STANDARDS DRIFT

Analysis

The first CRA standards deadline has passed

On 30 August 2026 the first deadline in the Cyber Resilience Act's standardisation request fell due. This is what the official record showed that day.

The Commission issued standardisation request C(2025)618 on 3 February 2025. It asks the European Standardisation Organisations for 41 standards in support of Regulation (EU) 2024/2847, the Cyber Resilience Act. The annex to that request sets deadlines under the heading "Deadline for the adoption by the ESOs". Two items carry the earliest date, and that date was 30 August 2026: 573 days after the request was issued, and 628 days after the regulation entered into force.

No harmonised standard has been cited in the Official Journal for the Cyber Resilience Act. The Commission's index of harmonised standards, which lists every instrument that has one, carries no entry for Regulation (EU) 2024/2847 at all. That has been true since the regulation entered into force on 10 December 2024, and it was still true on the day the first deadline passed.

That is the claim worth stating precisely, because it is the one that does legal work. Adoption by a standardisation organisation and citation in the Official Journal are two different steps. A standard can be adopted and still confer no presumption of conformity until the Commission has assessed it and cited it. We report the citation, because that is the step a manufacturer can rely on, and because it is the step that is publicly verifiable on the Commission's own pages.

The deadline has not been moved

A draft amendment to the standardisation request circulated in July 2026. It proposed pushing the horizontal deadline to 31 October 2026 and the product-specific ones to 31 December 2026.

It has not been adopted. Not rejected, not withdrawn: simply not adopted. The Commission's own CRA standardisation page, last updated on 31 July 2026, still describes the request as issued, with no amendment and no revised dates anywhere on it.

Standardisation requests are not published in the Official Journal at all, so there is no public register entry to check a draft against. Until an amendment is adopted, the dates in C(2025)618 are the dates that stand. That is why our status page reads "first adoption deadline 30 August 2026, unchanged on the official record" rather than reporting a date that exists only in a draft.

There is also no delivery counter. The Commission publishes no dashboard, no progress table and no count of how many of the 41 have been delivered. The implementation factpage lists "first standardisation deliverables" as an expected Q3 2026 item and nothing more precise. Anyone who tells you how many are ready is not reading it off an official source, because there is not one.

What ETSI's own timetable says about the next deadline

On 13 August 2026, ETSI opened the public enquiry stage on 17 final draft European Standards supporting the Cyber Resilience Act, covering products including password managers, antivirus software, smart home assistants, connected toys, wearables and VPNs.

Public enquiry is the stage at which a draft is opened for comment. It comes before approval, before adoption, and a long way before citation. In ETSI's own words the approval procedure "will run until mid-September to mid-November 2026, depending on the vertical".

The adoption deadline for those product-specific items is 30 October 2026.

A draft still taking comments in November was not adopted in October. That is not a forecast about whether the deadline will be met. It is arithmetic on two sets of published dates, one from the Commission's annex and one from ETSI's own announcement.

What happens in twelve days

On 11 September 2026, twelve days after this first deadline passed, the incident reporting obligations in Article 14 of the Cyber Resilience Act begin to apply.

Those obligations do not wait for standards. A harmonised standard gives a manufacturer a presumption of conformity: a defined, defensible route to demonstrating compliance. Without one, the obligation still applies and the route is left to each manufacturer to construct and defend on its own.

The count of harmonised standards cited for the Cyber Resilience Act is zero. It was zero when the regulation entered into force, it was zero on the day the first standardisation deadline passed, and nothing on the official record has changed it.

We keep the dates. When they move, the old ones stay here.