CRA Presumption of Conformity and Common Specifications

CRA Article 27 establishes the legal framework and mechanisms by which products with digital elements (and their manufacturers’ processes) can obtain a Presumption of Conformity with the Regulation’s essential cybersecurity requirements (as set out in Annex I).

What you may not realize is the role of Common Specifications (CS).

In the CRA, Common Specifications (CS) and Harmonized Standards (HS) are two distinct legal pathways for demonstrating conformity, and they occupy different levels of the EU regulatory hierarchy. HS are the primary and preferred route; CS are a fallback issued by the Commission when HS are missing, insufficient, or delayed.

Key Mechanisms for Demonstrating Compliance

Harmonized Standards

Products and manufacturing processes aligned with EU harmonized standards (published in the Official Journal of the European Union) automatically enjoy a presumption of conformity with the requirements covered by those standards.

Common Specifications

If European standardization bodies fail to deliver appropriate harmonized standards, face delays, or reject standardization requests, the European Commission may adopt common specifications through implementing acts to set technical requirements. Compliance with these common specifications creates a presumption of conformity.

Cybersecurity Certification Schemes

Products certified or issued a statement of conformity under a European cybersecurity certification scheme (pursuant to Regulation (EU) 2019/881) are presumed to comply with the relevant essential cybersecurity requirements.

Procedural Rules & Special Provisions

Mandatory Standard Requests

The Commission is tasked with requesting that European standardization organizations draft harmonized standards, taking into account existing international cybersecurity standards.

Delegated Authority for Certification

The Commission is authorized to adopt delegated acts that specify which European cybersecurity certification schemes qualify as evidence of compliance.

Exemption from Third-Party Assessments

Obtaining a certificate under an approved scheme at the “substantial” assurance level (or higher) exempts manufacturers from additional third-party conformity assessments for those requirements.

Safeguards and Member State Feedback

If a Member State demonstrates that a common specification does not fully meet the essential cybersecurity requirements, the Commission will evaluate the feedback and may amend or repeal the relevant implementing act. Similarly, if a harmonized standard is published that covers the same scope, the Commission will repeal the corresponding common specifications.

Will we see Common Specifications from the Commission?

Your guess is as good as mine, but I would not be surprised as we approach 2027.

Let’s Turn Strategy Into Delivered Value

Whether you are navigating CRA and NIS2 conformity, transitioning toward an empowered Product Operating Model, or de-risking a mission-critical technology project, let’s explore how we can work together.