Skip to content

Conversation

@jmaris
Copy link
Contributor

@jmaris jmaris commented Nov 5, 2025

This adds an entry to the standards section on the rationale for the vertical standards. It is an answer to issue #313

Proposal for a question for the Q&A: I thought the CRA would be focussed on broad horizontal standards? What are these vertical standards and why are they so strict?

Proposed Answer:

The CRA classified types of digital products based on the risk they pose. For higher risk Class I and II products, to achieve a presumption of conformity through compliance with standards, manufacturers must also comply with the relevant vertical standards, as per Articles 7 and 32 of the Cyber Resilience Act.

A list of Class I and II products can be found in Annex III of the CRA. You can find a list of requested vertical standards the European Commission have requested in Annex I of the CRA Standardisation Request.

jmaris and others added 3 commits November 5, 2025 12:52
Added an explanation of vertical standards in relation to the CRA.

Signed-off-by: Jordan Maris <[email protected]>
@tobie
Copy link
Contributor

tobie commented Nov 5, 2025

Thanks @jmaris! This is super useful and an under documented part of the FAQs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants