STANDARDS DRIFT

Analysis

The CRA countdown is running. The standards are not.

When we started taking daily snapshots of the EU's official standards record earlier this month, the first thing that struck us was how much of the compliance timeline exists only in the present tense. Official pages show today's expected dates. When a date moves, yesterday's date is simply gone.

That would be a curiosity if the dates were stable. They are not, and the money involved is serious.

What lands on 11 September 2026

On 11 September 2026, Article 14 of the Cyber Resilience Act goes live. From that day, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents, starting with an early warning within 24 hours of becoming aware. This is not only about next year's product launches. The Commission's own summary states that the reporting obligations apply to all products with digital elements made available on the Union market, including those already placed on it before 11 December 2027. In plain terms, the deployed fleet is in scope, not just the roadmap.

The penalty tier says how seriously to take it. Under Article 64(2), non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14 is subject to administrative fines of up to 15 million euros or, if the offender is an undertaking, up to 2.5 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. Two lower tiers sit beneath it: 10 million euros or 2 percent under Article 64(3), and 5 million euros or 1 percent under Article 64(4) for supplying incorrect or misleading information to authorities. Reporting failures sit in the same top tier as shipping an insecure product.

So which harmonised standards can manufacturers actually build and test against to show conformity? As of today, none. Not one harmonised standard has been cited in the Official Journal in support of the Cyber Resilience Act.

The standards were requested. They have not arrived.

The standards are coming, in theory on a schedule. In February 2025 the Commission formally requested 41 standards from the European standardisation organisations, with the last of those standards due to be adopted by 30 October 2027. Industry saw the problem immediately. DIGITALEUROPE, whose members include most of the companies this regulation touches, put it in writing as early as May 2024: "13 out of 15 horizontal standards will only be ready after the CRA's application date."

Since then a proposal to move the schedule has appeared. In July 2026 the Commission circulated a draft amendment to the standardisation request that would push the adoption deadlines for the horizontal standards to 31 October 2026 and the product-specific ones to 31 December 2026, two months later than planned. Note the word draft. The amendment has not been adopted, and standardisation requests are not published in the Official Journal at all, so there is no public register entry to check it against. The adopted deadline and the working deadline are currently different dates, and both are quoted in the market as if they were the only one. This confusion, between what has been proposed and what is legally in force, is precisely how planning mistakes happen.

There is now a harder measure than any of this. On 13 August 2026 ETSI opened the public enquiry stage on 17 final draft European Standards supporting the Cyber Resilience Act, covering products including password managers, antivirus software, smart home assistants, connected toys, wearables and VPNs. Public enquiry is the stage at which a draft is opened for comment. It comes before approval, before adoption, and a long way before citation in the Official Journal. The comment windows on those 17 drafts close between mid-September and mid-November 2026. The adoption deadline for the product-specific standards is 30 October 2026. A draft still taking comments in November was not adopted in October. That is not a forecast about whether the deadline will be met. It is arithmetic on two sets of published dates.

The radio equipment sector already ran this experiment

If you want to know how this movie ends, watch the radio equipment sector, which got there first. Cybersecurity requirements under the Radio Equipment Directive needed their own harmonised standards, the EN 18031 series. After months of disputes between the Commission and the standardisation bodies, the standards were finally cited on 30 January 2025 by Implementing Decision (EU) 2025/138, but with restrictions. Among them: where a user can choose not to set a password, the standard's coverage does not deliver the presumption of conformity. Teams that had scheduled certification testing against the full standard discovered that the version that reached the Official Journal did not fully cover them. Try reconstructing that sequence today from official sources. You cannot, unless you kept your own dated copies.

That is the quiet operational problem underneath all of this. A regulatory affairs lead has to tell engineering when to book notified body slots, which are reserved months ahead. Book too early against a moving draft and you pay for retesting. Book too late and you miss your launch window. The decision depends on dates that change without an archive, on pages that only show the present tense. Even the AI assistants that teams increasingly ask for regulatory timelines are trained on last year's pages, and confidently repeat superseded dates.

Machinery is next in the queue. Regulation 2023/1230 becomes mandatory on 20 January 2027, bringing cybersecurity requirements into machinery law for the first time, and its harmonised standards list is a living document that has been amended six times since 2023. The AI Act's dates moved wholesale this summer, when the July omnibus regulation shifted the high-risk obligations to December 2027 and August 2028. Every one of these moves rewrites someone's product plan.

What we are doing about it

So we started keeping the receipts. Since 7 August 2026, when the collector first ran, an automated archive has been taking a dated snapshot of every public official source that says when a European harmonised standard is due: the Commission's harmonised standards lists, the standardisation request documents, the implementing decisions on EUR-Lex. Every change is stored as a diff with its date and its source. Our first capture alone found 534 standard references in the text of Implementing Decision (EU) 2023/1586 on EUR-Lex, as published that day. That is a count of one document. The larger figure we publish as standards under watch counts the Commission's summary lists, which are a different and fuller source, so the two numbers are not the same measurement and should not be read against each other. From now on, when a date moves, the old date does not vanish. It becomes part of the record.

None of this is legal advice, and it does not tell anyone what to build. It is the dated evidence of what the official record said, and when it changed. In a regime where the reporting clock starts in weeks, the application date is fixed, and the standards underneath it are still moving, the sequence of dates is not trivia. It is the planning input.

If that record would be useful to your team, the weekly changelog of what moved is free. the weekly changelog