CRA and the Standardization Request M/606

The Standardization Request M/606 has been referenced several times in the blog. But what is it?

That is the topic for this article.

The Standardization Request M/606

The Standardization Request M/606 is the official mandate issued by the European Commission to the European Standardization Organizations (CEN, CENELEC, and ETSI). It directs these bodies to draft and deliver the set of European Harmonized Standards (hENs) required to support the implementation of the Cyber Resilience Act (CRA).

Key purpose & scope

The overarching objective of M/606 is to establish standards that manufacturers can use to demonstrate compliance with the CRA’s mandatory Essential Cybersecurity Requirements (Annex I, Parts I and II). Products that comply with these harmonized standards receive an automatic Presumption of Conformity.

M/606 divides the required technical deliverables into 41 standards split across two main structural tiers:

Standardisation Request M/606 Horizontal Standards (Items 1–15) GOAL Product-agnostic frameworks establishing baseline security, process, and architectural lifecycle rules. CORE BACKBONE (THE EN 40000 SERIES) EN 40000-1-1: Terminology & Vocabulary EN 40000-1-2: Principles & Lifecycle Risk Management EN 40000-1-3: Vulnerability Handling & Disclosure EN 40000-1-4: Generic Technical Security Requirements (Access Control, Data Protection, Secure Updates, etc.) FOCUS AREAS General secure development practices Vulnerability disclosure policies & processes Software Bill of Materials (SBOM) handling Hardware security baselines End-to-end lifecycle management Vertical Standards (Items 16–41) GOAL Domain-specific requirements tailored to particular classes of Products with Digital Elements (PDEs), accounting for operational environments, criticality, & sector risk profiles. TARGET CATEGORIES Industrial Automation & Control Systems (IACS) / OT Drawing heavily from IEC 62443 adaptations Operating Systems & Hypervisors Smart Home & Consumer IoT Network Interfaces, Routers, & Firewalls Smart Meters & Industrial IoT Microprocessors & Hardware Security Modules (HSMs & secure enclaves)

In CEN/CENELEC, work is primarily led by CEN-CLC/JTC 13 (Cybersecurity and Data Protection, particularly WG 9 for horizontal CRA standards and WG 6 for cryptography) and CLC/TC 65X (Industrial-process measurement, control, and automation).

In ETSI, technical work is driven via a dedicated group (ETSI EUSR) under ETSI TC CYBER.

Every standard delivered under M/606 intended for legal presumption of conformity must include an Annex ZA/ZZ mapping standard clauses directly to the corresponding provisions of CRA Annex I.

Let’s Turn Strategy Into Delivered Value

Whether you are navigating CRA and NIS2 conformity, transitioning toward an empowered Product Operating Model, or de-risking a mission-critical technology project, let’s explore how we can work together.