How Nord Security is contributing to the implementation of the Cyber Resilience Act

The EU Cyber Resilience Act (CRA) introduces new cybersecurity requirements for software and connected products sold in the EU. Through its ETSI membership, Nord Security is contributing to technical standards for VPNs, password managers, and the CRA’s antivirus software category. These standards translate the CRA’s requirements into practical guidance for companies.

July 29, 2026

6 min read

NordVPN ETSI membership

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is an EU regulation that introduces mandatory cybersecurity requirements for products with digital elements available on the EU market. This broad category includes software and connected hardware, from consumer devices and operating systems to cybersecurity products. The regulation aims to ensure that manufacturers address cybersecurity throughout a product’s lifecycle rather than only after vulnerabilities are discovered.

Under the CRA, manufacturers must build security into products from initial design through ongoing maintenance. They also need processes for finding and fixing security weaknesses, releasing updates, and explaining how you can use their products securely.

The CRA entered into force on December 10, 2024, but most of its requirements will apply from December 11, 2027. Some provisions take effect earlier, including vulnerability and incident reporting obligations from September 11, 2026.

The regulation classifies browsers, password managers, antivirus software, and virtual private network (VPN) products as “important products with digital elements.” Because these tools protect or process sensitive browsing and account data, the standards developed for them may influence how providers design, update, and maintain the products you use.

Why harmonized standards matter for CRA compliance

Harmonized standards are technical specifications that, once officially recognized by the EU, show manufacturers how to apply broad legal requirements in practice. They give companies a shared set of requirements to follow, reducing the risk that each provider interprets the CRA differently.

Once the EU cites a harmonized standard in its Official Journal, manufacturers that apply it can benefit from a “presumption of conformity” for the CRA requirements it covers. In practical terms, this gives manufacturers a recognized way to show that they meet the CRA requirements covered by that standard — though it does not prove compliance with every part of the regulation.

For some products and CRA requirements, following an applicable harmonized standard may support an internal conformity assessment. Where that assessment route is unavailable, an authorized third party may need to review the product.

Why Nord Security’s ETSI membership matters

Nord Security became an official member of the European Telecommunications Standards Institute (ETSI) on March 22, 2026. As one of three European Standardization Organizations recognized by the EU, ETSI develops standards that support European legislation and policies, including the technical guidance needed to implement the Cyber Resilience Act.

Membership gives Nord Security a formal role in this process, allowing its experts to review draft requirements, propose changes, and flag provisions that may not reflect how the covered products and features operate in practice.

By contributing while the standards are still being developed, Nord Security brings product and cybersecurity expertise to the process and can advocate for requirements that reflect real-world operating conditions, remain technically robust, and can be applied consistently across different products and organizations.

How Nord Security is contributing to the standards

Nord Security experts are helping develop ETSI standards for consumer and enterprise VPNs, password managers, and antivirus software. They review draft requirements, propose changes, add provisions, and flag rules that may not reflect how products in these categories operate.

For the draft VPN standard, Nord Security contributed requirements covering privacy measures such as memory-only server infrastructure and limits on retaining data about user activity. It also introduced Threat Protection’s browser-protection use case in the antivirus standard and a mesh networking use case in the VPN standard.

Nord Security also contributed to encryption and password-protection requirements across the draft standards. Its experts supported established methods such as ChaCha20, Argon2id, and BLAKE2 for encryption, password hashing, and data integrity, respectively.

Developing practical standards with industry experts

Useful standards require input from organizations with different products, technical architectures, and security perspectives. Through ETSI, Nord Security has worked with experts from different organizations such as the German Federal Office for Information Security (BSI), Dashlane, 1Password, Palo Alto Networks, and Airbus.

This exchange allows participants to compare approaches, challenge potentially impractical requirements, and identify areas where they can establish a shared technical baseline. It can also reduce the risk of standards being shaped around the design or operating model of a single company.

Nord Security contributes experience drawn from its work on VPNs, password managers, browser protection, mesh networking, and cryptographic requirements. Other participants bring knowledge of their own products and systems, along with different technical and regulatory perspectives. Together, these contributions support standards that can accommodate different product designs across the industry.

What these standards could mean for the industry and users

Harmonized standards can give technology providers clearer and more consistent guidance on how to meet the Cyber Resilience Act’s cybersecurity requirements. Instead of interpreting broad legal obligations independently, companies can work from shared technical benchmarks covering areas such as secure product design, vulnerability handling, security updates, and documentation.

This common framework may also make conformity assessments more predictable across the EU. Providers developing similar products could be evaluated against comparable criteria, reducing uncertainty and giving companies a clearer basis for preparing their products and internal processes before all CRA requirements take effect.

A common baseline could mean more consistent security practices across the digital products you use. Providers would be expected to plan for security throughout a product’s lifecycle, release updates, and fix reported weaknesses instead of treating security as a one-time launch requirement.

These standards cannot make a product immune to security flaws or cyberattacks. Instead, they establish a common approach to vulnerability management, long-term product maintenance, and responses to security incidents.

What comes next for CRA implementation

While ETSI continues developing the harmonized standards, technology providers can prepare for the CRA before most of its requirements begin to apply. This includes reviewing their product design, vulnerability-management processes, security-update practices, and technical documentation against the regulation’s essential cybersecurity requirements.

Once the relevant standards are officially recognized under the CRA, they can give manufacturers a basis for demonstrating conformity with the requirements they cover. Following the standards as they develop can also reveal potential gaps before the regulation takes full effect.

Online security starts with a click.

Stay safe with the world’s leading VPN

Blog author Domantas Lapinskas

Domantas Lapinskas

Domantas writes about cybersecurity, privacy, and the strange little ways the internet gets people into trouble. He offers clear, practical advice for staying safe online that is easier to remember than another complicated password.