Cyber Resilience Act
Harmonised standard
Legal definition Art. 3(36) CRA
“a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012”
The Cyber Resilience Act (CRA) does not define a harmonised standard itself; it refers to the European standardisation regulation. There, a harmonised standard is a European standard adopted on the basis of a request from the Commission for the application of Union harmonisation legislation.
Three features set it apart from an ordinary standard: it originates from a formal standardisation request, it relates to a specific legal act, and its reference is published in the Official Journal of the EU. Only that publication produces the legal effect.
The presumption of conformity
The practical value sits in Article 27: products that conform to harmonised standards, or parts thereof, whose references have been published in the Official Journal are presumed to be in conformity with the requirements those standards cover.
That reverses the burden. Without a standard you have to set out why your implementation meets a requirement. With one, evidence that you complied with the standard suffices.
Two limits matter: the presumption applies only to the extent the standard covers the requirements. Gaps still need evidence of their own. And it is rebuttable; it is a presumption, not a guarantee.
Where the CRA stands
Harmonised standards for the CRA are still being developed. For manufacturers that means the convenient route is not yet fully available, while the regulation’s deadlines run unchanged.
A two-stage approach works well in this situation. Document how each Annex I requirement is met on its own terms, recording which established standards you took your bearings from. When a suitable harmonised standard appears later, the documentation can be re-based on it rather than started from scratch.
Not the same as certification
Applying a standard is not the same as being certified. Conformity assessment can rest on a standard but remains a separate exercise, one that for most products the manufacturer carries out itself. Third-party certification is required by the CRA only for particular product categories.
Practical questions
-
No. Standards are voluntary. Only the essential cybersecurity requirements in Annex I are binding. Applying a harmonised standard does bring the presumption of conformity, so compliance need not be derived requirement by requirement. Without one, the same demonstration has to be made another way: permissible, but more work.
-
The requirements apply regardless. The presumption is a relief, not a precondition. In the meantime you rely on recognised international standards or European standards without harmonised status, plus your own carefully documented reasoning. What counts is that the assessment can be followed.
-
The presumption reaches only as far as the parts applied and only for the requirements they cover. Applying a standard selectively means demonstrating everything else yourself, and recording precisely which sections were applied and which were not in the technical documentation.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.