Draft Details

Number:Draft ETSI EN 304 622 V1.0.0 (2026-08)
Source:NSAI
Committee:NSAI/TC 2
Committee name:ICT
Review published:24 Aug 2026
Review end date:05 Oct 2026
Categories:General
Contact email:nepadmin(at)nsai.ie
Draft Scope:

The present document specifies technical requirements and corresponding assessment criteria for Security Information 
and Event Management related to cybersecurity. 
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems": 
• are specified within the "technical description" of the "category of product" number 7 by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: Products with digital elements that collect data from 
multiple sources, analyse and correlate that data and present it as actionable information for security-related 
purposes, such as threat and incident detection, forensic analysis or compliance purposes. 
• are covered only within the product context described in clause 4. 
The present document covers those products for the purpose of demonstrating compliance with the essential 
cybersecurity requirements of Regulation (EU) 2024/2847 [i.1] Annex I, Part I under the conditions identified in 
Annex A. 
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the 
present document, see prEN 50770 series [i.5]. 

You may comment on any clause of this document. Simply enter the clause number, make your comment and your proposed changed text for each clause, subclause, paragraph, table or figure.

All comments are checked by a moderator before they are made public on the site. This is to ensure that improper language or marketing is not placed on the site – we will not judge or modify technical content. Similarly, we will not correct your grammar or spelling