Expertise / 05

STANDARDS & STANDARDISATION

European and international standards increasingly sit at the point where legal requirements become technical controls, evidence and conformity.

OSTRAI advises organisations on the regulatory role of standards, their application to products and systems, their relationship with conformity obligations and the implications of standards that are still being developed.

Our work is informed by direct participation of OSTRAI's leadership in European and international standardisation across cybersecurity, artificial intelligence, data protection and regulated technology.

STANDARDS & REGULATION

The regulatory effect depends on the framework.

Standards can support implementation, interoperability, testing, assurance and conformity. Their regulatory significance, however, depends on the applicable legal framework, the status of the standard and the requirements it covers.

Within EU harmonisation legislation, particular significance can attach to harmonised standards whose references are published in the Official Journal of the European Union. Where the applicable legislation provides for it, applying those standards can support a presumption of conformity with the legal requirements they cover.

OSTRAI assesses standards within this regulatory architecture rather than treating compliance with a standard as equivalent to compliance with the law.

Standard

A technical document developed through a recognised standardisation process.

European standard

A standard adopted by a recognised European standardisation organisation.

Harmonised standard

A European standard developed in response to a European Commission standardisation request and capable of supporting Union harmonisation legislation where its reference is published in the Official Journal.

Presumption of conformity

A regulatory effect arising only where provided by the applicable legislation and only for the requirements covered by the referenced harmonised standard.

The distinction between conformity with a standard and presumption of conformity is important: harmonised standards do not replace legally binding requirements, and the presumption extends only to the requirements actually covered.

Layered stone, glass and metal materials arranged as a precise architectural assembly

ADVISORY & IMPLEMENTATION

From standards strategy to implementation.

OSTRAI helps organisations determine which standards matter, what regulatory effect they have and how they should be integrated into product, governance and conformity programmes.

Regulatory standards strategy

Identification of relevant European and international standards, applicable regulatory frameworks, standardisation requests, sector-specific requirements and the role of standards within the wider compliance strategy.

Harmonisation & citation status

Assessment of Official Journal citation, scope, regulatory coverage, limitations, transition arrangements and the extent to which a harmonised standard can support a presumption of conformity.

Requirements mapping

Mapping of legal requirements against standards, clauses, technical controls, test methods, implementation measures and conformity evidence.

Coverage & conformity gaps

Assessment of partial coverage, missing standards, standards that are not yet harmonised, alternative technical specifications, common specifications and resulting conformity implications.

Standardisation intelligence

Monitoring of draft standards, revisions, standardisation requests, enquiry and voting stages, publication, harmonisation status, Official Journal references and regulatory developments.

Implementation & evidence

Translation of standards into implementation requirements, technical documentation, testing dependencies, evidence structures and conformity-readiness programmes.

HARMONISATION

The starting point remains the applicable legal requirement.

A harmonised standard can provide a recognised technical route for demonstrating conformity, but its effect depends on the legislation, its Official Journal status and the precise requirements it covers.

That analysis matters particularly where standards are applied only partially, multiple standards are relevant, a standard does not cover every applicable requirement or the technical solution departs from the standard.

Official Journal status

Is the relevant reference published, restricted, superseded or withdrawn?

Regulatory coverage

Which legal requirements are actually covered by the standard?

Edition & transition

Which edition applies and what transition arrangements affect the conformity position?

Additional evidence

What additional analysis, testing or documentation is required where coverage is incomplete?

FORWARD-LOOKING COMPLIANCE

Preparing for standards still in development.

Emerging regulatory frameworks can require organisations to design products, controls, governance and evidence while the technical standards intended to support implementation are still being developed.

A draft standard can provide important visibility into the direction of technical work, but it is not equivalent to an adopted standard and does not acquire the regulatory effect of a harmonised standard simply because development is advanced.

OSTRAI supports organisations in monitoring and preparing for developing standards while maintaining that distinction.

Development stages

Working drafts · Enquiry · Comments · Formal vote · Publication

Regulatory direction

Standardisation requests · Legal requirements · Expected conformity role

Implementation planning

Product design · Governance · Testing · Documentation · Evidence

Readiness & flexibility

Preparing internal programmes for developing technical expectations while retaining flexibility until the applicable standard and regulatory status are settled

SELECTED DIRECT PARTICIPATION

Direct insight into standards development.

OSTRAI's regulatory work is informed by the independent participation of its leadership in European and international standardisation through relevant delegate, expert and drafting roles.

Selected examples of current and recent participation are set out below. This involvement spans horizontal and sector-specific work across cybersecurity, artificial intelligence, data protection, industrial technology, semiconductor environments, secure identity and other regulated technologies.

CEN-CENELEC JTC 13 / WG 9

WG 9 | Cyber Resilience Act horizontal standards

Participation in the development of horizontal European standards supporting implementation of the Cyber Resilience Act under Standardisation Request M/606, including work concerning the EN 40000 series for products with digital elements.

CEN-CENELEC JTC 21

AI governance, cybersecurity and regulatory implementation

Participation in European AI standardisation supporting implementation of the AI Act and the wider development of standards for trustworthy, secure and robust artificial intelligence. The work includes the interaction between AI governance requirements, technical controls, cybersecurity, robustness and conformity evidence.

CEN-CENELEC JTC 13 / WG 5

EN 17529 | Data protection and privacy by design and by default

Assigned rapporteur for the revision of EN 17529 within CEN-CENELEC JTC 13/WG 5. The work concerns the translation of data protection and privacy-by-design principles into implementation-oriented requirements for products and services.

The examples above are selective and are not intended to provide an exhaustive record of OSTRAI leadership's standardisation participation.

CYBER RESILIENCE ACT

CRA standardisation is not limited to horizontal cybersecurity requirements.

Sector and product-specific standards are also relevant to how the Regulation is implemented across different technological environments.

OSTRAI participates in CRA-related standardisation activities across selected technical committees including:

CLC/TC 65X

Industrial-process measurement, control and automation

Standardisation relevant to industrial and automation environments, including cybersecurity requirements affecting connected industrial products and systems.

CLC/TC 47X

Semiconductor devices and trusted hardware

Standardisation relevant to semiconductor devices, trusted components and hardware environments forming part of digital products.

CEN/TC 224

Secure identity and security-functional devices

Standardisation concerning secure elements, identification systems, hardware devices with security functionalities and secure digital-identity environments.

Explore Cyber Resilience Act

CYBERSECURITY STANDARDISATION

CEN-CENELEC JTC 13 / WG 8

Continuity across product-cybersecurity frameworks.

Before the CRA harmonised-standards programme, European standardisation was already translating cybersecurity requirements into technical standards for connected radio equipment and wireless devices.

Through CEN-CENELEC JTC 13/WG 8, OSTRAI's leadership participates in standardisation activities associated with cybersecurity requirements affecting radio equipment and connected products.

This experience provides continuity across the evolution from earlier product-cybersecurity frameworks to the broader horizontal architecture introduced by the CRA.

ARTIFICIAL INTELLIGENCE

Legal requirements into technical expectations.

The AI Act creates legal requirements across areas including risk management, data, technical documentation, transparency, human oversight, accuracy, robustness and cybersecurity.

European standardisation is developing technical approaches intended to support implementation and, where the applicable conditions are met, regulatory conformity.

OSTRAI monitors and participates in this evolving standards environment to understand how legal requirements are being translated into technical expectations and evidence.

Governance & oversight

Risk management · Quality management · Documentation · Oversight

Cybersecurity & robustness

Security · Resilience · Technical controls · Lifecycle

Evidence & conformity

Standards mapping · Testing · Documentation · Harmonisation status

Explore Artificial Intelligence

DATA PROTECTION ENGINEERING

From privacy principles to implementation.

Standards can support organisations in translating privacy, security and data-protection requirements into product design, engineering processes and organisational controls.

OSTRAI's work combines regulatory interpretation with direct participation in privacy and data-protection engineering standardisation.

EN 17529

Implementation-oriented European standardisation concerning privacy by design and privacy by default.

Data-protection engineering

Participation in ENISA expert work concerning technologies, techniques and engineering approaches for implementing data-protection principles.

Explore Privacy & Data

REGULATORY ECOSYSTEMS

Standards within the wider regulatory environment.

Technical standards increasingly interact with European cybersecurity policy, certification, market access, regulatory implementation and supervisory practice.

OSTRAI's leadership participates in expert and regulatory ecosystems relevant to these developments.

ENISA standardisation

Observer participation in ENISA's Ad Hoc Working Group on Standardisation, contributing to the wider European dialogue around cybersecurity standards and standardisation priorities.

Privacy-enhancing technologies

Participation in expert work concerning privacy-enhancing technologies, data-protection engineering and technical implementation of data-protection principles.

Regulatory consultations

Engagement with European regulatory and standardisation consultations concerning cybersecurity, AI, digital regulation and emerging technology.

Participation also extends to ETSI and ISO/IEC standardisation activities relevant to cybersecurity, artificial intelligence and regulated digital technology.

Precision measuring instruments, engineered components and technical drawings

IMPLEMENTATION

Identifying the correct standard is only one part of the regulatory exercise.

Organisations must determine which provisions are relevant, how they map to legal requirements, what evidence must be created and how standards interact with product development, governance, testing and conformity assessment.

OSTRAI connects those elements.

Legal requirement

Applicable legislation and regulatory obligation

Technical standard

Relevant clauses, controls, methods and specifications

Implementation

Product design · Governance · Processes · Testing

Evidence & conformity

Technical documentation · Assessment · Traceability · Regulatory evidence

REGULATORY INTELLIGENCE

Standardisation framework in transition.

The EU is reviewing how standardisation supports regulation, competitiveness, technological development and access to the Single Market.

The announced European Product Act is intended to update the New Legislative Framework, market-surveillance rules and the European standardisation framework.

At the same time, newer product legislation increasingly provides for common specifications or other mechanisms that can operate where harmonised standards are unavailable, insufficient or cannot be delivered within the required regulatory timeframe.

OSTRAI monitors these developments for their implications across standards strategy, conformity, technical evidence and market access.

Standardisation reform

European standardisation framework

Harmonised standards

Development · Citation · Coverage · Transition

Common specifications

Alternative regulatory mechanisms where legislation provides for them

Market access

Conformity · Evidence · Product implementation

Standardisation reform · Harmonised standards · Common specifications · OJEU citation · Conformity · European Product Act

Ordered material samples and transparent geometric drawings on a drafting table

FROM DEVELOPMENT TO IMPLEMENTATION

Direct participation does not change the legal status of a standard.

It does not turn a draft into a requirement, and it does not replace the need to assess the final published text, Official Journal status and applicable legislation.

Participation in standardisation is undertaken in the relevant institutional, delegate, expert or drafting capacity and is distinct from OSTRAI's representation of individual clients.

It does, however, provide direct insight into the regulatory questions, implementation challenges and technical evidence being considered as standards develop.

OSTRAI brings that perspective into regulatory advisory work while maintaining a clear distinction between:

Standards in development

Developing technical approaches and standards under preparation

Published standards

Published European or international standards

Regulatory effect

European standards with the regulatory effect created by the applicable legal framework and Official Journal citation

Implementation

Applying the final legal and technical requirements to products, systems and organisations

Standards & standardisation

From standards to implementation and conformity.

OSTRAI helps organisations understand which standards matter, what regulatory effect they have and how to translate them into implementation, technical evidence and conformity.

Discuss a standards matter