On 26 February 2025, Maria Raphael participated as a speaker in the “Standardisation for the Cyber Resilience Act” webinar, co-organised by Cyberstand.eu, HSbooster.eu and Stan4CR.

The event brought together EU cybersecurity professionals, policymakers, standards experts and industry participants to discuss developments surrounding the Cyber Resilience Act and the progress of European standardisation work supporting its implementation.

Speakers included Filipe Jones-Mourão from DG CONNECT and Lucia Lanfri from CEN-CENELEC, who discussed the current status of CRA implementation, the relevant working groups and the expected timelines for developing horizontal and vertical standards.

Maria Raphael presented the scope and rules of the CRA, the different product categories provided for in the Regulation and the conformity-assessment processes corresponding to those categories, including Critical Products and Important Products, Class I and Class II.

She also presented the work being carried out by PT1 of CEN/CLC/JTC 13/WG 9 on the first standardisation deliverable requested under the CRA standardisation programme, for which she was acting as one of the editors.

The Cyber Resilience Act framework

The Cyber Resilience Act establishes cybersecurity requirements for products with digital elements in order to support a high level of cybersecurity across the European Union.

Among its core elements are:

  • rules for market access, requiring covered digital products to meet applicable cybersecurity requirements before being placed on the market;
  • security-by-design principles, requiring manufacturers to integrate cybersecurity measures into the design, development and production of their products;
  • vulnerability-handling obligations, requiring processes to manage vulnerabilities throughout the product lifecycle; and
  • enforcement mechanisms, under which market-surveillance authorities oversee compliance and may act in cases of non-conformity.

Product categories and conformity assessment

During the webinar, Maria Raphael informed the audience about the CRA’s scope and rules, the different product categories provided for in the Regulation and the corresponding conformity-assessment processes.

This included discussion of:

  • Important Products;
  • Class I Important Products;
  • Class II Important Products; and
  • Critical Products.

The applicable conformity-assessment route depends on the relevant product category and the conditions established by the CRA.

The first CRA framework standardisation deliverable

A central part of Maria Raphael’s presentation concerned the work being carried out by PT1 of CEN/CLC/JTC 13/WG 9 on the first standardisation deliverable requested under the CRA standardisation programme, for which she was acting as one of the editors.

The scope of the first requested item was to serve as a framework covering all elements defined in Section 1 of Annex II of the standardisation request.

It was intended to set out specifications for the design, development and production of products with digital elements in order to ensure an appropriate level of cybersecurity based on risk.

At the time, the state of the art in cybersecurity for products with digital elements lacked a unified, comprehensive framework across the EU.

Existing standards and regulations were often fragmented, with some covering specific sectors or aspects of cybersecurity but failing to address the full lifecycle of products with digital elements.

As a result, manufacturers could face inconsistent requirements, while users could experience varying levels of cybersecurity assurance, contributing to vulnerabilities and a lack of transparency.

The first requested item was intended to facilitate consistency, implementability and a harmonised approach among the requested deliverables.

Consistency, implementability and a harmonised approach

The first requested deliverable was intended to support consistency and implementability across the wider set of CRA standards.

The objective was not simply to produce another cybersecurity standard.

It was to establish a framework capable of supporting the other requested deliverables through common principles and a coherent approach to product cybersecurity.

That common foundation was particularly important because the CRA standardisation programme was expected to include both horizontal and vertical standards.

The challenge of horizontal and vertical standards

One of the key challenges discussed during the presentation was the requirement in the standardisation request that vertical standards remain coherent with the requested horizontal deliverable.

As part of the work on the first requested deliverable, the aim was to develop comprehensive cybersecurity principles that could be adopted by different verticals without compromising the adaptability and flexibility required by individual product standards.

At the same time, the standards needed to remain aligned with a common foundational cybersecurity framework.

The objective was therefore to balance:

  • harmonisation;
  • consistency across the standards architecture;
  • interoperability between deliverables; and
  • flexibility for product-specific requirements.

The work sought to maintain a common cybersecurity foundation while allowing each vertical standard to adapt the framework to its own technical context.

Why the framework matters

The first requested deliverable was intended to provide a coherent foundation for the wider CRA standardisation programme.

Its significance lay in supporting greater consistency between regulatory requirements, technical standards, product-specific cybersecurity measures and conformity-assessment processes.

The webinar therefore provided an early view into the technical standardisation work intended to support practical implementation of the Cyber Resilience Act.

Presenting the work to the CRA community

Maria Raphael’s contribution focused on explaining both the regulatory structure of the CRA and the standardisation work being developed to support its implementation.

The presentation addressed product classification, conformity assessment and the work of CEN/CLC/JTC 13/WG 9 on the first framework deliverable.

It provided participants with direct insight into the developing standards work and the challenge of translating broad CRA requirements into a coherent technical framework.