Cyberstand.eu just launched a new survey, inviting cybersecurity professionals and SME stakeholders to share their views on how technical standards should support compliance with the EU Cyber Resilience Act (CRA). Their input matters because the standards developed over the coming months will shape how thousands of companies across Europe demonstrate that their products meet the law's requirements. For SMEs in particular, the outcome of this process could determine whether compliance remains manageable or becomes a costly burden.
What Is the Cyber Resilience Act?
The Cyber Resilience Act is the EU's flagship regulation for the cybersecurity of products with digital elements, covering everything from consumer devices to industrial software. It sets baseline security requirements for manufacturers, importers and distributors placing such products on the EU single market, with the aim of reducing vulnerabilities and improving incident response across the digital supply chain.
Why Harmonised Standards Are Central to Compliance
Standards will play a central role in how companies demonstrate compliance, especially for cybersecurity products and services used across the EU market. Rather than interpreting the CRA's legal text directly, most companies are expected to rely on harmonised technical standards that translate those requirements into concrete engineering and documentation practices.
This matters most for smaller businesses. For many SMEs, these future product standards will be the most practical and cost-effective way to meet regulatory requirements. Larger organisations often have the legal and technical resources to build bespoke compliance programmes, but SMEs generally cannot. Clear, well-designed standards would allow them to follow an established path rather than developing compliance solutions from scratch.
Inside the CYBERSTAND.eu Survey
The Cyberstand.eu survey aims to collect insights precisely on this point: how standards can best support real-world compliance needs under the Cyber Resilience Act. It asks cybersecurity professionals and SME representatives to describe their expectations, concerns and practical experience with existing standards and certification schemes.
Responses will feed directly into the work of the European Commission, which is expected to use the findings to design guidance, tools and other supporting materials. The goal is to help SMEs efficiently understand, select and apply the product standards that will be developed under the CRA, rather than leaving them to navigate dense technical documents alone.
Why Your Participation Matters
Cyberstand.eu is encouraging broad participation. By sharing their experience and expectations, respondents will contribute directly to making CRA-related standards more usable, proportionate and SME-friendly across Europe.
With the CRA's compliance deadlines approaching, the coming months are likely to be decisive for how the standards landscape takes shape. Cybersecurity professionals and SME stakeholders who want a say in that process are invited to complete the survey.
TAKE THE SURVEY