Cyber Resilience Act

International standard

Legal definition Art. 3(34) CRA

“an international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012”
Regulation (EU) 2024/2847, Art. 3(34) CRA

An international standard is not a definition the Cyber Resilience Act (CRA) writes itself. Article 3, point (34), takes the term from Article 2, point (1)(a), of Regulation (EU) No 1025/2012 on European standardisation.

What stands there is a single clause: a standard adopted by an international standardisation body. The frame comes from the opening words of the same point. A standard is a technical specification, adopted by a recognised standardisation body, for repeated or continuous application, with which compliance is not compulsory.

Three bodies, and no others

Who qualifies as an international standardisation body is settled exhaustively in Article 2, point (9), of that same regulation: the International Organisation for Standardisation (ISO), the International Electrotechnical Commission (IEC) and the International Telecommunication Union (ITU). There are no criteria against which further bodies could be measured, only this list.

That has an awkward practical consequence. Widely used specifications from industry consortia and trade associations are not international standards for CRA purposes, however respected they may be technically. You may still apply them; the term simply does not cover them.

The two neighbouring terms come from the same Article 2, point (1), and the CRA takes both over in Article 3, points (35) and (36): the European standard as a standard adopted by a European standardisation organisation, and the Harmonised standard as a European standard adopted on the basis of a Commission request for the application of Union harmonisation legislation. All three are told apart solely by who adopts them and at whose instigation.

No presumption of conformity

Article 27 attaches the Presumption of conformity to three bases: harmonised standards whose references are published in the Official Journal (paragraph 1), the Commission’s Common specifications (paragraph 5), and European cybersecurity certification schemes adopted under Regulation (EU) 2019/881 (paragraph 8).

International standards appear in none of the three. Applying one therefore saves you nothing in terms of demonstration: for every applicable Annex I requirement, the manufacturer still has to show how it is met.

Where the CRA does draw on them

In several places the regulation gives international standards a role, without any presumption of conformity hanging on it:

  • Under Article 27(1), the Commission strives to take existing European and international cybersecurity standards into account when preparing standardisation requests, whether those standards are already in place or under development.
  • Under Article 13(24), the Commission may specify the format and elements of the software bill of materials by implementing act, taking European or international standards and best practices into account.
  • The recitals record that international standards in line with the level of cybersecurity protection sought by the essential requirements should also be taken into account. One stated aim is to make compliance easier for microenterprises, small and medium-sized enterprises and companies operating globally.

A further recital expects manufacturers, once they have assessed the cybersecurity risks, to apply suitable harmonised standards, common specifications or European or international standards as appropriate. Recitals do not bind directly, but they show the intended role: a working basis and a template, not a means of proof with legal effect of its own.

Where it belongs in the documentation

Annex VII, point 5, calls for a list of the harmonised standards whose references have been published in the Official Journal of the European Union, the common specifications and the certification schemes applied in full or in part. Where none of those instruments was applied, their place is taken by descriptions of the solutions adopted to meet the requirements in Parts I and II of Annex I, together with a list of other relevant technical specifications applied.

That is exactly where an international standard sits in the Technical documentation. The difference becomes tangible at this point: with a harmonised standard, citing the reference is enough. With an international standard, describing the chosen solution remains the real work, and the standard backs it up.

Consequences for the assessment route

For an important product with digital elements in class I under Annex III, the question gets expensive. Article 32(2) mandates one of the routes involving a notified body where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least “substantial”, or where none of those exist. The choice is then EU-type examination under module B followed by module C, or full quality assurance under module H. However well an international standard fits, it changes nothing here.

For products listed in neither Annex III nor Annex IV, the internal control procedure under module A remains open by virtue of Article 32(1). There an international standard is a sound anchor, because the assessment rests with the manufacturer in any case and everything turns on documenting it traceably.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.