
The EU Cyber Resilience Act (CRA) categorizes digital products into three tiers based on risk: Default, important, and critical. Password managers fall under “important” products, Class I. Products in this class will be required to have CE marking and follow specific security requirements and compliance obligations.
Starting September 2026, reporting obligations require manufacturers to notify ENISA and their national CSIRT within 24 hours of discovering an actively exploited vulnerability or a severe security incident, with a fuller notification due within 72 hours and a final report within 14 days.
The standard for our category, EN 304 618, is currently being written to define the requirements we'll be assessed against. It covers secret generation, encryption, authentication, session management, audit logging, and a long list of other controls specific to how password managers store and protect credentials.
By December 2027, all password managers sold in the EU will have to self-assess conformity to this new standard.
Dashlane's participation in the standard
These standards are developed through working groups, with periods where the standard is open for public comment. EN 304 618 is drafted in public on ETSI's repository. Dashlane is an ETSI member and an active contributor to these standards. That participation gives us early visibility into requirements before they're final and the ability to ensure what’s going to be codified into law is sound.
EN 304 618 requirements impact what you'd expect from a password manager standard: Secure and random number generation for passwords, WebAuthn and FIDO conformance for passkeys, key derivation for vault encryption, multi-factor authentication, and tamper-resistant audit logs for vault access and credential events.
The draft is undergoing the review process at the EU level, and final publication is expected by the end of 2026. We'll share more detail on our conformity work once the standard stabilizes.
Raising the bar for the industry
Compliance that helps level up security and privacy is welcome. Dashlane has long advocated for security and privacy by design. We will use the standard as a way to keep challenging ourselves and invest in stepping up the security architecture of our product.
The CRA doesn’t change the direction we were already headed. Dashlane's zero-knowledge architecture was built on the same principle the CRA now codifies: Security should be the default.
A binding EU standard raises the baseline across the industry. Our job is to keep building above it, the same way we have with encryption, passkeys, and enclave-based AI processing.
What this means for you
If you're evaluating Dashlane or already rely on it, we have you covered. We're tracking the CRA timeline, preparing for Class I self-assessment, and contributing to the standard that will define what compliance looks like for our category.
If you have questions about how this affects your organization's own compliance obligations or procurement process, reach out to your Dashlane contact. We'll publish more details as EN 304 618 moves toward final publication.
Sources
Sign up to receive news and updates about Dashlane





