~/f4n6 $ grep -r "Risky Bulletin: The EU publishes its upcoming cybersecurity standards" ./investigations/ --include="*.md"

Risky Bulletin: The EU publishes its upcoming cybersecurity standards

Jeff Davies 17 Aug 2026 3 min read

1. Executive summary

ETSI has published 17 interim draft cybersecurity standards defining minimum security requirements for product categories — including operating systems, network devices, VPNs, virtualization containers, SIEMs, antivirus, PKI software, and password managers — that vendors must meet to sell into the EU under the Cyber Resilience Act (CRA), effective December 2027. The drafts are open for public comment through national standardization bodies until November 2026, with final versions expected by December 2026. For EMEA financial services, the standards formalise baseline expectations — SBOMs, secure-by-default configurations, modern cryptography, and post-sale updateability — that will become procurement gatekeepers for ICT products; institutions should begin aligning vendor assessment and third-party risk processes now.

2. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The CRA standards are a forward-looking regulatory development, not an incident or a specific obligation trigger under the DORA or NIS2 articles in scope of this advisory. While DORA Art. 28 (ICT third-party risk — general principles) is conceptually adjacent — CRA-compliant products will eventually simplify vendor risk assessments — the standards are interim drafts and do not yet impose a distinctive, actionable obligation that changes what a client must do today under that article.

3. Technical analysis & attack chain

This is a strategic/policy item, not a vulnerability or threat campaign. No attack chain applies.

How the CRA standards framework works (from source facts only)

ETSI has released 17 cybersecurity standards covering core technology product categories. The full list of categories from the source:

  • Operating systems
  • Routers, modems, and switches
  • Firewalls
  • VPNs
  • Virtualization containers
  • Network management systems
  • SIEMs
  • Antivirus software
  • Boot managers
  • Network interfaces
  • Browsers
  • Password managers
  • PKI software
  • Smart home appliances
  • Smart home security systems
  • Internet-connected toys
  • Wearables

Each standard describes a list of minimum security features a product must implement to be CRA-compliant. The common baseline requirements across most categories are:

  • Post-sale updateability: Products must support security updates after sale.
  • SBOM: Devices must ship with a Software Bill of Materials.
  • Modern cryptography: Products must use current cryptographic standards.
  • Secure-by-default settings: Products must ship with secure configurations out of the box.

Category-specific requirements exist but, per the source, none introduce unreasonable demands. The standards largely codify long-standing expert recommendations that vendors have rarely adopted voluntarily.

Timeline

  • Current status: Interim drafts, public comment phase open.
  • Comment deadline: November 2026 (national standardization bodies across the EU and EEA submit feedback).
  • Final standards expected: December 2026.
  • CRA compliance effective: December 2027.

The source notes that most vendors should already be aware of these expectations, as EU lawmakers have signalled the requirements for years, and many vendors already support features like automatic security updates, default secure configs, and better crypto.

4. Mitigation & containment

P1 — Within 24 hours (awareness & inventory)

  • Distribute this advisory to procurement, vendor risk, and legal teams. The CRA standards will become a procurement gatekeeper for ICT products sold into the EU from December 2027.

P2 — Within 72 hours (gap assessment)

  • Inventory current critical ICT vendors across the 17 product categories (prioritise SIEM, VPN, firewall, virtualization container, PKI, and antivirus vendors — these are core to financial services infrastructure).
  • For each, determine whether the vendor already ships SBOMs, supports automatic security updates, uses modern cryptography, and ships secure-by-default configurations. These are the four baseline requirements most standards share.
  • Identify vendors likely to struggle with CRA compliance (legacy products, no SBOM capability, no update mechanism).

P3 — Within 7 days (process alignment)

  • Review and update vendor procurement questionnaires and third-party risk assessment templates to include CRA-readiness questions aligned to the four baseline requirements above.
  • Submit feedback on the draft standards through your national standardization body before the November 2026 comment deadline if any category-specific requirement would create operational friction for your institution.
  • Monitor ETSI for publication of final standards in December 2026 and update procurement templates accordingly.
  • Begin planning for DORA Art. 28 alignment: CRA-compliant products will eventually feed into ICT third-party risk assessments, but the standards are not yet final.

5. Indicators of compromise

No indicators of compromise available in the source material.

6. Detection

Insufficient indicators to author detection rules.

7. Sources

  • Risky Business News, "Risky Bulletin: The EU publishes its upcoming cybersecurity standards," https://news.risky.biz/risky-bulletin-the-eu-publishes-its-upcoming-cybersecurity-standards/, 2026-08-17

8. Adverse Trace position

This is a low-immediacy, high-strategic-significance development. The CRA standards are interim drafts and do not take effect until December 2027, giving institutions a clear runway. The practical risk for EMEA financial services is not a security threat but a procurement and vendor-risk readiness gap: institutions that delay aligning assessment processes risk discovering non-compliance in critical ICT vendors too late to remediate before the CRA deadline. The four baseline requirements (SBOM, updateability, modern crypto, secure-by-default) are not technically demanding — most reputable vendors already meet them — but the 17 category-specific standards may contain requirements that create friction for specific product lines. We will monitor the November comment phase and December finalisation, and produce a follow-up advisory with a detailed procurement checklist once the final standards are published. Clients should treat this as a P3 planning priority, not a P1 operational threat.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies