Cyber Resilience Act
Common specifications
Practical term
Common specifications are technical requirements that the European Commission lays down itself, so that manufacturers can meet the essential cybersecurity requirements of the Cyber Resilience Act (CRA). The legal basis sits in Article 27(2): the Commission may adopt implementing acts establishing such specifications.
What separates them from a harmonised standard is authorship and legal form. A standard is drafted by a European standardisation organisation, and what the Official Journal carries under Article 27(1) is only its reference. A common specification is adopted by the Commission itself as an implementing act, under the examination procedure in Article 62(2), in which the committee referred to in Article 62(1) takes part.
The fallback route, not the default one
Article 27(1) obliges the Commission to request one or more European standardisation organisations to draft harmonised standards for the Annex I requirements. That is the intended path. It may turn to a common specification only where two conditions are met together:
- the standardisation request under Article 10(1) of Regulation (EU) No 1025/2012 has failed, because it was not accepted, because the standards were not delivered within the deadline, or because they do not comply with the request;
- no suitable reference has been published in the Official Journal, and no such reference is expected to be published within a reasonable period.
Recital 83 stresses how exceptional this is meant to be: it describes a fall-back solution for exceptional cases and says the Commission should consider first whether a delay simply reflects the technical complexity of the standard in question. Recital 85 puts a figure on the reasonable period in the second condition: it should not exceed one year after the deadline set for drafting the European standard. Before preparing a draft, the Commission must also inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it regards the conditions as fulfilled (Article 27(3)).
What the presumption delivers
Article 27(5) attaches the same legal effect to conformity with a common specification as to conformity with a standard: the presumption of conformity. It reaches exactly as far as the specification, or the part of it applied, covers the essential cybersecurity requirements in Annex I. What it covers is not only the product but also the processes put in place by the manufacturer.
Everything beyond that stays with the manufacturer. Where none of these bases is applied, Annex VII, point 5 requires the technical documentation to describe the solutions adopted to meet the requirements in Parts I and II of Annex I instead, and to list the other technical specifications relied on.
Why the assessment route can turn on this
For an important product in class I under Annex III the question carries immediate cost. Under Article 32(2) the manufacturer must take a route involving a notified body (modules B and C, or module H) where it has not applied, or has applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least “substantial”, and equally where no such basis exists. Where it applies them in full, the procedures of Article 32(1) remain open, among them the internal control procedure based on module A under point (a).
The notified body checks against the same basis. Where it finds that the requirements in Annex I, or in the corresponding harmonised standards or common specifications, have not been met, it must require corrective measures and withhold the certificate (Article 47(4)).
Designed to expire
A common specification is a placeholder. Once a harmonised standard has been adopted and its reference published in the Official Journal, Article 27(6) requires the Commission to repeal the implementing act, or at least those parts of it covering the same essential cybersecurity requirements as that standard.
For the product file that creates an unfamiliar situation: the basis you rely on can fall away during the market phase without anything having changed in the product itself.
When the specification itself is the defect
The CRA anticipates that a common specification may fall short. Where a Market surveillance authority notifies the Commission and the other Member States of a provisional measure, Article 54(6) requires it to state whether the non-compliance has one or more of two causes: the product or the manufacturer’s processes fail the Annex I requirements (point (a)), or there are shortcomings in the harmonised standards, European cybersecurity certification schemes or common specifications referred to in Article 27 (point (b)). Where the national measure proves justified on the second ground, Article 55(5) has the Commission consider whether to amend or repeal the implementing act.
For your own planning the reference point therefore stays the harmonised standard. Whether the Commission uses Article 27(2) at all, and for which requirements, will be decided by whether standardisation delivers in time. A compliance strategy that waits for a common specification not yet adopted only defers the risk.
Practical questions
-
Yes. The presumption of conformity is not granted for the product as a whole but for the requirements each basis covers. You can therefore rely on a standard for part of Annex I, on a common specification for another part, and derive the rest yourself. Annex VII, point 5 does require the technical documentation to list what was applied in full and what only in part, and in the latter case to identify the parts concerned.
-
Repeal under Article 27(6) follows once the reference to a harmonised standard covering the same essential cybersecurity requirements is published in the Official Journal, and the CRA provides no transition period for it. For ongoing series production, Article 13(14) expressly requires manufacturers to take account of changes to the standards and specifications their conformity rests on. The EU declaration of conformity names that basis under Annex V, point 6, and Article 28(2) requires the declaration to be updated as necessary. In practice: re-base before the next batch goes out.
-
Not as a member of a standardisation body, because the Commission drafts the text itself. Article 27(4) does oblige it to take account of the views of relevant bodies and to duly consult all relevant stakeholders. No individual right of objection follows from that. Against a specification already in force the route runs through your own Member State: where it considers the specification does not entirely satisfy Annex I, Article 27(7) has it inform the Commission by submitting a detailed explanation. The Commission assesses that explanation and may amend the implementing act as a result.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.