General

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 28 Aug 2026
View moreView less
 

The present document applies to Mobile Earth Station (MES) radio equipment which have the following characteristics: 
• the MES has both transmit and receive capabilities and operate in a Satellite-Personal Communications 
Network (S-PCN). An S-PCN MES can be a handheld, portable, vehicle-mounted, host connected, semi-fixed 
or fixed equipment, or can be an element in a multi-mode terminal. It consists of a number of modules with 
associated connections and user interface, or can be a self-contained single unit; 
• these MESs are controlled and monitored by Control Monitoring Functions (CMF). The CMF is outside the 
scope of the present document; 
• if the MES is an element in a multi-mode terminal, unless otherwise stated in the present document, its 
requirements apply only to the S-PCN MES element of the terminal operating in the MSS frequency bands 
given in table 1; 
• the MES is capable in operating in all or part of the frequency bands shown in table 1. 
Table 1: Mobile Satellite Service (MSS) frequency bands 
MES 
MSS frequency bands 
Transmit 
Receive 
1 610 MHz to 1 626,5 MHz 
1 613,8 MHz to 1 626,5 MHz 
Receive 
2 483,5 MHz to 2 500,0 MHz 
NOTE: The relationship between the present document and essential requirements of article 3.2 of Directive 
2014/53/EU [i.3] is given in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin:
Close date: 28 Aug 2026
View moreView less
 

The present document specifies technical characteristics and methods of measurements for Mobile Earth Stations 
(MES) providing Low Bit Rate Data Communications (LBRDC) using Low Earth Orbit (LEO) satellites and which 
have the following characteristics: - - - - 
the MES as covered by the present document are a Based MES (BMES), a Vehicle mounted MES (VMES), or 
a Portable MES (PMES); 
the MESs operate through satellites in Low Earth Orbit (LEO) as part of a network providing Low Bit Rate 
Data Communications (LBRDC); 
these radio equipment are designed to operate in all or any part of the frequency bands given in table 1. 
The MESs have to be part of a satellite network and controlled and monitored by a Network Control Facility 
(NCF). The specification of the NCF is outside the scope of the present document. 
Table 1: Frequency ranges in Transmit and Receive frequencies 
MES Transmit frequencies and Service allocations 
(MHz) 
MES Receive frequencies and Service allocations 
(MHz) 
148 to 149,9 
MSS 
137 to 137,025 
149,9 to 150,05 
MSS 
137,025 to 137,175 
MSS 
235 to 322 
mss 
MSS 
137,175 to 137,825 
335,4 to 399,9 
MSS 
MSS 
137,825 to 138 
399,9 to 400,05 
mss 
MSS 
235 to 322 
335,4 to 399,9 
MSS 
MSS 
400,15 to 401 
MSS 
NOTE 1: The acronyms "MSS" and "mss" refer to mobile satellite service (See list of abbreviations). Capital letters 
"MSS" refer to Primary MSS service. Lower case "mss" refers to secondary MSS service.  
The present document is intended to cover the provisions of article 3.2 of Directive 2014/53/EU [i.3] (RE Directive). 
NOTE 2: The relationship between the present document and essential requirements of article 3.2 of the Directive 
2014/53 [i.3] is given in Annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 28 Aug 2026
View moreView less
 

The present document specifies technical characteristics and methods for measurements for satellite communications 
Earth Stations (ES) with the following characteristics: 
• The ES is designed for stationary operation. 
• The ES is operating as part of a satellite network (e.g. star, mesh or point to point) used for the distribution 
and/or exchange of information. 
• The transmit and receive frequencies are shown in Table 1. 
Table 1: Frequency bands 
Transmit (Earth-to-space) 1 
Frequency Bands/frequencies 
Transmit (Earth-to-space) 2 
27,5 GHz to 29,1 GHz  
29,5 GHz to 30,0 GHz 
Receive (space-to-Earth) 
17,3 GHz to 20,2 GHz 
• The ES transmits within the frequency range from 27,5 GHz to 29,1 GHz and 29,5 GHz to 30,0 GHz, which 
are bands allocated to the Fixed Satellite Services (FSS) (Earth-to-space) among other services. 
• At the national level, terminals covered by the present document, might operate on a co-frequency basis, with 
stations of other FSS networks / systems or with stations of other services. The present document does not 
cover requirements for ensuring protection of such services. 
• The ES receives within the range from 17,30 GHz to 20,20 GHz (FSS). 
• The ES uses linear or circular polarization. 
• The ES operates through non-geostationary satellites. 
• The ES is designed for unattended operation and it does not address specifications or requirements for earth 
stations operating as gateways or master earth station. 
• The ES is controlled and monitored by a Network Control Facility (NCF). This function may be performed 
centrally (e.g. for a network of ESs with a central hub) or it could be performed within the ES for autonomous 
control. The NCF is outside the scope of the present document. 
• The ES has one or more directive antennas that track satellites. 
The present document may also be applicable to the frequency bands 30,0 GHz to 31,0 GHz (Earth-to-space) and 
20,2 GHz to 21,2 GHz (space-to-Earth) subject to national regulation. 
The present document applies to the ES including its ancillary equipment and its various telecommunication ports, and 
when operated within the boundary limits of the operational environmental profile as defined by the intended use of the 
ES 
NOTE: The relationship between the present document and essential requirements of article 3.2 of Directive 
2014/53/EU [i.1] is given in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 30 Aug 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for routers, modems intended for connection to the internet, and switches related to cybersecurity. The products 
with digital elements in scope: 
• are specified within the "technical description" of the "category of product" in Class I, point 12 by the 
Commission Implementing Regulation (EU) 2025/2392 [i.2] of 28 November 2025 on the technical 
description of the categories of important and critical products with digital elements pursuant to 
Regulation (EU) 2024/2847 of the European Parliament and of the Council [i.1] as: - - - 
"Routers are products with digital elements that establish and control the flow of data between different 
networks by selecting paths or routes using routing protocol mechanisms and algorithms, typically 
operating at the network layer. 
This category includes but is not limited to wired and wireless routers, virtual routers and routers with or 
without modems."; 
"Modems intended for the connection to the Internet are hardware products with digital elements that use 
digital modulation and demodulation techniques to convert analogue signals from and to digital signals 
for IP-based communication. 
This category includes but is not limited to fibre modems, Digital Subscriber Line (DSL) modems, cable 
(DOCSIS) modems, satellite modems and cellular modems."; 
"Switches are products with digital elements that provide connectivity between networked devices 
through traffic forwarding mechanisms typically implemented at the data link layer. 
This category includes but is not limited to managed switches, smart switches, multilayer switches, 
virtual security switches, programmable switches for software-defined networking and bridges such as 
wireless access points."; 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with the essential cybersecurity requirements 
of Regulation (EU) 2024/2847 [i.1], Annex I Part I, under the conditions identified in Annex A. 
NOTE 1: The term "internet" refers to any public network accessible beyond organizational boundaries. Public 
networks are accessible to multiple organizations or the general public. Private networks operate under 
single organizational control. 
Routers, modems intended for connection to the internet, and switches fall within the scope of the present document 
when they provide management capabilities. This applies to all deployment forms such as dedicated hardware, virtual 
machines, containerized applications, and cloud-native network functions. The intended purpose or reasonably 
foreseeable use is to process, forward, or manage network traffic between devices, network segments, or between public 
and private networks. 
NOTE 2: Unmanaged products with fixed functionality and no configuration interface are excluded from scope, as 
they lack the interfaces needed to implement the security controls of the present document. 
The present document does not specify protocol conformance requirements, performance specifications, QoS metrics, 
or interoperability testing. Security controls for protocol implementation and vulnerability management remain within 
scope. 
NOTE 3: Products that integrate particular wireless or wired communication technologies, such as Wi-Fi®, cellular, 
DECT, and DECT-2020 NR remain within scope when they function as routers, modems intended for 
connection to the internet, or switches 
Routers, modems intended for connection to the internet, and switches intended for use in the industrial Operational 
Technology (OT) domain are excluded from the scope of the present document, see prEN 50770-5 [i.14].

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 30 Aug 2026
View moreView less
 

The present document specifies test severities and methods for the verification of the required resistibility of equipment 
according to the relevant environmental class. 
The tests in the present document apply to stationary use of equipment at weatherprotected locations covering the 
environmental conditions stated in ETSI EN 300 019-1-3 [1]. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin:
Close date: 05 Sep 2026
View moreView less
 

The present document specifies technical characteristic and methods of measurements for Very Small Aperture 
Terminal (VSAT) equipment which has the following characteristics: 
• the VSAT is operating in one or more frequency ranges within the following bands allocated to the Fixed 
Satellite Service (FSS), shared with other services, e.g. the Fixed Service (FS) and the Mobile Service (MS): - - - 
5,850 GHz to 7,075 GHz (Earth-to-space); 
3,400 GHz to 4,200 GHz (space-to-Earth); 
4,500 GHz to 4,800 GHz (space-to-Earth); 
• the VSAT uses linear or circular polarization; 
• the VSAT operates through a geostationary satellite at least 2° away from any other geostationary satellite 
operating in the same frequency band and covering the same area; 
• the VSAT antenna diameter does not exceed 7,3 m, or equivalent effective area; 
• the VSAT is either: - - - 
a transmit-only VSAT: designed for transmission-only of radio-communications signals in the frequency 
band (earth-to-space) specified in the present clause; or 
a transmit-and-receive VSAT: designed for transmission-and-reception of radio-communications signals 
in the frequency bands specified in the present clause; or 
a receive-only VSAT: designed for reception-only of radio-communications signals in the frequency 
band (space-to-Earth) specified in the present clause; 
• the VSAT is designed for unattended operation; 
• the VSAT is operating as part of a satellite network (e.g. star, mesh or point-to-point) used for the distribution 
and/or exchange of information between users; the VSAT is controlled, and monitored for the transmit 
functionality, by a Centralized Control and Monitoring Facility (CCMF). The VSAT has to implement Control 
and Monitoring Functions with either Class A or Class B (structures of the radio states). The specifications 
associated to the CCMF facility are outside the scope of the present document. 
The present document applies to the VSAT with its ancillary equipment and its various terrestrial ports, and when 
operated within the boundary limits of the operational environmental profile defined for the intended use of the VSAT 
including all equipment as brought to the market. 
The present document does not contain any requirement, recommendation or information about the installation of the 
VSAT. 
All parts of the indoor unit related to reception, processing and presentation of the received information except the 
control channel are not within the scope of the present document. The syntax of the control channel messages is outside 
the scope of the present document. The present document is intended to cover the provisions of Directive 2014/53/EU 
(Radio Equipment Directive) [i.5] article 3.2.  
NOTE: The relationship between the present document and essential requirements of article 3.2 of 
Directive 2014/53/EU [i.5] is given in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for firewalls, intrusion detection systems, and intrusion prevention systems related to cybersecurity. The 
products with digital elements in scope: 
• are specified within the "technical description" of the "category of product" in Class II, point 2 by the 
Commission Implementing Regulation (EU) 2025/2392 [i.2] of 28 November 2025 on the technical 
description of the categories of important and critical products with digital elements pursuant to Regulation 
(EU) 2024/2847 of the European Parliament and of the Council [i.1] as: - - - 
"Firewalls are products with digital elements that protect a connected network or system from 
unauthorised access by monitoring and restricting data communication traffic to and from that network. 
This category includes but is not limited to network firewalls and application firewalls such as web 
application firewalls or filters and anti-spam gateways."; 
"Intrusion detection systems are products with digital elements that monitor traffic once it has entered the 
network environment for suspicious activity and detect or identify that an intrusion has been attempted, 
is occurring, or has occurred on a connected network or system. 
This category includes but is not limited to network-based intrusion detection systems and host-based 
intrusion detection systems."; 
"Intrusion prevention systems are products with digital elements composed of an intrusion detection 
system that actively responds to an intrusion to a connected network or system. 
This category includes but is not limited to network-based intrusion prevention systems and host-based 
intrusion prevention systems."; 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with the essential cybersecurity requirements 
of Regulation (EU) 2024/2847 [i.1], Annex I Part I, under the conditions identified in Annex A. 
Firewalls, intrusion detection systems, and intrusion prevention systems fall within the scope of the present document, 
whether deployed as physical appliances or software. The present document applies when the intended purpose or 
reasonably foreseeable use involves monitoring, analysing, or controlling network traffic for security purposes. 
Products that detect access attempts made without authorisation, identify malicious activity, or enforce traffic controls 
to protect networks and systems from intrusions are within scope. 
Firewalls, intrusion detection systems, and intrusion prevention systems intended for use in the industrial OT 
(Operational Technology) domain are excluded from the scope of the present document, see prEN 50770-1 [i.7]. 
The present document does not specify how products detect threats, classify traffic, or implement inspection algorithms. 
Detection accuracy rates, false positive thresholds, and signature effectiveness metrics are outside scope. Security 
requirements for the robustness of protocol parsing engines, the integrity of inspection processes, and vulnerability 
management remain within scope.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for software products 
with digital elements that detect or search for malicious software or code on a device, or remove or quarantine such 
software or code to prevent or mitigate system infection related to cybersecurity. The products with digital elements in 
scope, thereafter "the product": 
• are specified within the "technical description" of the "category of product" number "4" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: - 
"Software products with digital elements, typically referred to as antivirus or antimalware, that detect or 
search for malicious software or code on devices, or remove or quarantine such software or code, in 
order to maintain the integrity, confidentiality, or availability of such devices. 
In the context of this category of products, malicious software means software containing malicious 
features or capabilities that can cause harm directly or indirectly to the user and/or the computer system, 
such as viruses, worms, ransomware, spyware and trojans. 
This category includes but is not limited to software that detects or searches for malicious software in 
real-time or manually, rootkit detection and rescue disks with the core functionality of searching, 
removing or quarantining malicious software." 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A. 
The present document specifies technical characteristics and methods of assessment for Antivirus/Antimalware 
products. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for smart home general purpose virtual assistants related to cybersecurity. The products with digital elements in 
scope, thereafter "smart home general purpose virtual assistants": 
• are specified within the "technical description" of the "category of product" number "16." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Products with digital elements that communicate on the public Internet, whether directly or via other 
equipment, that process demands, tasks or questions based on natural language prompts, such as through audio 
or written input, and that, based on those demands, tasks or questions, provide access to other services or 
control the functions of connected devices in residential settings. 
This category includes but is not limited to smart speakers with an integrated virtual assistant, and standalone 
virtual assistants that meet this description"; and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for smart home products with security functionalities related to cybersecurity. The products with digital 
elements in scope, thereafter "smart home products with security functionalities": 
• are specified within the "technical description" of the "category of product" number "17." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Products with digital elements that protect the physical security of consumers in a residential setting and 
which can be controlled or managed remotely from other systems, as well as hardware and software that 
centrally control such products. 
This category includes but is not limited to smart door locking devices, baby monitoring systems, alarm 
systems and home security cameras"; and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in clause A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for internet connected toys related to cybersecurity. The products with digital elements in scope, thereafter 
"internet connected toys": 
• are specified within the "technical description" of the "category of product" number "18." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Internet connected toys that have social interactive features are products with digital elements that are 
covered by Directive 2009/48/EC, that communicate on the public Internet, whether directly or via any other 
equipment, and that have embedded technologies that enable inbound and outbound communication, such as 
keyboard, microphone, speaker or camera." or "Internet connected toys that have location tracking features are 
products with digital elements that are covered by Directive 2009/48/EC, that communicate on the public 
Internet, whether directly or via any other equipment, and that have technologies that enable tracking or 
inferring of the geographical location of the toy or its user. Where the toy merely detects the proximity of the 
user or of other toys by using sensing technologies, the toy is not to be considered to have location tracking 
features." and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] under the conditions identified in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 14 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for personal wearable 
products that have a health monitoring purpose or that are intended for the use by and for children, related to 
cybersecurity. The products with digital elements in scope, thereafter "personal wearable": 
• are specified within the "technical description" of the "category of product" number "19" by the Commission 
Implementing Regulation (EU) 2025/2392 of 28 November 2025 [i.2] as: 
"Personal wearable products to be worn or placed on a human body that have a health monitoring (such as 
tracking) purpose and to which Regulation (EU) 2017/745(2)or (EU) 2017/746 of the European Parliament 
and of the Council do not apply, or personal wearable products that are intended for the use by and for 
children". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 29 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for public key
infrastructure and digital certificate issuance software related to cybersecurity. The products with digital elements in
scope, thereafter "the Products":
• are specified within the "technical description" of the "category of product" number "9" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements used as part of a public key infrastructure (PKI) that manage the validation,
creation, issuance, distribution, status publication, renewal or revocation of digital certificates, or the
generation, storage, escrow, exchange, destruction or rotation of cryptographic keys associated with such
digital certificates. This category includes but is not limited to key management systems, digital certificate
management systems, online certificate status protocol responders and all-in-one PKI solutions".
• are only covered within the product context described in clause 4.
The present document covers those Products to demonstrate compliance with essential cybersecurity requirements in
the Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
Different use cases representing different product architecture are presented in clause 4.6. Requirements applicability in
clause 5 then defines which requirements apply to which use case to ensure compliance with the CRA's essential
cybersecurity requirements.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 02 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for physical and virtual 
network interfaces related to cybersecurity. The products with digital elements in scope, thereafter "network interfaces": 
• are specified within the "technical description" of the "category of product" number "10" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as:  
"Physical network interfaces are products with digital elements that directly connect a device to a network via 
an Application Programming Interface (API) provided by the interface drivers, typically operating at the data 
link layer, and that feature hardware adapters to transmission media with corresponding firmware, typically 
operating at the physical and data link layer. 
Virtual network interfaces are products with digital elements that directly or indirectly connect a device to a 
network via an API that emulates that of drivers of physical network interfaces, typically operating at the data 
link layer. 
This category includes but is not limited to wired and wireless network interface cards, controllers and 
adapters, such as for Wi-Fi®, Ethernet, IrDA, USB, Bluetooth, NearLink, Zigbee®, or Fieldbus, as well as 
purely virtual standalone products, such as virtual network interface cards, container network interfaces and 
VPN interfaces". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I Part I under the conditions identified in Annex A. 
Network interfaces intended for use in the industrial Operational Technology (OT) domain are excluded from the scope 
of the present document, see prEN 50770 series [i.5]. 
Network interfaces whose intended purpose includes management or configuration of the product over the attached 
network are excluded from the present document. 
Network interfaces whose intended purpose includes routing, switching; or transfer of information from one attached 
network to a different attached network are excluded from the present document.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for web browsers related 
to cybersecurity. The products with digital elements in scope, thereafter "the products" are specified within the 
"technical description" of the "category of product" number "2" by the Commission Implementing Regulation (EU) 
2025/2392 [i.2] as: 
• "Software products with digital elements that enable end users to access, render, and interact with web content 
and services hosted on servers that are connected to networks such as the Internet. They typically include a 
browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for 
web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of 
temporary or persistent data from websites (cookies). 
This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded 
browsers intended for integration into another system or application as well as browsers with AI agent integration." 
The products are only covered within the product context described in clause 4. The present document specifies 
technical characteristics and methods of assessment for: 
• Standalone web browsers: standalone applications that fulfil the functions of web browsers 
• Embedded web browsers: embedded browsers intended for integration into another system or application 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A. 
Browsers with AI agent integration are out of the scope of the present document as well.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for Virtual Private 
Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs": 
• are specified within the "technical description" of the "category of product" number "5" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that establish an encrypted 
logical tunnel that is constructed from the system resources of a physical or virtual network". 
• are only covered within the product context described in clause 4 and the text of this clause. 
In particular, the present document specifies technical characteristics and methods of assessment for: 
1) 
2) 
3) 
4) 
Software that operates as a VPN client or endpoint 
Software that operates as a node within a mesh VPN network 
Software that operates as a VPN server 
Remote data processing, specifically VPN server software performing the logical server role, and associated 
software used for such VPN products 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A. 
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document. 
VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the 
present document, see prEN 50770 series [i.5].

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for Network Management 
Systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":  
• are specified within the "technical description" of the "category of product" number "6" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that manage connected 
network elements, such as servers, routers, switches, workstations, printers or mobile devices, by monitoring 
them and controlling their network operations and configuration". 
This category includes but is not limited to end-to-end management systems and dedicated configuration 
management systems, such as controllers for software-defined networking. 
• The products with digital elements in scope are only covered within the product context described in clause 4 
of the present document. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A. 
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking, e.g when 
an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI). 
NMS intended for use in the industrial Operational Technology (OT) [i.18] domain are excluded from the scope of the 
present document. 
An NMS is a product controlling at least partially connected devices with network access. Despite its central 
positioning, an NMS can be an aggregate of several components, including but not limited to: end-to-end management 
systems, dedicated configuration management systems, or controllers for software-defined networking. 
NMS can be composed of several components or can implement additional functions that are outside the scope of the 
present document. 
EXAMPLE: 
Aggregate product design would be an implementation where the operating system acts as an 
abstraction layer for the system(s) that host the NMS, or the networking interfaces.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for Security Information 
and Event Management related to cybersecurity. 
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems": 
• are specified within the "technical description" of the "category of product" number 7 by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: Products with digital elements that collect data from 
multiple sources, analyse and correlate that data and present it as actionable information for security-related 
purposes, such as threat and incident detection, forensic analysis or compliance purposes. 
• are covered only within the product context described in clause 4. 
The present document covers those products for the purpose of demonstrating compliance with the essential 
cybersecurity requirements of Regulation (EU) 2024/2847 [i.1] Annex I, Part I under the conditions identified in 
Annex A. 
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the 
present document, see prEN 50770 series [i.5]. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Oct 2026
View moreView less
 

1.1 
General 
The present document specifies technical requirements and corresponding assessment criteria for operating systems 
related to cybersecurity. The products with digital elements in scope, thereafter "the operating system": 
• are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by 
the Commission Implementing Regulation (EU) 2025/2392 [i.2] as: 
"software products with digital elements that provide an abstract interface of the underlying hardware and 
control the execution of software, and that may provide services such as computing resource management and 
configuration, scheduling, input-output control, managing data, and providing an interface through which 
applications interact with system resources and peripherals. This category includes but is not limited to real
time operating systems, general-purpose and special-purpose operating systems". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A. 
The use of harmonised standards is voluntary. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 09 Oct 2026
View moreView less
 

The present document specifies PAdES digital signatures. PAdES signatures build on PDF signature mechanisms 
defined in the ISO 32000 series. For documents conforming to ISO 32000-1 [1] PAdES utilizes an extended, alternative 
signature encoding. For documents conforming to ISO 32000-2 [9], these signature structures are incorporated natively 
by default within the core standard. Both approaches support digital signature formats equivalent to the signature format 
CAdES as specified in ETSI EN 319 122-1 [2], by incorporation of signed and unsigned attributes, which fulfil certain 
common requirements (such as the long term validity of digital signatures) in a number of use cases. 
The present document specifies formats for PAdES baseline signatures, which provide the basic features necessary for a 
wide range of business and governmental use cases for electronic procedures and communications to be applicable to a 
wide range of communities when there is a clear need for interoperability of digital signatures used in electronic 
documents. 
The present document defines four levels of PAdES baseline signatures addressing incremental requirements to 
maintain the validity of the signatures over the long term, in a way that a certain level always addresses all the 
requirements addressed at levels that are below it. Each level requires the presence of certain PAdES attributes, suitably 
profiled for reducing the optionality as much as possible. 
Procedures for creation, augmentation, and validation of PAdES digital signatures are out of scope and specified in 
ETSI EN 319 102-1 [10]. Guidance on creation, augmentation and validation of PAdES digital signatures including the 
usage of the different attributes defined in the present document is provided in ETSI TR 119 100 [i.4]. The present 
document aims at supporting electronic signatures in different regulatory frameworks. 
NOTE: Specifically but not exclusively, PAdES digital signatures specified in the present document aim at 
supporting electronic signatures, advanced electronic signatures, qualified electronic signatures, 
electronic seals, advanced electronic seals, and qualified electronic seals as per Regulation (EU) 
No 910/2014 [i.2].