Verified Commit 1526612a authored by Aki Braun's avatar Aki Braun
Browse files

Edits from Laure's review of the document

parent b73143e0
Loading
Loading
Loading
Loading
+64 −29
Original line number Diff line number Diff line
@@ -115,13 +115,17 @@ The present document may include trademarks and/or tradenames which are asserted

This draft Harmonised European Standard (EN) has been produced by ETSI Technical Committee Cyber Working Group for EUSR (CYBER-EUSR), and is now submitted for the combined Public Enquiry and Vote phase of the ETSI Standardisation Request deliverable Approval Procedure (SRdAP).

```
The present document has been prepared under the Commission's standardisation request C(2025) 618 final to provide one voluntary means of conforming to the requirements of Regulation (EU) No 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).
```

Once the present document is cited in the Official Journal of the European Union under that Regulation, compliance with the normative clauses of the present document given in table A.1 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding requirements of that Regulation and associated EFTA regulations.

Transposition table
The present document is part 1 of a multi-part deliverable covering Cyber Security (CYBER); Essential cybersecurity requirements for products with digital elements with the function of virtual private networks (VPN)

Part 1: VPNs for secure remote access to private networks

Part 2: VPN services for private routing to public networks 

## Transposition table

The Harmonised Standard shall have appropriate transposition periods specified. A Harmonised Standard confers presumption of conformity when it has been published in the Official Journal of the European Union (OJEU) and transposed by a member state.

@@ -150,9 +154,9 @@ The purpose of this document is to provide essential cybersecurity requirements

# Introduction

The present document is a European harmonised standard that defines cybersecurity requirements for products with digital elements whose primary purpose is connecting private networks with public networks or other private networks. Demonstrating compliance with this standard is not necessary, but doing so provides a presumption of conformity with Regulation (EU) 2024/2847, the Cyber Resilience Act <a href="#_ref_i.1">[i.1]</a>.
The present document defines cybersecurity requirements for products with digital elements whose primary purpose is connecting private networks with public networks or other private networks. Demonstrating compliance with this standard is voluntary, but doing so provides a presumption of conformity with Regulation (EU) 2024/2847, the Cyber Resilience Act <a href="#_ref_i.1">[i.1]</a>.

This standard does not apply to products that have VPN capabilities as a feature of a broader holistic networking or security product, though it may be useful as one part of the process of demonstrating compliance for a product containing or interacting with VPNs.
This standard does not provide presumption of conformity for products with digital elements with have a VPN feature as part of a larger networking or security product, though it may be useful as one part of the process of demonstrating compliance for a product containing or interacting with VPNs.

# 1 Scope

@@ -167,8 +171,6 @@ This includes products whose use cases are focused on enterprise workforce deplo
1. Software for managing the configuration of the VPN and its end-points, including authentication
1. Remote data processing for services associated with enterprise VPNs

This standard explicitly excludes VPNs used in the industrial OT domain, as mentioned in CRA Annex III Class I important products, which are covered in EN 62443-5-XX.

## 1.2 Products in scope

The scope of this standard covers products intended for enterprise, business, or institutional use cases, specifically for remote workforce access or secure network-to-network connections. It applies to both standalone products and those that are part of a larger security platform.
@@ -182,10 +184,10 @@ This includes:
- Remote Data Processing:
  - Cloud-based services or remote data processing solutions that are essential for the operation of an enterprise VPN, such as authentication services, policy enforcement, and management portals.

This part of the standard explicitly excludes consumer VPN services and VPNs used in the industrial OT domain.

## 1.3 Products not in scope

This part of the standard explicitly excludes consumer VPN services and VPNs used in the industrial OT domain.

This list clarifies products whose functionality might be confused with the in-scope products of this standard, but which are excluded due to their primary purpose or operational environment. This standard does not cover products in use in contexts other than those identified in Annex &lt;L>.

- Consumer VPN services: Products with an intended purpose of providing a VPN for a single user or home network to connect to a public network are not in the scope of this standard, as they are covered in a separate document.
@@ -237,8 +239,9 @@ The following referenced documents may be useful in implementing an ETSI deliver

* <a name="_ref_i.1">[i.1]</a>    Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
* <a name="_ref_i.2">[i.2]</a>    Commission Implementing Regulation (EU) TK TODO on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council (Text with EEA relevance)
* <a name="_ref_i.4">[i.3]</a>    Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (Text with EEA relevance) (notified under document number C(2003) 1422)
* <a name="_ref_i.4">[i.4]</a>    Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)
* <a name="_ref_i.3">[i.3]</a>    C(2025)618 – Standardisation request M/606: Commission Implementing decision of 3.2.2025 on a standardisation request to the European Committee for Standardisation (CEN), the European Committee for Electrotechnical Standardisation (Cenelec) and the European Telecommunications Standards Institute (ETSI) as regards products with digital elements in support of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020and Directive (EU) 2020/1828 (Cyber Resilience Act)
* <a name="_ref_i.4">[i.4]</a>    Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (Text with EEA relevance) (notified under document number C(2003) 1422)
* <a name="_ref_i.5">[i.5]</a>    Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)

[References]: https://portal.etsi.org/Portals/0/TBpages/edithelp/Docs/News_from_editHelp/References_in_ETSI_deliverables.pdf

@@ -248,39 +251,67 @@ The following referenced documents may be useful in implementing an ETSI deliver

This section provides terms and definitions based on CEN/CLC JTC13 WG09's work on terms and definitions, terms and definitions provided by ETSI EN 303 645/TS 103 701 and terms and definitions provided by CEN/CLC EN 18031 series.

For the purposes of the present document, the terms given in [i.3], and the following apply:
For the purposes of the present document, the terms given in [i.1], [i.4], and the following apply:

product with digital elements
: software or hardware product and its remote data processing solutions (including software or hardware components being placed on the market separately)

virtual private network
: product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network

'product with digital elements' (aka "product") means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;
> [!note]
> This includes cases where that product provides access from a restricted-use logical computer network to the public internet.

'virtual private network' means products with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where that product provides access from a restricted-use logical computer network to the public internet.
remote data processing
: data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer

'remote data processing' means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions;
> [!note]
> This specifically refers to processing the absence of which would prevent the product with digital elements from performing one of its functions.

'cybersecurity' means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881 [i4];
cybersecurity
: cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881 [i5]

'software' means the part of an electronic information system which consists of computer code;
software
: part of an electronic information system which consists of computer code

'hardware' means a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data;
hardware
: physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data

'logical connection' means a virtual representation of a data connection implemented through a software interface;
logical connection
: virtual representation of a data connection implemented through a software interface

'physical connection' means a connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves;
physical connection
: connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves

'indirect connection' means a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network;
indirect connection
: connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network

'end-point' means any device that is connected to a network and serves as an entry point to that network;
end-point
: any device that is connected to a network and serves as an entry point to that network

'consumer' means a natural person who acts for purposes which are outside that person's trade, business, craft or profession;
consumer
: a natural person who acts for purposes which are outside that person's trade, business, craft or profession

'making available on the market' means the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
making available on the market
: the supply of a product with digital elements for distribution or use on the European Union single market in the course of a commercial activity, whether in return for payment or free of charge

'intended purpose' means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;
intended purpose
: the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use

'software bill of materials' means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;
> [!note]
> An intended purposes is what is specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.

'on-premises infrastructure' means the collection of servers, switches, and other hardware used to connect company-owned resources to internal and external networks. Unless specified otherwise, applies to equipment located within a corporate campus, inside of a multi-tenant data centre, inside of a single tenant data centre, or any combination of the three.
software bill of materials
: formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements

'cloud' means a data centre or collection of data centres operated entirely by a third party which rents out space and time on their equipment, as well as providing services for managing infrastructure from outside networks.
on-premises infrastructure
: collection of servers, switches, and other hardware used to connect company-owned resources to internal and external networks

> [!note]
> Unless specified otherwise, on-premises infrastructure designates equipment located within a corporate campus, inside of a multi-tenant data centre, inside of a single tenant data centre, or any combination of the three.

cloud
: data centre or collection of data centres operated entirely by a third party which rents out space and time on their equipment, as well as providing services for managing infrastructure from outside networks

## 3.2 Abbreviations

@@ -291,6 +322,8 @@ For the purposes of the present document, the following abbreviations apply:
| CRA          | Cyber Resilience Act         |
| VPN          | Virtual Private Network      |
| PwDE         | Product with Digital Element |
| DNS          | Domain Name Server           |
| SBOM         | Software Bill of Materials   |

# 4 Product context

@@ -317,7 +350,9 @@ The following types of products have reduced or varied requirements under Regula

### 4.2.1 Product overview

As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel on two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.
For the purpose of this document, a VPN is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where that product provides access from a restricted-use logical computer network to a public network.

As a holistic product, a Virtual Private Network includes, at minimum, VPN software capable of establishing a secure encrypted tunnel between two or more devices. VPN products also provide management capabilities to network administrators: user and group management, access control, logging and monitoring.

![A diagram illustrating an offsite device using a VPN client to encrypt traffic and send it through a public network, to a VPN server which decrypts the traffic.](./media/VPN%20diagrams.svg)