General
The present document specifies the accessibility requirements applicable to ICT products and services, together with a
description of the test procedures and evaluation methodology for each accessibility requirement.
The present document is intended for use by designers, developers, evaluators, manufacturers, market surveillance
entities, procurers, researchers, and anyone else interested in the accessibility of ICT products and services.
The present document is not intended to apply to assistive technologies that are designed specifically for use by people
with disabilities, except for requirement 11.5.2.4 that requires assistive technologies to use the documented platform
accessibility services, although making assistive technologies usable and applicable for people with multiple disabilities
is desirable. The requirements do apply to the launch of assistive technologies since that is a function of the platform,
not the assistive technology.
The present document supports the implementation of Directive (EU) 2016/2102 on the accessibility of the websites
and mobile applications of public sector bodies [i.27], and of Directive (EU) 2019/882 on the accessibility of ICT
products and services [i.29]. The coverage of the essential requirements of these Directives is given in Annexes ZA and
ZB.
The present document contains the necessary accessibility requirements and provides a reference document such that if
procedures are followed by different actors, the results of testing are similar and the interpretation of those results is
clear. The test descriptions and evaluation methodology included in the present document are elaborated to a level of
detail compliant with ISO/IEC 17007:2009 [i.14], so that conformance testing can give conclusive results.
The present document defines Product Specific Requirements for Life Cycle Assessment (LCA) of Smartphones so that
it is possible to compare the LCA between different smartphone models on SKU level (e.g. considering different
memory configurations). The present document provides a methodology for evaluating the environmental impact of
smartphones objectively and transparently and is based upon the Life Cycle Assessment (LCA) framework standardized
in ETSI ES 203 199 [1] and IEC 63366 [i.1]. The purpose of the present document is to:
• Provide smartphone-specific requirements, i.e. Product Specific Rules (PSR), in addition to those of ETSI
ES 203 199 [1] and IEC 63366 [i.1] to ensure comparability of LCA studies of smartphones on SKU level.
• Harmonize the LCAs of smartphones.
• Increase the transparency and facilitate the interpretation of LCA studies of smartphones.
• Facilitate the communication of LCA studies of smartphones on SKU level.
The present document is valid for all types of smartphones. Moreover, the present document defines a set of
requirements for which the LCA practitioners will comply. Comparisons of results from LCA studies of smartphones
which belong to the same product family, including assessments which have been performed by different organizations,
are within the scope of the present document.
The present document specifies the Service Information (SI) data which forms a part of Digital Video Broadcasting
(DVB) bitstreams, in order that the user can be provided with information to assist in selection of services and/or events
within the bitstream, and so that the Integrated Receiver Decoder (IRD) can automatically configure itself for the
selected service. SI data for automatic configuration is mostly specified within ISO/IEC 13818-1 [1] as Program
Specific Information (PSI).
The present document specifies additional data which complements the PSI by providing data to aid automatic tuning of
IRDs, and additional information intended for display to the user. The manner of presentation of the information is not
specified in the present document, and IRD manufacturers have freedom to choose appropriate presentation methods.
It is expected that Electronic Programme Guide (EPG) will be a feature of Digital TeleVision (TV) transmissions.
The definition of an EPG is outside the scope of the present document (i.e. the SI specification), but the data contained
within the SI specified in the present document may be used as the basis for an EPG.
Rules of operation for the implementation of the present document are specified in ETSI TS 101 211 [i.1].
The present document covers the assessment of VHF radiotelephone transmitters and receivers for the maritime mobile
service operating in the frequency range 156 MHz to 174 MHz, and ancillary equipment in respect of ElectroMagnetic
Compatibility (EMC) intended to be used in a marine environment.
Technical specifications related to the antenna port and emissions from the enclosure port of marine radiotelephone
transmitters and receivers are not included in the present document. Such technical specifications are found in the
related product standards for the effective use of the radio spectrum.
The present document specifies the applicable test conditions, performance assessment, and performance criteria for
VHF radiotelephone transmitters and receivers for the maritime mobile service, and associated ancillary equipment.
NOTE: The relationship between the present document and essential requirements of article 3.1b of
Directive 2014/53/EU [i.2] is given in annex A.
The present document specifies technical cybersecurity product requirements and corresponding assessment criteria for
boot managers. The products with digital elements in scope, there after "the products":
• are specified within the technical description of the category of product number 8 by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: -
"Software products with digital elements that manage the process of initial system startup after power
on/restart by initialising hardware, loading or transferring control to the operating system environment or
system resources, and selecting boot options. This category includes but is not limited to UEFI firmware,
single-stage and multi-stage boot loaders."
• are only covered within the product context described in clause 4.
The scope covers software and firmware components that manage the boot process from power-on through
establishment of the chain of trust to handoff to the boot target. Products in scope include boot management software
and firmware regardless of distribution model or integration level. These are:
• System firmware that performs hardware initialisation and boot management.
• Bootloaders that manage boot target selection, verification, and loading.
• Embedded boot firmware in IoT and embedded devices.
• Network boot implementations enabling remote boot capabilities.
• Boot managers that integrate with hardware security components for chain of trust establishment.
NOTE 1: Boot managers may be single-stage (direct loading) or multi-stage (staged verification).
NOTE 2: For microcontrollers (MCUs) and microprocessors (MPUs):
• Silicon-integrated immutable firmware: Mask ROM, fused code, or boot firmware integrated during chip
manufacturing is assessed as part of MCU/MPU hardware under semiconductor standards.
• Updateable boot managers: Boot software in flash storage (including OTP programmed post-manufacture) is
assessed using the present document when distinctly identifiable or independently updatable.
NOTE 3: Runtime services executing after boot target handoff (such as secure monitor mode handlers or attestation
services) are in scope only if they provide verification or attestation services to the boot process itself, not
to the boot target.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I Part I under the conditions identified in Annex A.
The present document specifies technical requirements and corresponding assessment criteria for Virtualisation
Execution Stack (VES) and Container Execution Stack (CES) products, including hypervisors and container runtime
systems, related to cybersecurity. The products with digital elements in scope, thereafter referred to as the "product":
• are specified within the "technical description" of the "category of product" in Class II, point 1 by the
Commission Implementing Regulation (EU) 2025/2392 [i.2] as:
"Hypervisors and container runtime systems that support virtualised execution of operating systems and
similar environments";
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A.
Commission Implementing Regulation (EU) 2025/2392 [i.2] identifies hypervisors and container runtime systems as
core components. However, actual market products typically include additional elements beyond the hypervisor kernel
or container runtime binary. These additional components provide essential management, orchestration, and operational
capabilities that are necessary for real-world deployment and are therefore included within the scope of the present
document.
The present document addresses the CRA Class II, point 1 product category within the following product contexts:
• Virtualisation Execution Stack (VES) for hypervisor-based environments; and
• Container Execution Stack (CES) for container-based environments.
The corresponding terms and definitions are provided in clause 3. The architectural decomposition, in-scope
components, and security-relevant environmental dependencies are specified in clause 4.
Accordingly, the present document defines security requirements not only for the core execution systems identified in
the CRA but also for the broader product context in which these systems are deployed, ensuring alignment with market
reality and comprehensive coverage of security risks. The Management and Orchestration (M&O) System, Container
Engine (CE), and Container Orchestrator (CO) are covered by the present document and are in scope only where they
are developed or provided by the manufacturer, or under the responsibility of the manufacturer, as part of the declared
product.
Any usage of AI agents is out of scope of the present document.
Where the product includes or depends on components that are outside the scope of the present document, the
applicable requirements are to be addressed through the relevant operational-environment provisions or other relevant harmonised standards, as identified in clause 4.3.