Cyber Resilience Act

European standard

Legal definition Art. 3(35) CRA

“a European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012”
Regulation (EU) 2024/2847, Art. 3(35) CRA

A European standard is a standard adopted by a European standardisation organisation. The Cyber Resilience Act (CRA) does not define the term in Article 3, point (35), on its own account; it refers instead to Article 2, point (1)(b), of Regulation (EU) No 1025/2012, the European standardisation regulation.

That cross-reference carries more than it looks, because it pulls in the parent definition as well. A standard is a technical specification for repeated or continuous application, adopted by a recognised standardisation body, with which compliance is not compulsory. Being voluntary is therefore not a concession granted in practice; it is part of the legal definition.

Who adopts European standards

European standardisation organisations are not simply any body that publishes specifications. Article 2, point (8), of Regulation (EU) No 1025/2012 means by them the organisations set out in Annex I, and Annex I lists exactly three: CEN, Cenelec and ETSI. Only what one of those three adopts as a standard is a European standard in the sense the CRA uses.

Specifications from consortia, industry associations and vendor alliances fall outside the term, however widely used they may be. They can be technically excellent and can play a part in your files, but they do not carry the label the CRA points to.

Three notions of a standard and how they relate

The CRA works with three notions of a standard. Article 2, point (1), of Regulation (EU) No 1025/2012 lists them as categories of the same definition; only the last two sit inside one another:

  • The international standard in Article 3, point (34), is adopted by an international standardisation body, meaning ISO, IEC or ITU.
  • The European standard in Article 3, point (35), comes from one of the three European standardisation organisations.
  • The harmonised standard in Article 3, point (36), is a European standard adopted on the basis of a Commission request for the application of Union harmonisation legislation.

Every harmonised standard is thus a European standard, and the reverse does not hold. What has to be added is the Commission request for the application of Union harmonisation legislation; that alone makes the standard harmonised. The presumption of conformity does not yet follow from it. Article 27(1) additionally requires the reference to have been published in the Official Journal of the European Union, which the Commission does without delay under Article 10(6) of Regulation (EU) No 1025/2012 once the standard satisfies the requirements it aims to cover.

No harmonisation, no presumption of conformity

This is where the distinction becomes practical. Article 27 attaches the Presumption of conformity to three anchors, and the European standard as such is none of them:

  • harmonised standards, or parts of them, whose references have been published in the Official Journal (paragraph 1),
  • Common specifications laid down by a Commission implementing act (paragraph 5),
  • an EU declaration of conformity or a cybersecurity certificate issued under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881 (paragraph 8).

Applying a European standard without harmonised status therefore buys no relief from the burden of proof. Each individual requirement in Annex I still has to be demonstrated on its own.

Where it counts nonetheless

None of that makes the exercise pointless. Where no harmonised standard, no common specification and no certification scheme has been applied, point 5 of Annex VII calls for a description of the solutions adopted together with a list of other relevant technical specifications applied. That is exactly where a non-harmonised European standard belongs in the Technical documentation.

The EU declaration of conformity has no slot for it. Point 6 of Annex V provides only for references to harmonised standards, common specifications and cybersecurity certification. Entering a non-harmonised standard there suggests a legal effect that does not attach to it.

From standardisation request to legal effect

Article 27(1) sets out how European standardisation work becomes usable ground for the CRA. Under Article 10(1) of Regulation (EU) No 1025/2012 the Commission requests one or more European standardisation organisations to draft harmonised standards for the requirements in Annex I. In doing so it shall strive to take into account existing European and international cybersecurity standards that are in place or under development.

The procedure has deadlines and an emergency exit. Under Article 10(3) of Regulation (EU) No 1025/2012 the organisation receiving the request states, within one month of receipt, whether it accepts. If it declines, if the standard is not delivered on time, or if it does not match the request, and if no reference is expected in the Official Journal within a reasonable period either, the Commission may lay down common specifications under Article 27(2). Recital 85 explains what counts as reasonable there: the period should not exceed one year after the deadline for drafting a European standard.

Recital 83 calls the European standardisation framework the default framework for standards that provide a presumption of conformity. Common specifications are the fallback, not an equivalent second route.

When the standard itself falls short

A harmonised standard remains open to challenge. Where a national measure in the Union safeguard procedure under Article 55 is considered justified and the non-compliance of the product is attributed to shortcomings in the harmonised standards, Article 55(3) has the Commission open the formal objection procedure under Article 11 of Regulation (EU) No 1025/2012. That procedure can decide to maintain the reference in the Official Journal, to maintain it with restriction, or to withdraw it.

The underlying European standard does not disappear when that happens. It loses only the legal effect harmonisation had lent it and reverts to what it was before, a technical specification that anyone may apply voluntarily.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.