Main Categories
- +Signs, Symbols and Product Specifications (2)
- +Information management (3)
- +Business (4)
- +Services (1)
- +Measurement and Science (11)
- +Healthcare (24)
- +Environment (11)
- +Health and Safety (11)
- +Engineering (57)
- +ICT (17)
- +Manufacturing (45)
- +Agriculture and Food (6)
- +Construction (21)
- +Commercial and Consumer Goods (26)
- General (30)
The present document specifies technical requirements and corresponding assessment criteria for software products
with digital elements that detect or search for malicious software or code on a device, or remove or quarantine such
software or code to prevent or mitigate system infection related to cybersecurity. The products with digital elements in
scope, thereafter "the product":
• are specified within the "technical description" of the "category of product" number "4" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: -
"Software products with digital elements, typically referred to as antivirus or antimalware, that detect or
search for malicious software or code on devices, or remove or quarantine such software or code, in
order to maintain the integrity, confidentiality, or availability of such devices.
In the context of this category of products, malicious software means software containing malicious
features or capabilities that can cause harm directly or indirectly to the user and/or the computer system,
such as viruses, worms, ransomware, spyware and trojans.
This category includes but is not limited to software that detects or searches for malicious software in
real-time or manually, rootkit detection and rescue disks with the core functionality of searching,
removing or quarantining malicious software."
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A.
The present document specifies technical characteristics and methods of assessment for Antivirus/Antimalware
products.
The present document specifies vulnerability handling activities, technical requirements and corresponding assessment
criteria for smart home general purpose virtual assistants related to cybersecurity. The products with digital elements in
scope, thereafter "smart home general purpose virtual assistants":
• are specified within the "technical description" of the "category of product" number "16." by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements that communicate on the public Internet, whether directly or via other
equipment, that process demands, tasks or questions based on natural language prompts, such as through audio
or written input, and that, based on those demands, tasks or questions, provide access to other services or
control the functions of connected devices in residential settings.
This category includes but is not limited to smart speakers with an integrated virtual assistant, and standalone
virtual assistants that meet this description"; and
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A