{"id":6240,"date":"2026-09-21T08:57:29","date_gmt":"2026-09-21T05:57:29","guid":{"rendered":"https:\/\/aesinn.com\/test-ve-olcum-hizmetleri\/ab-siber-dayaniklilik-yasasi-cra-uyumlastirilmis-standartlar-ve-uyum-yolu\/"},"modified":"2026-09-21T10:09:42","modified_gmt":"2026-09-21T07:09:42","slug":"ab-siber-dayaniklilik-yasasi-cra-uyumlastirilmis-standartlar-ve-uyum-yolu","status":"publish","type":"page","link":"https:\/\/aesinn.com\/en\/test-ve-olcum-hizmetleri\/ab-siber-dayaniklilik-yasasi-cra-uyumlastirilmis-standartlar-ve-uyum-yolu\/","title":{"rendered":"EU Cyber Resilience Act (CRA): Harmonized Standards and Compliance Pathway"},"content":{"rendered":"<h2 class=\"wp-block-heading\">What is CRA and why is the standards base important?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EU Cyber Resilience Act (EU) 2024\/2847 is a European Union regulation that introduces horizontal cybersecurity requirements for products with digital elements; it entered into force on 10 December 2024. The general scope of the regulation, its core requirements, and its impact on access to the market are covered in a separate introductory article. This content focuses on a different aspect: the standards by which compliance is demonstrated in practice, i.e., the standards base of the CRA and the compliance pathway based on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In CRA, core cybersecurity requirements are defined as abstract principles in Annex I. A manufacturer needs harmonized standards to translate these principles into concrete engineering practice. Full implementation of a harmonized standard provides a presumption of compliance with the relevant core requirements; that is, the manufacturer can demonstrate compliance through this standard. Therefore, the maturity of the standards base directly determines how predictable the compliance path will be.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Reference: EU Cyber Resilience Act, Regulation (EU) 2024\/2847<\/li>\n\n\n<li>Effective date: December 10, 2024<\/li>\n\n\n<li>Essential requirements: Annex I<\/li>\n\n\n<li>Conformity tool: presumption of conformity through harmonized standards<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Timeline: critical dates for compliance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CRA obligations are implemented in stages. The manufacturer needs to structure its standard preparation and compliance plan according to this timeline. Two main stages stand out: vulnerability and incident reporting obligations, and full implementation of core requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Notification obligations (Article 14) came into effect on 11 September 2026. From this date, when a manufacturer becomes aware of an actively exploited vulnerability, they are obliged to submit an early warning within 24 hours, a more detailed notification within 72 hours, and a final report no later than 14 days after the corrective measure is published. The remaining main obligations of the regulation, in particular full compliance with the essential requirements of Annex I and conformity assessment, are expected to come into effect on 11 December 2027.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This content is for informational purposes only, and the official calendar and article texts should be verified with current publications of the European Union; dates and technical details are subject to update over time.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>September 11, 2026: Vulnerability and incident reporting obligations (Article 14) have begun.<\/li>\n\n\n<li>Notification schedule: 24-hour early warning, 72-hour notification, 14-day final report.<\/li>\n\n\n<li>December 11, 2027: Full implementation of Annex I essential requirements and conformity assessment (expected)<\/li>\n\n\n<li>Preparation window: standard and technical file work must be completed before this date.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Standard baseline: Status of CRA harmonized standards 2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CRA&#039;s own harmonized standards are developed by the European standardization bodies CEN, CENELEC, and ETSI. To this end, the European Commission has published a standardization mandate, requesting the organizations to prepare a set of standards that will meet the CRA&#039;s essential requirements. This set is planned to consist of horizontal (general, applicable to all products) and vertical (specific, to particular product categories) standards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of 2026, most of these standards are still in draft or public review phase and have not yet been referenced in the Official Journal of the European Union. Some of the vertical ETSI drafts have been opened for public comment, while horizontal standards continue to be developed within CEN-CENELEC. In mid-2026, the Commission published a draft regulation that somewhat pushed back the deadlines for standardization requests. The practical implication of this is that manufacturers must begin preparations before the final set of harmonized standards is finalized, and a bridging strategy based on existing relevant standards is a reasonable approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Until harmonized standards are published in the Official Gazette with reference, their full implementation does not automatically create a presumption of compliance for CRA purposes; therefore, it is necessary to monitor the current publication status from official sources. A standard status that cannot be verified is not presented as definitive in this content, but is indicated as being in a development phase.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Harmonized standards are developed by CEN, CENELEC, and ETSI.<\/li>\n\n\n<li>The commission&#039;s standardization request includes both horizontal and vertical standards.<\/li>\n\n\n<li>Status 2026: most standards are in draft or public review phase, no reference to them in the Official Gazette yet.<\/li>\n\n\n<li>Delivery dates have been shifted back slightly to mid-2026.<\/li>\n\n\n<li>Bridge strategy: early preparation with existing relevant standards<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Related standards: EN 18031, ETSI EN 303 645 and ISO\/IEC 27001<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While the CRA&#039;s own harmonized standards are maturing, some existing standards offer manufacturers a concrete basis for preparation. Foremost among these is the EN 18031 series. EN 18031-1, EN 18031-2, and EN 18031-3 are harmonized standards for cybersecurity requirements under the Radio Equipment Directive (RED, 2014\/53). These requirements were introduced by Delegated Regulation (EU) 2022\/30 and will apply to internet-connected radio equipment as of August 1, 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is an important distinction here: the EN 18031 series is not CRA&#039;s harmonized standard; it is for RED. However, because the topics it covers\u2014for example, network security, authentication, secure updates, and data protection\u2014largely overlap with CRA&#039;s core requirements, it serves as a practical foundation and bridge. A manufacturer who has worked with EN 18031 under RED will be better prepared for the transition to CRA&#039;s own harmonized standards. In contrast, CRA&#039;s own harmonized standards are being developed in a separate process, and these two approaches should not be confused.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For consumer Internet of Things (IoT) products, ETSI EN 303 645 is a widely used reference for basic cybersecurity provisions and translates many safe default principles into practical requirements. On the process side, ISO\/IEC 27001 covers the manufacturer&#039;s information security management system, not the product itself; it helps to implement CRA process obligations such as vulnerability management and coordinated disclosure at the corporate level. For industrial automation and operational technology environments, the IEC 62443 series is a relevant reference; this series is discussed in a separate section and is only mentioned here as a reference.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>EN 18031-1 \/ -2 \/ -3: RED (2014\/53) harmonized standards for cybersecurity will be effective from 1 August 2025.<\/li>\n\n\n<li>EN 18031 is not a CRA standard, but it forms a bridge and foundation to CRA.<\/li>\n\n\n<li>ETSI EN 303 645: Consumer Internet of Things Cybersecurity Reference<\/li>\n\n\n<li>ISO\/IEC 27001: Manufacturer&#039;s Information Security Management System, Process Side<\/li>\n\n\n<li>IEC 62443: separate reference for industrial automation and operational technology (in separate content)<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Conformity assessment method: importance classes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA categorizes products into risk levels, and each level determines how independently proof of conformity is required. The level does not change which essential requirements the product must meet; all levels must meet the same Annex I requirements. The level only changes how conformity is proven, i.e., whether self-assessment or third-party involvement is required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vast majority of ordinary products demonstrate compliance through self-declaration, i.e., self-assessment based on internal controls (Module A); the technical file and EU declaration of conformity are still mandatory. Important products are divided into Class I and Class II under Annex III. Class I products can continue self-assessment if they fully implement the relevant harmonized standard; third-party involvement is required if the standard is not fully implemented. Class II products, in all cases, require third-party conformity assessment by a notified body. Critical products are covered under Annex IV, and the use of a notified body or a relevant EU cybersecurity certification scheme may be mandatory for these.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This table also explains why the standards base is so important: especially for Class I products, the fact that the harmonized standard is published and fully applicable directly distinguishes between third-party requirements and self-assessment.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Standard products: self-assessment (Module A), technical file and EU declaration of conformity are mandatory.<\/li>\n\n\n<li>Important Class I (Annex III): Self-assessment is possible if the harmonized standard is fully implemented.<\/li>\n\n\n<li>Major Class II (Annex III): third-party assessment by a notified body in all cases.<\/li>\n\n\n<li>Critical (Annex IV): Notified body or EU cybersecurity certification scheme may be mandatory.<\/li>\n\n\n<li>All levels meet the same Annex I essential requirements.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">CRA basic cybersecurity requirements (Appendix I)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Appendix I conceptually defines the core cybersecurity principles that a product must meet and the vulnerability management processes that a manufacturer must maintain. Harmonized standards and related bridging standards translate these principles into measurable engineering requirements. The following headings are the main axes that a manufacturer will follow when performing standards matching.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Deliver with a secure default configuration and disable unnecessary open services.<\/li>\n\n\n<li>Vulnerability management: the process of detection, prioritization, and remediation.<\/li>\n\n\n<li>Update and patch mechanism: secure and automatic updates whenever possible.<\/li>\n\n\n<li>Data protection: confidentiality and integrity during transmission and storage.<\/li>\n\n\n<li>Reducing the attack surface and limiting the impact of incidents.<\/li>\n\n\n<li>Software Materials Account (SBOM) for component and dependency transparency.<\/li>\n\n\n<li>Coordinated vulnerability disclosure policy and communication channel.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The path to adaptation for Turkish exporters.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Turkish manufacturers offering products with digital elements to the European Union market are also covered by CRA. A practical preparation approach begins with determining the product&#039;s importance class: is the product ordinary, important under Annex III, or critical under Annex IV? This classification distinguishes the self-assessment and notified body approach, and thus determines the project timeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second step is standard matching: mapping which existing standards (e.g., EN 18031 series or ETSI EN 303 645, where applicable) and future CRA harmonized standards the product will meet the Annex I requirements. The third step is establishing the disclosure processes coordinated with the technical file, EU declaration of conformity and vulnerability management. Since Article 14 notification obligations are already in place, the active exploit and serious incident reporting mechanism is expected to be operational from 11 September 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the standards base is still maturing, a robust approach is to work early with existing bridging standards and plan the transition by monitoring the final CRA harmonized standards through Official Gazette publications. Reliance on official texts is essential for a product-specific interpretation of scope and obligations from a legal and technical perspective.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Step 1: Determine the importance class of the product (ordinary, important Annex III, critical Annex IV)<\/li>\n\n\n<li>Step 2: Align Annex I requirements with current and future standards.<\/li>\n\n\n<li>Step 3: Establish the technical file, EU declaration of conformity, and vulnerability management.<\/li>\n\n\n<li>Step 4: Keep the Article 14 notification mechanism operational.<\/li>\n\n\n<li>Bridge strategy: early preparation with existing standards, follow official publications.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Information and scope of AES<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This content is for informational purposes only and does not substitute for legal or conformity assessment advice. CRA is a rapidly evolving regulatory field; decisions should be based on official European Union sources, as the publication status, clause numbers, and dates of standards may change over time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">AES is not a notified body or certification body; it does not issue CE certificates, cybersecurity conformity assessments, or certificates under the CRA. CRA conformity assessments (for Class II and critical products) fall under the purview of authorized notified bodies and the relevant EU cybersecurity certification schemes. AES&#039;s T\u00dcRKAK accreditation is limited solely to the 6.1 Electrical Installation field.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Authorized engineers can provide technical assessments on matters within the scope of electrical installation inspections; however, cybersecurity and CRA compliance are outside the scope of this accreditation, and this content has been prepared to clearly state this distinction.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>This content is for informational purposes only and does not constitute advice.<\/li>\n\n\n<li>AES is not an approved body or certification body.<\/li>\n\n\n<li>CE certificates or cybersecurity certificates are not issued under the CRA program.<\/li>\n\n\n<li>AES accreditation is limited to the 6.1 Electrical Installation field only.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Related Services<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><a href=\"https:\/\/aesinn.com\/en\/test-ve-olcum-hizmetleri\/iec-62443-endustriyel-otomasyon-ve-kontrol-sistemleri-ot-ics-siber-guvenligi-bilgilendirme-rehberi\/\">IEC 62443 Industrial (OT\/ICS) Cybersecurity Guidance<\/a><\/li>\n\n\n<li><a href=\"https:\/\/aesinn.com\/en\/ab-siber-dayaniklilik-yasasi-cra-dijital-urunlerde-yeni-siber-guvenlik-donemi\/\">EU Cyber Resilience Act (CRA): A New Era of Cybersecurity in Digital Products<\/a><\/li>\n\n\n<li><a href=\"https:\/\/aesinn.com\/en\/muayene-periyodik-kontrol\/mekanik-ekipman-muayeneleri\/makine-ce-uygunlugu-risk-degerlendirmesi-ve-teknik-dosya-danismanligi\/\">Machine CE Conformity, Risk Assessment and Technical File Consulting<\/a><\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Has the CRA published its own harmonized standards?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As of 2026, most of the harmonized standards of the CRA are still in draft or public review phase and have not yet been published in the Official Journal of the European Union. These standards are being developed by CEN, CENELEC and ETSI, and the current status should be monitored from official sources.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is the EN 18031 series a CRA standard?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. EN 18031-1, -2 and -3 are harmonized standards for the Radio Equipment Directive (RED) and will be in effect as of 1 August 2025. The CRA&#039;s own harmonized standards are being developed separately; however, EN 18031 provides a practical bridge and foundation as the topics it covers overlap with CRA requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When do CRA obligations begin to apply?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerability and incident reporting obligations (Article 14) came into effect on September 11, 2026. Full implementation of the essential requirements of Annex I and conformity assessment is expected on December 11, 2027. The regulation entered into force on December 10, 2024.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need a third-party review for my product?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This depends on the product&#039;s priority class. Ordinary products can perform self-assessment. Critical Class I products can continue self-assessment if they fully implement the relevant harmonized standard. Critical Class II products require a notified body in all cases. For critical products, a notified body or the EU cybersecurity certification scheme may be mandatory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is a Software Materials List (SBOM) mandatory?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA core requirements (Annex I) include maintaining a Software Materials List (SBOM) that provides transparency of software components and their dependencies. This is a fundamental tool for vulnerability management and rapid identification of affected components and should be addressed along with a full implementation schedule for the core requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can AES issue certificates or CE certifications under the CRA program?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. AES is not an approved body or certification body and does not issue CE certificates, cybersecurity conformity assessments, or certificates under the CRA. AES&#039;s T\u00dcRKAK accreditation is limited only to the 6.1 Electrical Installation field. This content is for informational purposes only.<\/p>","protected":false},"excerpt":{"rendered":"<p>AB Siber Dayan\u0131kl\u0131l\u0131k Yasas\u0131 (CRA) kapsam\u0131nda hangi standartlarla uyum sa\u011flanaca\u011f\u0131, uyumla\u015ft\u0131r\u0131lm\u0131\u015f standartlar\u0131n g\u00fcncel durumu, \u00fcr\u00fcn \u00f6nem s\u0131n\u0131flar\u0131 ve uygunluk de\u011ferlendirme yolu.<\/p>","protected":false},"author":1,"featured_media":6241,"parent":2518,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_kad_blocks_custom_css":".transparent-header.content-title-style-hide .content-area{padding-top:140px;}@media (max-width:767px){.transparent-header.content-title-style-hide .content-area{padding-top:90px;}}","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","slim_seo":{"title":"CRA Harmonized Standards and Compliance Pathway","description":"EU Cyber Resilience Act (CRA) standards database, status of harmonized standards 2026, severity classes and compliance pathway guidance."},"_pplb_hide_from_list":false,"footnotes":""},"class_list":["post-6240","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"taxonomy_info":[],"featured_image_src_large":["https:\/\/aesinn.com\/wp-content\/uploads\/cra_standards-aes-kart-1024x1024.png",1024,1024,true],"author_info":{"display_name":"Emre Metin","author_link":"https:\/\/aesinn.com\/en\/author\/yonetim\/"},"comment_info":"","_hostinger_reach_plugin_has_subscription_block":false,"_hostinger_reach_plugin_is_elementor":false,"_links":{"self":[{"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/pages\/6240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/comments?post=6240"}],"version-history":[{"count":2,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/pages\/6240\/revisions"}],"predecessor-version":[{"id":6243,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/pages\/6240\/revisions\/6243"}],"up":[{"embeddable":true,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/pages\/2518"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/media\/6241"}],"wp:attachment":[{"href":"https:\/\/aesinn.com\/en\/wp-json\/wp\/v2\/media?parent=6240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}