On 27 April 2026, SPAC Alliance took part in the CRA Standards Unlocked – EU Tour in Paris, held at AFNOR and organised by the European Standardisation Organisations (CEN, CENELEC, ETSI) and CYBERSTAND.eu. The event addressed key challenges for the market: understanding the impact of the Cyber Resilience Act (CRA), clarifying the role of the harmonised standards currently under development, and identifying concrete actions to support product compliance.
As part of the session dedicated to France’s CRA implementation efforts and the promotion of standardisation activities by the French institutions represented by ANSSI (the French National Cybersecurity Agency) and ANFR (the French National Frequency Agency), Mickaël Wajnglas, Secretary General of SPAC Alliance, was invited to share lessons learned from the HESTIA project. This project demonstrated the importance of mobilising an ecosystem capable of bringing a clear market perspective and field expertise to the development of the future harmonised standard No. 16. Once cited in the OJEU (Official Journal of the European Union), this standard will enable manufacturers of identity management and access control products to benefit from a presumption of conformity with the CRA.
HESTIA: supporting the industry in applying the CRA
The Cyber Resilience Act introduces a new European framework for products with digital elements. For manufacturers, this is not simply about meeting new documentation obligations: the regulation changes how products are designed, maintained, secured and demonstrated as compliant throughout their lifecycle.
In this implementation process, harmonised standards will play a central role, particularly for important Class I products, which include access control. These standards will translate CRA requirements into technical criteria, assessment methods and evidence of conformity. For SPAC Alliance, the objective is precisely to support the ecosystem concerned by the future harmonised standard No. 16.
HESTIA was launched with this objective in mind: to anticipate the impact of the CRA, structure an industry-wide perspective and enable physical security stakeholders to contribute meaningfully to European discussions. The aim was to provide expertise rooted in real-world use cases, existing access control architectures and industrial constraints.
Stéfane Mouille, a standardisation expert appointed by CEN-CENELEC as rapporteur for harmonised standard No. 16 within CEN/TC 224 WG17, also had the opportunity during the event to present the standardisation work that followed the HESTIA project and is currently being carried out within CEN. His contribution was particularly important, as it gave the market greater visibility on the current status of the future European cybersecurity standard applicable to access control and identity products, its structure, requirements, planned assessment methodology, next steps and the remaining work to be completed in 2026.
A complete ecosystem mobilised under the SPAC Alliance banner
As Mickaël Wajnglas explained, one of HESTIA’s major contributions was its ability to bring together the entire ecosystem: manufacturers, integrators, institutions, service providers, installers, design offices, end users, consultants and experts. This mobilisation was essential, as CRA compliance impacts the entire value chain.
The project made it possible to launch a collective effort around the requirements applicable to access control systems, in line with the CRA’s essential requirements and ANSSI’s reference frameworks. This approach aimed to co-build a set of pre-standardisation recommendations intended to support the development of standard No. 16 within CEN/TC 224 WG17.
HESTIA also helped strengthen the maturity of our ecosystem, both in terms of understanding the challenges raised by the CRA and in terms of participation in standardisation work.
The key role of ANSSI and ANFR
The event also clarified the organisation and operational mechanisms deployed by France for the implementation of the CRA. ANSSI presented its actions to support standardisation activities, help stakeholders build expertise and promote strong technical positions and standardisation initiatives within the French ecosystem.
It is precisely in this context that ANSSI’s support played a decisive role in the success of the HESTIA project.
ANFR, for its part, clarified its role as market surveillance authority in the implementation of the CRA, outlining the obligations of economic operators, conformity assessment mechanisms and the possible consequences of non-compliance. These new CRA conformity control objectives will form a natural continuation of its existing missions under the Radio Equipment Directive (RED).
Standardisation: a strategic issue for European competitiveness
Standardisation is not simply an administrative exercise. In the context of the CRA, it becomes a strategic lever for security, trust, competitiveness and sovereignty.
For the European electronic physical security market, the challenge is twofold:
- to ensure that conformity is based on strict requirements, adapted to the threat level and aligned with the state of the art;
- to recognise the efforts of stakeholders already investing in high security, standards and technological sovereignty.
By supporting manufacturers and bringing the market’s perspective into the discussion, SPAC Alliance helps bridge the gap between regulatory expectations, standardisation work and operational realities in the field.
HESTIA: from project to success story
This event positioned the HESTIA project as a genuine success story among the initiatives supporting the implementation of the CRA at European level.
The lessons learned from the project were presented to the European Commission, French and European standardisation organisations (AFNOR, CEN, CENELEC, ETSI), as well as an audience of assessors, manufacturers and market stakeholders. This helped strengthen the credibility of SPAC Alliance and the wider electronic physical security sector as a trusted contributor within the French and European standardisation and regulatory ecosystem.
