Cyber Resilience Act
European standard
Legal definition Art. 3(35) CRA
“a European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012”
A European standard is a standard adopted by a European standardisation organisation. The Cyber Resilience Act (CRA) does not define the term in Article 3, point (35), on its own account; it refers instead to Article 2, point (1)(b), of Regulation (EU) No 1025/2012, the European standardisation regulation.
That cross-reference carries more than it looks, because it pulls in the parent definition as well. A standard is a technical specification for repeated or continuous application, adopted by a recognised standardisation body, with which compliance is not compulsory. Being voluntary is therefore not a concession granted in practice; it is part of the legal definition.
Who adopts European standards
European standardisation organisations are not simply any body that publishes specifications. Article 2, point (8), of Regulation (EU) No 1025/2012 means by them the organisations set out in Annex I, and Annex I lists exactly three: CEN, Cenelec and ETSI. Only what one of those three adopts as a standard is a European standard in the sense the CRA uses.
Specifications from consortia, industry associations and vendor alliances fall outside the term, however widely used they may be. They can be technically excellent and can play a part in your files, but they do not carry the label the CRA points to.
Three notions of a standard and how they relate
The CRA works with three notions of a standard. Article 2, point (1), of Regulation (EU) No 1025/2012 lists them as categories of the same definition; only the last two sit inside one another:
- The international standard in Article 3, point (34), is adopted by an international standardisation body, meaning ISO, IEC or ITU.
- The European standard in Article 3, point (35), comes from one of the three European standardisation organisations.
- The harmonised standard in Article 3, point (36), is a European standard adopted on the basis of a Commission request for the application of Union harmonisation legislation.
Every harmonised standard is thus a European standard, and the reverse does not hold. What has to be added is the Commission request for the application of Union harmonisation legislation; that alone makes the standard harmonised. The presumption of conformity does not yet follow from it. Article 27(1) additionally requires the reference to have been published in the Official Journal of the European Union, which the Commission does without delay under Article 10(6) of Regulation (EU) No 1025/2012 once the standard satisfies the requirements it aims to cover.
No harmonisation, no presumption of conformity
This is where the distinction becomes practical. Article 27 attaches the Presumption of conformity to three anchors, and the European standard as such is none of them:
- harmonised standards, or parts of them, whose references have been published in the Official Journal (paragraph 1),
- Common specifications laid down by a Commission implementing act (paragraph 5),
- an EU declaration of conformity or a cybersecurity certificate issued under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881 (paragraph 8).
Applying a European standard without harmonised status therefore buys no relief from the burden of proof. Each individual requirement in Annex I still has to be demonstrated on its own.
Where it counts nonetheless
None of that makes the exercise pointless. Where no harmonised standard, no common specification and no certification scheme has been applied, point 5 of Annex VII calls for a description of the solutions adopted together with a list of other relevant technical specifications applied. That is exactly where a non-harmonised European standard belongs in the Technical documentation.
The EU declaration of conformity has no slot for it. Point 6 of Annex V provides only for references to harmonised standards, common specifications and cybersecurity certification. Entering a non-harmonised standard there suggests a legal effect that does not attach to it.
From standardisation request to legal effect
Article 27(1) sets out how European standardisation work becomes usable ground for the CRA. Under Article 10(1) of Regulation (EU) No 1025/2012 the Commission requests one or more European standardisation organisations to draft harmonised standards for the requirements in Annex I. In doing so it shall strive to take into account existing European and international cybersecurity standards that are in place or under development.
The procedure has deadlines and an emergency exit. Under Article 10(3) of Regulation (EU) No 1025/2012 the organisation receiving the request states, within one month of receipt, whether it accepts. If it declines, if the standard is not delivered on time, or if it does not match the request, and if no reference is expected in the Official Journal within a reasonable period either, the Commission may lay down common specifications under Article 27(2). Recital 85 explains what counts as reasonable there: the period should not exceed one year after the deadline for drafting a European standard.
Recital 83 calls the European standardisation framework the default framework for standards that provide a presumption of conformity. Common specifications are the fallback, not an equivalent second route.
When the standard itself falls short
A harmonised standard remains open to challenge. Where a national measure in the Union safeguard procedure under Article 55 is considered justified and the non-compliance of the product is attributed to shortcomings in the harmonised standards, Article 55(3) has the Commission open the formal objection procedure under Article 11 of Regulation (EU) No 1025/2012. That procedure can decide to maintain the reference in the Official Journal, to maintain it with restriction, or to withdraw it.
The underlying European standard does not disappear when that happens. It loses only the legal effect harmonisation had lent it and reverts to what it was before, a technical specification that anyone may apply voluntarily.
Practical questions
-
It can then carry the presumption of conformity, but only once its reference has been published in the Official Journal of the European Union. Article 27(1) attaches the presumption to exactly the harmonised standard whose reference appears there, so check that this is the edition you apply. The standard then moves, within point 5 of Annex VII, out of the list of other technical specifications and into the list of harmonised standards, and it additionally belongs in the EU declaration of conformity. The technical work survives; only its legal status changes.
-
No, what decides it is the type of document rather than the publisher. Article 2, point (2), of Regulation (EU) No 1025/2012 sets the European standard against the “European standardisation deliverable”: any technical specification other than a European standard that one of those organisations adopts for repeated or continuous application and with which compliance is not compulsory. Whatever a European standardisation organisation does not adopt as a standard therefore falls into that second group. For your files this is no bar, because point 5 of Annex VII expressly admits other relevant technical specifications.
-
No. Under Article 10(6) of Regulation (EU) No 1025/2012 what appears there is the reference to the harmonised standard, not its content. Neither the CRA nor Regulation (EU) No 1025/2012 creates a general right to the text; Article 6 of that Regulation only obliges national standardisation bodies to ease access for SMEs, for instance through free access to draft standards, free abstracts on their websites and special rates for the provision of standards. If you intend to rely on several standards, plan the procurement early.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.