Overview
On August 13, 2026, the European Telecommunications Standards Institute (ETSI) released 17 draft cybersecurity standards. These cover a range of products from operating systems to internet-connected toys and form the technical foundation of the EU Cyber Resilience Act, which takes full effect in December 2027. The standards require features like modern cryptography, secure-by-default settings, software bills of materials (SBOM), and post-sale update capabilities.
The issue is timing. ETSI submitted these drafts to 41 member organizations for public inquiry, with comment periods closing between mid-September and mid-November 2026. The final versions won't be published until December 2026, leaving manufacturers, importers, distributors, and service providers just twelve months to implement technical requirements that affect product architecture, development workflows, and supply chain transparency.
This isn't a vendor issue; it's a structural failure in regulatory timing that will likely lead to numerous incidents starting in January 2028.
Timeline
August 13, 2026: ETSI publishes 17 draft standards for public inquiry
Mid-September to mid-November 2026: Comment periods close by product vertical
December 2026: Final standards expected to publish
December 2027: EU Cyber Resilience Act takes full effect
January 2028 and beyond: Non-compliant products blocked from EU market
The gap is significant because these are engineering requirements, not just documentation standards. Implementing cryptographic libraries, SBOM generation pipelines, and secure-by-default configurations takes months, not weeks.
Key Failures
Inadequate lead time for technical implementation
The regulatory design assumes vendors can implement architectural changes in twelve months. Real product development cycles for affected categories like routers, firewalls, and VPNs typically run 18 to 36 months from requirements freeze to general availability.
No phased enforcement mechanism
The Cyber Resilience Act treats all products equally, requiring full compliance by December 2027. There's no classification to prioritize high-risk categories or grace periods for lower-risk products.
Lack of pre-standard guidance
ETSI organized workshops for small and medium businesses but didn't publish interim technical guidance before the draft standards. Vendors who waited for official requirements now face a compressed timeline with no fallback.
Insufficient Supply Chain Illumination requirements
The SBOM mandate is correct, but the standards don't specify how deep the dependency tree must go or how often it must update. Gaps in Fourth and Nth Party Management will persist even after compliance.
What the Standards Require
The EU Cyber Resilience Act doesn't specify technical requirements directly. It delegates that authority to harmonized standards bodies like ETSI, CEN, and CENELEC. Compliance with the published ETSI standards creates a "presumption of conformity" with the CRA's essential requirements.
The 17 proposed standards cover distinct product categories but share common mandates:
Modern cryptography: Products must use current cryptographic algorithms and key lengths. Legacy cipher suites like TLS 1.0 and SHA-1 signatures won't meet the requirements.
Secure-by-default settings: Out-of-box configurations must disable unnecessary services, enforce authentication, and require explicit user action to weaken security posture.
Software bill of materials: Machine-readable inventories of all software dependencies, updated with each release. This affects every vendor's build pipeline and version control system.
Post-sale update capabilities: Products must support security patches after sale. For hardware with long lifecycles, this means architecting remote update mechanisms into devices that historically shipped as appliances.
These standards go beyond ISO 27036, which addresses information security for supplier relationships but doesn't mandate specific product features. The CRA standards are design requirements, not process requirements.
Action Items for Your Team
If you're procuring products for EU operations:
Audit your current vendor roster against the 17 product categories now. Don't wait for December 2026 finals. The categories won't change materially between draft and publication.
Add CRA compliance status as a mandatory field in your vendor intake workflow. Ask vendors for their implementation timeline, not just their intent to comply. A vendor who hasn't started SBOM generation by Q4 2026 won't ship compliant products by December 2027.
Revise your criticality classification criteria to include regulatory compliance risk. A vendor selling non-compliant products into the EU after December 2027 faces enforcement action, posing an availability risk for your operations.
Update your pre-contractual assessment templates to verify post-sale update commitments. Ask how long the vendor will maintain update capabilities and what happens if they discontinue the product line. The CRA requires updates but doesn't specify duration.
Request SBOM access as part of your Right to Right to Audit. The standards mandate that vendors generate SBOMs but don't require they share them with customers. Negotiate access now, before contracts renew.
If you're managing a vendor program:
Map your vendor portfolio to the 17 categories and flag concentration risk. If 40% of your network security stack comes from vendors who haven't published CRA roadmaps, you're exposed to simultaneous substitutability challenges in Q4 2027.
Build a compliance tracking dashboard that monitors vendor progress against the December 2027 deadline. Track three states: compliant, in-progress with credible timeline, and at-risk. Escalate the at-risk vendors to procurement leadership now.
Prepare wind-down plans for vendors who won't meet the deadline. Substitutability assessments take months. Start identifying alternatives for high-risk categories where vendor concentration is high.
The regulatory timeline has failed vendors and their customers, but you can avoid being caught off guard. Act now to ensure your critical security infrastructure will be CRA-compliant and ready for the future.




