Title:Cybersecurity (CYBER); CRA; Cybersecurity requirements for network management systems
Spec Number:304 621
Version:v0.2.4
Date:2026-07-08
Release:5
Version:v1.0.0
Date:2026-07-20
Release:1
Work Item:DEN/CYBER-EUS-009
keywords:CRA, Cybersecurity, Network
Copyright Year:2026
@@ -96,7 +96,7 @@ The present document covers those products to demonstrate compliance with essent
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking , e.g when an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI).
NMS intended for use in the industrial OT (Operational Technology) domain are excluded from the scope of the present document.
NMS intended for use in the industrial OT (Operational Technology)[\[i.18\]](#_ref_i.18) domain are excluded from the scope of the present document.
# 2 References
@@ -150,7 +150,7 @@ The following referenced documents may be useful in implementing an ETSI deliver
<spanid="_ref_i.14"></span><aname="_ref_i.14">[i.14]</a> ETSI EN 304 622 "Essential cybersecurity requirements for Security information and event management (SIEM) systems"
<spanid="_ref_i.15"></span><aname="_ref_i.15">[i.15]</a> EN 304 626 "Operating systems"
<spanid="_ref_i.15"></span><aname="_ref_i.15">[i.15]</a>ETSI EN 304 626 "Operating systems"
<spanid="_ref_i.16"></span><aname="_ref_i.16">[i.16]</a> ETSI EN 304 627 "Router, modems and switches"
@@ -158,6 +158,8 @@ The following referenced documents may be useful in implementing an ETSI deliver
<spanid="_ref_i.18"></span><aname="_ref_i.18">[i.18]</a> Example source for DDoS related threat reports https://radar.cloudflare.com/reports
<spanid="_ref_i.19"></span><aname="_ref_i.19">[i.19]</a> prEN 50770 series: "Security for operational technologies" (produced by CENELEC).
# 3 Definition of terms, symbols and abbreviations
## 3.1 Terms
@@ -756,7 +758,7 @@ The applicability of the supplementary requirements specified in Annex R should
The following functionalities can be implemented as part of the product or addressed as RDPS:
*From external provided updates on secured channels that the product uses to update the managed elements and also itself.
***Product update channels** that external provided updates on secured channels that the product uses to update the managed elements and also itself.
***Identity management systems** that provide mechanisms for identification and authentication. The system can include also the lifecycle management of identity credentials [\[i.2\]](#_ref_i.2)
***Provision of cryptographic keys** coming from a public key infrastructure or other key management system for services of key generation, provision, establishment, and for certificate services such as generation, signing, verification, validation or withdrawal. [\[i.11\]](#_ref_i.11)
***Processing of monitoring data** that filters, aggregates and transforms metrics, logs, events, traces and provides administrative visibility to the system operation.
@@ -4589,6 +4591,17 @@ The product risk levels scales with **RF_CRITICAL** and the product needs to be
When determining the risk level, a high water mark defines the applicable requirements.
# Annex C (informative): Relationship between the present document and any related ETSI standards (if any, e.g. EN 303 645)
ETSI Standards referenced by this document:
* ETSI EN 304 624 "PKIs and certificate issuance software" [\[i.11\]](#_ref_i.11)
* ETSI EN 304 620 "Virtual Private Networks (VPNs)" [\[i.12\]](#_ref_i.12)
* ETSI EN 304 622 "Essential cybersecurity requirements for Security information and event management (SIEM) systems" [\[i.14\]](#_ref_i.14)
* ETSI EN 304 626 "Operating systems" [\[i.15\]](#_ref_i.15)
* ETSI EN 304 627 "Router, modems and switches" [\[i.16\]](#_ref_i.16)
* ETSI EN 304 642 "Cybersecurity Requirements for Telecommunication Systems" [\[i.17\]](#_ref_i.17)
# Annex K (normative): Generic cryptographic requirements and assessment
::include{file=EN-304-621_AnnexK.md}
@@ -4596,3 +4609,14 @@ When determining the risk level, a high water mark defines the applicable requir
# Annex R (normative): Additional provisions for products relying on remote data processing solutions (RDPS)