Under the Cyber Resilience Act, the conformity route for a product depends on its class. For Important Class I products, the cheapest route, self-assessment, depends on something that does not exist yet: a harmonised standard cited in the Official Journal.
The four tiers
Class | Examples | Conformity route |
|---|---|---|
Default | Most products with digital elements | Self-assessment |
Important Class I | Password managers, VPNs, network management products | Self-assessment against a harmonised standard, or third-party assessment |
Important Class II | Operating systems, firewalls, microprocessors | Third-party assessment |
Critical | Smart meters, smart cards, secure elements | Certification |
The standards are late
The first core horizontal standards were due on 30 August 2026. That deadline has moved to 31 October 2026. Product-specific vertical standards moved from 30 October to 31 December 2026. None has been cited in the Official Journal yet, and notified bodies have only been designatable since 11 June 2026.

If your conformity route depends on a standard that arrives late, you are competing for assessment capacity.
In plain language
Until a standard is cited, a Class I product cannot rely on self-assessment. That means a notified body. Everyone in the same position will be looking for one in the same twelve months.
Why 2027 gets crowded
CE marking against the CRA's essential requirements applies from 11 December 2027. Standards that arrive at the end of 2026 still need to be cited, read and implemented. Notified bodies are new to this regulation and building capacity. The arithmetic points one way: firms that classify and start now will get a slot, and some that start in 2027 will not.
What to do now
Classify every SKU. Default, Class I, Class II or Critical, with the reasoning written down.
Find the Class I exposure. These are the products whose route depends on the standards timeline.
Map the gap to Annex I. Secure by design, secure defaults, vulnerability handling, an SBOM and a support period of at least five years.
Book capacity early. Open conversations with notified bodies before the queue forms.
Put a figure on it. Express the remaining exposure in euros, so the board can fund the fix and an underwriter can recognise it.
Next step. Our CRA briefing pack covers scope, the four risk tiers, the reporting clock and the dates that have already slipped. CRA readiness starts from EUR 5,000 a year. Get the briefing pack →
For any comments or information please reach out to info@astragar.com







