CRA Article 27 establishes the legal framework and mechanisms by which products with digital elements (and their manufacturers’ processes) can obtain a Presumption of Conformity with the Regulation’s essential cybersecurity requirements (as set out in Annex I).
What you may not realize is the role of Common Specifications (CS).
In the CRA, Common Specifications (CS) and Harmonized Standards (HS) are two distinct legal pathways for demonstrating conformity, and they occupy different levels of the EU regulatory hierarchy. HS are the primary and preferred route; CS are a fallback issued by the Commission when HS are missing, insufficient, or delayed.
Key Mechanisms for Demonstrating Compliance
Harmonized Standards
Products and manufacturing processes aligned with EU harmonized standards (published in the Official Journal of the European Union) automatically enjoy a presumption of conformity with the requirements covered by those standards.
Common Specifications
If European standardization bodies fail to deliver appropriate harmonized standards, face delays, or reject standardization requests, the European Commission may adopt common specifications through implementing acts to set technical requirements. Compliance with these common specifications creates a presumption of conformity.
Cybersecurity Certification Schemes
Products certified or issued a statement of conformity under a European cybersecurity certification scheme (pursuant to Regulation (EU) 2019/881) are presumed to comply with the relevant essential cybersecurity requirements.
Procedural Rules & Special Provisions
Mandatory Standard Requests
The Commission is tasked with requesting that European standardization organizations draft harmonized standards, taking into account existing international cybersecurity standards.
Delegated Authority for Certification
The Commission is authorized to adopt delegated acts that specify which European cybersecurity certification schemes qualify as evidence of compliance.
Exemption from Third-Party Assessments
Obtaining a certificate under an approved scheme at the “substantial” assurance level (or higher) exempts manufacturers from additional third-party conformity assessments for those requirements.
Safeguards and Member State Feedback
If a Member State demonstrates that a common specification does not fully meet the essential cybersecurity requirements, the Commission will evaluate the feedback and may amend or repeal the relevant implementing act. Similarly, if a harmonized standard is published that covers the same scope, the Commission will repeal the corresponding common specifications.
Will we see Common Specifications from the Commission?
Your guess is as good as mine, but I would not be surprised as we approach 2027.
Let’s Turn Strategy Into Delivered Value
Whether you are navigating CRA and NIS2 conformity, transitioning toward an empowered Product Operating Model, or de-risking a mission-critical technology project, let’s explore how we can work together.

