Standard
A technical document developed through a recognised standardisation process.
STANDARDS & STANDARDISATION
OSTRAI advises organisations on the regulatory role of standards, their application to products and systems, their relationship with conformity obligations and the implications of standards that are still being developed.
Our work is informed by direct participation of OSTRAI's leadership in European and international standardisation across cybersecurity, artificial intelligence, data protection and regulated technology.
STANDARDS & REGULATION
Standards can support implementation, interoperability, testing, assurance and conformity. Their regulatory significance, however, depends on the applicable legal framework, the status of the standard and the requirements it covers.
Within EU harmonisation legislation, particular significance can attach to harmonised standards whose references are published in the Official Journal of the European Union. Where the applicable legislation provides for it, applying those standards can support a presumption of conformity with the legal requirements they cover.
OSTRAI assesses standards within this regulatory architecture rather than treating compliance with a standard as equivalent to compliance with the law.
A technical document developed through a recognised standardisation process.
A standard adopted by a recognised European standardisation organisation.
A European standard developed in response to a European Commission standardisation request and capable of supporting Union harmonisation legislation where its reference is published in the Official Journal.
A regulatory effect arising only where provided by the applicable legislation and only for the requirements covered by the referenced harmonised standard.
The distinction between conformity with a standard and presumption of conformity is important: harmonised standards do not replace legally binding requirements, and the presumption extends only to the requirements actually covered.

ADVISORY & IMPLEMENTATION
OSTRAI helps organisations determine which standards matter, what regulatory effect they have and how they should be integrated into product, governance and conformity programmes.
Identification of relevant European and international standards, applicable regulatory frameworks, standardisation requests, sector-specific requirements and the role of standards within the wider compliance strategy.
Assessment of Official Journal citation, scope, regulatory coverage, limitations, transition arrangements and the extent to which a harmonised standard can support a presumption of conformity.
Mapping of legal requirements against standards, clauses, technical controls, test methods, implementation measures and conformity evidence.
Assessment of partial coverage, missing standards, standards that are not yet harmonised, alternative technical specifications, common specifications and resulting conformity implications.
Monitoring of draft standards, revisions, standardisation requests, enquiry and voting stages, publication, harmonisation status, Official Journal references and regulatory developments.
Translation of standards into implementation requirements, technical documentation, testing dependencies, evidence structures and conformity-readiness programmes.
HARMONISATION
A harmonised standard can provide a recognised technical route for demonstrating conformity, but its effect depends on the legislation, its Official Journal status and the precise requirements it covers.
That analysis matters particularly where standards are applied only partially, multiple standards are relevant, a standard does not cover every applicable requirement or the technical solution departs from the standard.
Is the relevant reference published, restricted, superseded or withdrawn?
Which legal requirements are actually covered by the standard?
Which edition applies and what transition arrangements affect the conformity position?
What additional analysis, testing or documentation is required where coverage is incomplete?
FORWARD-LOOKING COMPLIANCE
Emerging regulatory frameworks can require organisations to design products, controls, governance and evidence while the technical standards intended to support implementation are still being developed.
A draft standard can provide important visibility into the direction of technical work, but it is not equivalent to an adopted standard and does not acquire the regulatory effect of a harmonised standard simply because development is advanced.
OSTRAI supports organisations in monitoring and preparing for developing standards while maintaining that distinction.
Working drafts · Enquiry · Comments · Formal vote · Publication
Standardisation requests · Legal requirements · Expected conformity role
Product design · Governance · Testing · Documentation · Evidence
Preparing internal programmes for developing technical expectations while retaining flexibility until the applicable standard and regulatory status are settled
SELECTED DIRECT PARTICIPATION
OSTRAI's regulatory work is informed by the independent participation of its leadership in European and international standardisation through relevant delegate, expert and drafting roles.
Selected examples of current and recent participation are set out below. This involvement spans horizontal and sector-specific work across cybersecurity, artificial intelligence, data protection, industrial technology, semiconductor environments, secure identity and other regulated technologies.
WG 9 | Cyber Resilience Act horizontal standards
Participation in the development of horizontal European standards supporting implementation of the Cyber Resilience Act under Standardisation Request M/606, including work concerning the EN 40000 series for products with digital elements.
AI governance, cybersecurity and regulatory implementation
Participation in European AI standardisation supporting implementation of the AI Act and the wider development of standards for trustworthy, secure and robust artificial intelligence. The work includes the interaction between AI governance requirements, technical controls, cybersecurity, robustness and conformity evidence.
EN 17529 | Data protection and privacy by design and by default
Assigned rapporteur for the revision of EN 17529 within CEN-CENELEC JTC 13/WG 5. The work concerns the translation of data protection and privacy-by-design principles into implementation-oriented requirements for products and services.
The examples above are selective and are not intended to provide an exhaustive record of OSTRAI leadership's standardisation participation.
CYBER RESILIENCE ACT
Sector and product-specific standards are also relevant to how the Regulation is implemented across different technological environments.
OSTRAI participates in CRA-related standardisation activities across selected technical committees including:
Industrial-process measurement, control and automation
Standardisation relevant to industrial and automation environments, including cybersecurity requirements affecting connected industrial products and systems.
Semiconductor devices and trusted hardware
Standardisation relevant to semiconductor devices, trusted components and hardware environments forming part of digital products.
Secure identity and security-functional devices
Standardisation concerning secure elements, identification systems, hardware devices with security functionalities and secure digital-identity environments.
CYBERSECURITY STANDARDISATION
CEN-CENELEC JTC 13 / WG 8
Before the CRA harmonised-standards programme, European standardisation was already translating cybersecurity requirements into technical standards for connected radio equipment and wireless devices.
Through CEN-CENELEC JTC 13/WG 8, OSTRAI's leadership participates in standardisation activities associated with cybersecurity requirements affecting radio equipment and connected products.
This experience provides continuity across the evolution from earlier product-cybersecurity frameworks to the broader horizontal architecture introduced by the CRA.
ARTIFICIAL INTELLIGENCE
The AI Act creates legal requirements across areas including risk management, data, technical documentation, transparency, human oversight, accuracy, robustness and cybersecurity.
European standardisation is developing technical approaches intended to support implementation and, where the applicable conditions are met, regulatory conformity.
OSTRAI monitors and participates in this evolving standards environment to understand how legal requirements are being translated into technical expectations and evidence.
Risk management · Quality management · Documentation · Oversight
Security · Resilience · Technical controls · Lifecycle
Standards mapping · Testing · Documentation · Harmonisation status
DATA PROTECTION ENGINEERING
Standards can support organisations in translating privacy, security and data-protection requirements into product design, engineering processes and organisational controls.
OSTRAI's work combines regulatory interpretation with direct participation in privacy and data-protection engineering standardisation.
Implementation-oriented European standardisation concerning privacy by design and privacy by default.
Participation in ENISA expert work concerning technologies, techniques and engineering approaches for implementing data-protection principles.
REGULATORY ECOSYSTEMS
Technical standards increasingly interact with European cybersecurity policy, certification, market access, regulatory implementation and supervisory practice.
OSTRAI's leadership participates in expert and regulatory ecosystems relevant to these developments.
Observer participation in ENISA's Ad Hoc Working Group on Standardisation, contributing to the wider European dialogue around cybersecurity standards and standardisation priorities.
Participation in expert work concerning privacy-enhancing technologies, data-protection engineering and technical implementation of data-protection principles.
Engagement with European regulatory and standardisation consultations concerning cybersecurity, AI, digital regulation and emerging technology.
Participation also extends to ETSI and ISO/IEC standardisation activities relevant to cybersecurity, artificial intelligence and regulated digital technology.

IMPLEMENTATION
Organisations must determine which provisions are relevant, how they map to legal requirements, what evidence must be created and how standards interact with product development, governance, testing and conformity assessment.
OSTRAI connects those elements.
Applicable legislation and regulatory obligation
Relevant clauses, controls, methods and specifications
Product design · Governance · Processes · Testing
Technical documentation · Assessment · Traceability · Regulatory evidence
REGULATORY INTELLIGENCE
The EU is reviewing how standardisation supports regulation, competitiveness, technological development and access to the Single Market.
The announced European Product Act is intended to update the New Legislative Framework, market-surveillance rules and the European standardisation framework.
At the same time, newer product legislation increasingly provides for common specifications or other mechanisms that can operate where harmonised standards are unavailable, insufficient or cannot be delivered within the required regulatory timeframe.
OSTRAI monitors these developments for their implications across standards strategy, conformity, technical evidence and market access.
European standardisation framework
Development · Citation · Coverage · Transition
Alternative regulatory mechanisms where legislation provides for them
Conformity · Evidence · Product implementation
Standardisation reform · Harmonised standards · Common specifications · OJEU citation · Conformity · European Product Act

FROM DEVELOPMENT TO IMPLEMENTATION
It does not turn a draft into a requirement, and it does not replace the need to assess the final published text, Official Journal status and applicable legislation.
Participation in standardisation is undertaken in the relevant institutional, delegate, expert or drafting capacity and is distinct from OSTRAI's representation of individual clients.
It does, however, provide direct insight into the regulatory questions, implementation challenges and technical evidence being considered as standards develop.
OSTRAI brings that perspective into regulatory advisory work while maintaining a clear distinction between:
Developing technical approaches and standards under preparation
Published European or international standards
European standards with the regulatory effect created by the applicable legal framework and Official Journal citation
Applying the final legal and technical requirements to products, systems and organisations
Standards & standardisation
OSTRAI helps organisations understand which standards matter, what regulatory effect they have and how to translate them into implementation, technical evidence and conformity.
Discuss a standards matter