Main Categories
- +Signs, Symbols and Product Specifications (1)
- +Information management (4)
- +Business (2)
- +Services (1)
- +Measurement and Science (17)
- +Healthcare (26)
- +Environment (13)
- +Health and Safety (13)
- +Engineering (92)
- +ICT (31)
- +Manufacturing (50)
- +Agriculture and Food (23)
- +Construction (44)
- +Commercial and Consumer Goods (18)
- General (41)
The present document specifies technical requirements and corresponding assessment criteria for web browsers related
to cybersecurity. The products with digital elements in scope, thereafter "the products" are specified within the
"technical description" of the "category of product" number "2" by the Commission Implementing Regulation (EU)
2025/2392 [i.2] as:
• "Software products with digital elements that enable end users to access, render, and interact with web content
and services hosted on servers that are connected to networks such as the Internet. They typically include a
browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for
web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of
temporary or persistent data from websites (cookies).
This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded
browsers intended for integration into another system or application as well as browsers with AI agent integration."
The products are only covered within the product context described in clause 4. The present document specifies
technical characteristics and methods of assessment for:
• Standalone web browsers: standalone applications that fulfil the functions of web browsers
• Embedded web browsers: embedded browsers intended for integration into another system or application
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
Browsers with AI agent integration are out of the scope of the present document as well.
The present document specifies technical requirements and corresponding assessment criteria for Virtual Private
Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs":
• are specified within the "technical description" of the "category of product" number "5" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that establish an encrypted
logical tunnel that is constructed from the system resources of a physical or virtual network".
• are only covered within the product context described in clause 4 and the text of this clause.
In particular, the present document specifies technical characteristics and methods of assessment for:
1)
2)
3)
4)
Software that operates as a VPN client or endpoint
Software that operates as a node within a mesh VPN network
Software that operates as a VPN server
Remote data processing, specifically VPN server software performing the logical server role, and associated
software used for such VPN products
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document.
VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
The present document specifies technical requirements and corresponding assessment criteria for Network Management
Systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":
• are specified within the "technical description" of the "category of product" number "6" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that manage connected
network elements, such as servers, routers, switches, workstations, printers or mobile devices, by monitoring
them and controlling their network operations and configuration".
This category includes but is not limited to end-to-end management systems and dedicated configuration
management systems, such as controllers for software-defined networking.
• The products with digital elements in scope are only covered within the product context described in clause 4
of the present document.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking, e.g when
an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI).
NMS intended for use in the industrial Operational Technology (OT) [i.18] domain are excluded from the scope of the
present document.
An NMS is a product controlling at least partially connected devices with network access. Despite its central
positioning, an NMS can be an aggregate of several components, including but not limited to: end-to-end management
systems, dedicated configuration management systems, or controllers for software-defined networking.
NMS can be composed of several components or can implement additional functions that are outside the scope of the
present document.
EXAMPLE:
Aggregate product design would be an implementation where the operating system acts as an
abstraction layer for the system(s) that host the NMS, or the networking interfaces.
The present document specifies technical requirements and corresponding assessment criteria for Security Information
and Event Management related to cybersecurity.
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems":
• are specified within the "technical description" of the "category of product" number 7 by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: Products with digital elements that collect data from
multiple sources, analyse and correlate that data and present it as actionable information for security-related
purposes, such as threat and incident detection, forensic analysis or compliance purposes.
• are covered only within the product context described in clause 4.
The present document covers those products for the purpose of demonstrating compliance with the essential
cybersecurity requirements of Regulation (EU) 2024/2847 [i.1] Annex I, Part I under the conditions identified in
Annex A.
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
1.1
General
The present document specifies technical requirements and corresponding assessment criteria for operating systems
related to cybersecurity. The products with digital elements in scope, thereafter "the operating system":
• are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by
the Commission Implementing Regulation (EU) 2025/2392 [i.2] as:
"software products with digital elements that provide an abstract interface of the underlying hardware and
control the execution of software, and that may provide services such as computing resource management and
configuration, scheduling, input-output control, managing data, and providing an interface through which
applications interact with system resources and peripherals. This category includes but is not limited to real
time operating systems, general-purpose and special-purpose operating systems".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
The use of harmonised standards is voluntary.