- Developers and service providers: The drafts and their public enquiry give these actors a direct opportunity to influence the final language; comments may be submitted during the mid-September to mid-November 2026 window depending on vertical, ahead of the planned December 2026 finalisation.
The pathway ETSI has opened binds a legislative deadline — CRA enforcement in December 2027 — to a standardisation timetable that aims to produce final standards by December 2026 and invites industry comment this autumn. Whether the drafts, as finalised, will be workable for all product types and company sizes will be tested in the coming months during the public enquiry and the workshops organised by ETSI, CEN and CENELEC.
Read the original ETSI announcement: https://www.infosecurity-magazine.com/news/etsi-proposes-17-cybersecurity/




