Skip to content

Comment on Ask HN: Is anyone else preparing for the EU Cyber Resilience Act?parent

Comments

Thanks. The CRA's own version of what you are describing is harmonised standards: Art. 27 gives you a presumption of conformity with the Annex I requirements if you follow one whose reference has been published in the Official Journal.

The catch is that they do not exist yet. M/606 covers around 41 standards and was accepted by CEN, CENELEC and ETSI in 2025, but the Commission's July 2026 draft amendment pushed the deadlines back two months: the two core horizontal standards (secure development, vulnerability handling) are now due 31 October 2026, the verticals 31 December 2026, and the remaining horizontal ones October 2027, about a year before full application.

And delivery is not the same as availability - a standard only gives you the Art. 27 presumption once its reference is cited in the Official Journal. Nothing has been cited for the CRA yet: the Commission's harmonised standards site lists 40 pieces of legislation and the CRA is not among them.

On tooling specifically: the Open Regulatory Compliance Working Group (orcwg.org) runs a CRA hub on GitHub, closest thing I have found to what you describe.

I wish it were less complicated. :)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.