Skip to main content

Standards and regulatory alignment

The Standards hub (https://cvdportal.com/standards) explains how CVD Portal maps to the European standards and bodies that sit underneath the EU Cyber Resilience Act (CRA). Each page states plainly which standards confer a presumption of conformity and which are supporting references, so you can see where your evidence carries legal weight and where it is good practice.

What is on the hub

The hub links a page for each standard or body:

  • CEN/CENELEC FprEN 40000-1-2 (FprEN 40000-1-2 Hub) — the horizontal draft harmonised standard for CRA Annex I Part I product security, risk management (Clause 6), and lifecycle activities (Clause 7). It reached CEN Formal Vote in August 2026. Detailed clause-by-clause guides map every requirement ID (RMA-01 to RMA-09, CLA-01 to CLA-10) directly to platform features.
  • CEN/CENELEC EN 40000-1-3 (https://cvdportal.com/standards/en-40000-1-3) — the draft harmonised standard for CRA vulnerability handling, with a full clause-to-feature mapping. It is a CEN Enquiry draft, so it does not yet confer presumption of conformity. Once it is cited in the Official Journal of the EU, fully applying it will support presumption of conformity for the Annex I vulnerability-handling requirements under Article 27.
  • ENISA, the EUVD and Article 14 (https://cvdportal.com/standards/enisa) — how the platform aligns with ENISA's role: the Article 14 Single Reporting Platform, the European Vulnerability Database (EUVD), and national CSIRTs. The page shows a live EUVD feed, the same feed the platform uses for vulnerability monitoring.
  • ETSI EN 304 6xx vertical standards (https://cvdportal.com/standards/etsi-en-304) — the 18 product-specific CRA standards ETSI is drafting under standardisation request M/606, one for each Annex III product category, from browsers and password managers through to firewalls and hypervisors. The page maps every Annex III and Annex IV point to the standard being written for it, names the nine points ETSI is not covering and who drafts them instead, and lists the parallel CENELEC prEN 50770 series for operational technology. All of it is draft, so none of it confers presumption of conformity.
  • ETSI EN 303 645 (https://cvdportal.com/standards/etsi-en-303-645) — the consumer-IoT cybersecurity baseline that accredited labs test against, with all 13 provisions mapped to CRA Annex I evidence and platform features. It predates the CRA and is separate from ETSI's EN 304 work.
  • ISO/IEC 27001 and IEC 62443 (https://cvdportal.com/standards/iso-62443-27001) — the information-security management system standard and the industrial (OT) security series, mapped to CRA process and product requirements.
  • ENISA Secure by Design and Default Playbook (https://cvdportal.com/standards/enisa-sbd) — all 22 ENISA playbooks with their release gates, mapped to CRA Annex I using ENISA's own Annex C, plus the requirements that rest on a single playbook. It is agency guidance rather than a standard, so it confers no presumption of conformity.
  • OSCAL catalog (https://cvdportal.com/standards/oscal) — the CRA vulnerability-handling requirements expressed as a machine-readable OSCAL catalog for automated compliance tooling.
  • Machine-processable attestation (https://cvdportal.com/standards/machine-processable-attestation) — section 5 of the ENISA playbook: the control, implementation and assessment cascade, the split between a publicly verifiable attestation layer and a restricted technical overlay, and the eleven formats in that ecosystem. The section deliberately defines no schema, and the page says which of the four layers this platform emits machine-readable output for today.
  • Notified bodies and testing labs (https://cvdportal.com/standards/notified-bodies) — a directory of EU conformity-assessment bodies and cybersecurity testing laboratories.

Which standards give a presumption of conformity?

Only a standard cited in the Official Journal of the EU confers a presumption of conformity with the CRA, and no CRA harmonised standard has been cited yet.

Two families of draft standards are being written under standardisation request M/606, and neither confers anything today. The horizontal family, CEN/CENELEC's EN 40000 series including EN 40000-1-3 for vulnerability handling, applies across all products with digital elements. The vertical family covers one Annex III product category each: mostly ETSI's EN 304 6xx series, with CENELEC handling the semiconductor, smartcard and metering categories. A manufacturer of an important product will likely need both.

ETSI EN 303 645, ISO/IEC 27001 and IEC 62443 are supporting standards: applying them produces reusable evidence for a CRA technical file and is what accredited labs test against, but it does not by itself grant presumption of conformity. Each page states this clearly.

If you want to know which vertical standard is being drafted for your product, the product classifier (https://cvdportal.com/classify) names it alongside your Annex III class and conformity assessment route.

Platform support boundaries: Default vs. Important/Critical

CVD Portal is built around clear compliance boundaries:

  • Default-class products (Module A): CVD Portal provides the complete, automated compliance path. You perform the risk assessment, satisfy the Annex I checklist, generate the EU Declaration of Conformity, and maintain the Annex VII technical documentation directly within the platform, without needing a third-party notified body.
  • Important products (Class I & Class II) and Critical products (Annex IV): These products are subject to category-specific vertical standards and mandatory third-party conformity assessment (Module B+C, Module H, or EUCC certification). CVD Portal does not conduct laboratory testing or issue notified-body certificates. For these products, CVD Portal helps you assemble the risk assessment, vulnerability-handling records, and technical file to submit to your designated notified body.

Notified bodies directory

The notified bodies page (https://cvdportal.com/standards/notified-bodies) lists EU conformity-assessment bodies and cybersecurity testing laboratories, filterable by country, standard and status. It also explains when you actually need a notified body.

Most products with digital elements use internal control (Module A): the manufacturer self-assesses, affixes the CE marking, and needs no notified body. A third-party conformity assessment, and therefore a notified body, applies to important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards. If you are unsure which route applies, run the free product classifier (https://cvdportal.com/classify) or the CRA self-assessment (https://cvdportal.com/cra-self-assessment).

The directory carries an important caveat. At the time of writing, the European Commission had not yet published notified bodies designated specifically under the CRA in the official NANDO database. The organisations listed are established conformity-assessment bodies and accredited testing laboratories that a manufacturer on a third-party route is likely to engage. None is presented as holding a CRA designation, and no NANDO number is shown for a body until one is confirmed. Always verify current designation status directly in NANDO before relying on any body for a CRA conformity assessment.