@@ -158,42 +158,47 @@ This standard does not apply to products that have VPN capabilities as a feature
## 1.1 General
The present document describes how to demonstrate compliance with requirements in the EU Regulation 2024/2847 under the conditions identified in Annex <L> of the following types of software:
The present document provides security requirements and assessment criteria covering all elements defined in EU Regulation 2024/2847 Cyber Resilience Act Annex I Part 1 and Part 2 for products with digital elements (products) with the intended main purpose to deploy Virtual Private Networks (VPNs) for secure remote access of an organization's workforce, or interconnect various infrastructures of those organizations through untrusted domains.
1. Software that operates as a virtual private network server, gateway, or concentrator
1. Software that operates as a virtual private network client
1. Remote data processing for services associated with virtual private networks
This includes products whose use cases are focused on enterprise workforce deployment and connecting data centers. The scope applies to:
within the context described in section 4, Product Context.
1. Software that operates as an enterprise VPN server, gateway, or concentrator
1. Software that operates as a VPN client for distributed workers
1. Hardware with the intended main purpose of providing enterprise VPN client, server or gateway functionality
1.<mark>Remote data processing for services associated with enterprise VPNs</mark>
For the purpose of this document, a virtual private network, or _VPN_, is a product with digital elements that provides access to a restricted-use logical computer network that is constructed from the system resources of a physical or virtual network, including cases where products provide access from a restricted-use logical computer network to a public network.
This standard explicitly excludes VPNs used in the industrial OT domain, as mentioned in CRA Annex III Class I important products, which are covered in EN 62443-5-XX.
## 1.2 Products in scope
> Detailed list of things that are in scope, to help manufacturers identify in-scope products. Make the scope as narrow as possible while still covering all products in the vertical. Use the latest draft of the technical descriptions to help. Technical experts are considered to be the authority for interpreting the meaning and definition of technical terms, so use your best technical judgement.
- software that establishes a tunnel between other networks
- software that establishes a tunnel between a private network and an end-point
- Software which enables end users to connect to a protected network, frequently the internal network of an enterprise
- TKTK the business/enterprise version of a consumer VPN service is in scope, bc again it generally does not protect traffic between vpn server and its final destination
The scope of this standard covers products intended for enterprise, business, or institutional use cases, specifically for remote workforce access or secure network-to-network connections. It applies to both standalone products and those that are part of a larger security platform.
## 1.3 Products not in scope
> Detailed list of things whose scope might be confusing, including parts of a system which are often included when the terms in the "in scope" section are used in general conversation. Reference the "Product Context" section again to remind the reader what operational environments are in scope.
This includes:
This standard does not cover products in use in contexts other than those identified in Annex <L>.
- Software:
- Software that operates as an enterprise-grade virtual private network server, gateway, or concentrator.
- VPN client software intended for installation on end-user devices for distributed workers connecting to a remote private network.
- Hardware:
- Commercially available hardware appliances whose intended purpose is to perform the duties of a VPN server, gateway, or concentrator for an enterprise network.
- Remote Data Processing:
- Cloud-based services or remote data processing solutions that are essential for the operation of an enterprise VPN, such as authentication services, policy enforcement, and management portals.
Products on the market which describe themselves as VPNs, but don't perform the specific listed in clause 1.2, are not VPNs for the sake of the present document.
This part of the standard explicitly excludes consumer VPN services and VPNs used in the industrial OT domain.
For example:
## 1.3 Products not in scope
- Modern enterprise software manufactured to provide network security from endpoint traffic frequently includes a feature of connecting that endpoint to a private logical network, but it is not done by establishing a secure tunnel between devices. Products offering technology like "Zero Trust Architecture" typically perform the function of a firewall, inspecting inbound traffic and sending it on or blocking it as appropriate.
- Routers, from consumer grade to enterprise may provide a VPN feature, but as part of a larger holistic product with an intended purpose of routing traffic within and between networks at the network layer.
- Network as a Service may include several features that align with Class I and II Important products within a larger holistic product, and indeed those vertical standards could prove beneficial to a service provider when assessing their conformity, but are out of scope for any one product category.
> Detailed list of things whose scope might be confusing, including parts of a system which are often included when the terms in the "in scope" section are used in general conversation. Reference the "Product Context" section again to remind the reader what operational environments are in scope.
VPN services which provide a client for a consumer to connect to a public network via servers controlled by the service provider are out of scope for the present document, they are covered by part 2 of this Standard.
This list clarifies products whose functionality might be confused with the in-scope products of this standard, but which are excluded due to their primary purpose or operational environment. This standard does not cover products in use in contexts other than those identified in Annex <L>.
Cyber Resilience Act security requirements for VPNs in the industrial OT domain are covered in EN 62443-5-XX.
- Consumer VPN services: Products with an intended purpose of providing a VPN for a single user or home network to connect to a public network are not in the scope of this standard, as they are covered in a separate document.
- VPNs for industrial OT domains: Products with digital elements intended for use in the industrial OT (Operational Technology) domain are explicitly excluded from this standard, as their security requirements are covered under a different standard (EN 62443-5-XX).
- Products with a VPN as a component: Products whose core purpose is not a VPN, but which contain VPN functionality, cannot rely on this standard alone for a presumption of conformity. This includes products like:
- Firewalls and routers. While these devices may have integrated VPN capabilities, their primary function is network traffic control, which is addressed by other standards.
- VPN services without a provided client: Commercial actors that provide a VPN service solely by giving users configuration details (e.g., an OpenVPN config file) and do not provide an associated end-user client or managed hardware are not in scope.
- Unsecured network connections: This standard does not apply to software or hardware intended to link two or more networks without implementing a secure connection.