ETSI advances cybersecurity standards supporting Cyber Resilience Act – Expert Comments

ETSI (European Telecommunications Standards Institute) has moved 17 cybersecurity standards into the formal approval process as part of Europe’s implementation of the Cyber Resilience Act (CRA).
The standards address specific categories of network and edge devices, security solutions and internet-of-things (IoT) appliances, including routers, operating systems, browsers, password managers, smart home devices and security software, and are designed to translate the CRA’s broader legal obligations into technical requirements manufacturers can follow.
The proposed standards establish baseline security requirements that manufacturers will need to meet for CRA compliance and to sell covered products in the EU beginning in December 2027.

Requirements include modern encryption, secure default configurations, a machine-readable software bill of materials (SBOM) documenting software dependencies, and mechanisms for delivering security updates after products are sold.

Doc McConnell, Head of Policy and Compliance, Finite State:

“The release of final draft standards from ETSI is great news for product manufacturers in these 17 verticals that cover many of the “important” products with digital elements defined in the Cyber Resilience Act. Seeing these documents makes it easier to concretely evaluate existing products to see where they align with the CRA requirements, and where manufacturers will need to do additional work prior to the December 2027 deadline.

“I expect we’ll see manufacturers looking for help in the immediate future to evaluate their existing products to get a baseline of their compliance status, as well as looking for partners who can help them engineer future products in ways that are CRA-compliant before they ever hit the market.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“The CRA’s Article 14 vulnerability reporting obligation starts September 11. Manufacturers will have 24 hours to submit an early warning for actively exploited vulnerabilities. Meeting that window in practice means knowing what components ship in every product, which versions are affected, and who owns remediation. I’ve watched that question consume most of the response time during live incidents, where teams dig through repositories and old release manifests while the clock runs.

“SBOMs built for incident response are produced automatically during builds, tied to specific product versions, retained across releases, and queryable when a new CVE drops. A document generated once for an auditor can’t answer those questions under a 24-hour clock. SBOMs are becoming incident-response infrastructure.

“AI-accelerated vulnerability discovery compounds the pressure. AI systems are already demonstrating the ability to discover previously unknown vulnerabilities in production software. As researchers run vulnerability-discovery agents in parallel, finding potential vulnerabilities can scale faster than the engineering processes required to triage and remediate them. When discovery outpaces your ability to identify affected products, component visibility becomes the bottleneck.

“The 17 ETSI draft standards now entering formal approval begin translating the CRA’s SBOM obligations into technical requirements. They don’t yet carry the presumption of conformity under Article 27, which requires publication in the Official Journal. Treat them as a gap analysis baseline.”

John Strand, Owner, Black Hills Information Security, Inc.:

“In so many ways, it seems like Europe is getting this a little bit faster than we are in the United States. This is exactly the type of guidance and requirements we need for companies building Internet of Things devices, appliances, routers, and all of the other technology that ends up connected to our networks.

“There need to be baseline security requirements built into these products from the very beginning. And hopefully, this continues to expand so manufacturers aren’t just responsible for security when a product ships. They need to maintain responsibility for the security of those devices throughout the lifespan of the product.”

Seemant Sehgal, Founder & CEO, BreachLock:

"Europe is doing something manufacturers have resisted for decades, which is making security a condition of market access. The seventeen standards moving through ETSI are essentially a translation layer, converting a legal obligation into something an engineering team can actually act on. What strikes me about the CRA requirements is how foundational they are.

“Encrypted communications, secure defaults, a documented software bill of materials, a defined path for delivering updates. These are not ambitious asks. They are baseline hygiene that the industry has been slow to standardize because there was no hard deadline and no real consequence for skipping it. December 2027 creates both of these.

“The question manufacturers should be considering now is how much of their existing product architecture was built with the assumption that they never would have to meet specific security requirements."

Articles similaires

Opinion

10 September 2026

Cyberattack encrypts German utility’s IT systems serving critical infrastructure – experts weigh in

A cyberattack that began September 1st has encrypted the central IT systems of Stadtwerke (…)

Opinion

9 September 2026

Are AI agents the next insider threat?

In a new interview published in Axios, Bugcrowd CEO Dave Gerry said that AI agents aren’t just (…)

Opinion

4 September 2026

CISA cuts critical infrastructure security services, concerns grow over the shrinking agency - Expert Comments

CISA is ending six free cybersecurity assessment programs used by critical infrastructure (…)