EU: ETSI publicly solicited comments on the draft EU CRA companion standard and updated the vulnerability reporting guidelines


On August 13, 2026, the European Telecommunications Standards Institute (ETSI) issued a notice announcing the official launch of a public consultation process for the EU Cybersecurity Act (CRA) supporting standards, releasing 17 technical specification drafts covering key digital products such as wearable devices, smart toys, internet routers, operating systems, smart homes, password managers, antivirus software, and virtual private networks (VPNs). These EN 304 XXX standards aim to provide a compliance framework for CRA, such as the antivirus software draft specifying the configuration path for "default security." According to the CRA timeline, starting September 11, 2026, relevant manufacturers must promptly report exploited vulnerabilities or serious security incidents through the European Union Agency for Cybersecurity (ENISA)'s unified reporting platform, with comprehensive compliance requirements set to take effect by the end of 2027.

Click this link to view the original text of ETSI's announcement. Click this link which allows you to view the operation guide for designated agents who have completed "EU Registration" registration on the ENISA reporting platform.