Topic
Harmonised standards
The missing piece that decides how easy self-assessment will be.
Under Article 27(1), harmonised standards whose references are published in the Official Journal give a presumption of conformity with the Annex I requirements they cover — but no CRA harmonised standards have been cited as of the facts date, with Commission and ESO work ongoing F-036.
The absence bites hardest for Annex III class I products, which keep the self-assessment route only by applying harmonised standards, common specifications or a European cybersecurity certification scheme in full F-026. Until citation, the harmonised-standards path to that condition is unavailable, which makes the standards pipeline one of the most consequential things to watch in this space F-036.
Verified facts this page relies on
- F-036 No harmonised standards for the CRA have been cited in the Official Journal as of the facts date; the Commission’s standardisation request M/606 covers 41 standards, with the first deliverables expected in Q3 2026. Commission / CEN-CENELEC
- F-026 Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.