@@ -241,19 +241,70 @@ based on Electronic Ledgers" - V1.1.1, October 2025
## 3.1 Terms
For the purposes of the present document, the [following] terms [given in ... and the following] apply:
| Term | Definition |
|--------------|-------------------------|
|PKI Software| Software implementing the PKI services, including, Registration, Certificate generation, Dissemination, Revocation management, Certificate status, Logging of security events, User accounts management.|
|Certificate| Public key of a user, together with some other information, rendered un-forgeable by encipherment with the private key of the certification authority which issued it. |
|Certificate Policy (CP) | Named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements. |
|Certificate Revocation List (CRL) | signed list indicating a set of certificates that have been revoked by the certificate issuer.|
|Certification Authority (CA) | Authority trusted by one or more users to create and assign certificates.|
| Digital signature | Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery e.g. by the recipient.|
|Registration Authority (RA) | entity that is responsible for identification and authentication of subjects of certificates mainly|
|Secure cryptographic device| Device which holds the user's private key, protects this key against compromise and performs signing or decryption functions on behalf of the user.|
|Critical entities | Critical entities as defined by Directive (EU) 2022/2557;|
For the purposes of the present document, the terms given in Regulation (EU) 2024/2847 [i.1](#_ref_i.1), CEN/CLC JT013095:2026 (CEN/CLC prEN 40000‑1‑1) [i.4](#_ref_i.4) and the following apply:
<tdstyle="border: none;">Product with Digital Elements in the scope of the present document
</td>
</tr>
<tr>
<tdstyle="border: none;">PKI Software</td>
<tdstyle="border: none;">Software implementing the PKI services, including, Registration, Certificate generation, Dissemination, Revocation management, Certificate status, Logging of security events, User accounts management.
</td>
</tr>
<tr>
<tdstyle="border: none;">Certificate</td>
<tdstyle="border: none;">Public key of a user, together with some other information, rendered un-forgeable by encipherment with the private key of the certification authority which issued it.
<tdstyle="border: none;">Named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements.
</td>
</tr>
<tr>
<tdstyle="border: none;">Certificate Revocation List (CRL)</td>
<tdstyle="border: none;">Signed list indicating a set of certificates that have been revoked by the certificate issuer.
<tdstyle="border: none;">Authority trusted by one or more users to create and assign certificates.
</td>
</tr>
<tr>
<tdstyle="border: none;">Digital signature</td>
<tdstyle="border: none;">Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery e.g. by the recipient.
<tdstyle="border: none;">device Device which holds the user's private key, protects this key against compromise and performs signing or decryption functions on behalf of the user.
</td>
</tr>
<tr>
<tdstyle="border: none;">Critical entities</td>
<tdstyle="border: none;">Critical entities as defined by Directive (EU) 2022/2557;
- All requirements in clause 5 including conformity requirement to ETSI EN 319 411-1 [\[7\]](#_ref_7) shall ensure conformity based on tests demonstrating equivalence to in ETSI TR 119 411-4 V1.2.1 [\[i.5\]](#_ref_i.5).
- VERDICT & EVIDENCES: As defined or demonstrated equivalent to ETSI TS 103 525-2 [\[i.4\]](#_ref_i.4) and ETSI TR 119 411-4 V1.2.1 [\[i.5\]](#_ref_i.5)
# Annex A Mapping with essential requirements of the CRA
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 – the Cyber Resilience Act
The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.1\]](#_ref_i.1) to provide, in additions to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2), conformance with the normative clauses of the present document given in the tables in Annex A confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
|No |Description|Clause(s) of the present document |
<divalign="center">
**Table A.1: Relationship between the present document the requirements of Regulation (EU) 2024/2847 – the Cyber Resilience Act**
</br>
> NOTE 1: The table cannot indicate direct relationship between the relevant legal requirement and other standards or normative clauses contained in other standards.
> NOTE 2: If the standard is developed according to the structure in the present skeleton document, then the number of the clauses in the table below don’t need to be changed.
> NOTE 3: The last two columns shall be either filled with details and the reference of the table(s) mapping the applicability of the technical cybersecurity requirements, or deleted all together.
</div>
|No |Description |Requirements of Regulation |Clause(s) of the present document |U/C |Condition |
|---|---|---|---|---|---|
|1| Annex I, Part 1, (1)|“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.” | Clause 5 | C | See mapping table on the applicability of the technical cybersecurity requirements in clause 5.1|
|2|Annex I, Part 1, (2)(a)|“Products with digital elements shall be made available on the market without known exploitable vulnerabilities.”|Clause 5.2|U/C| |
|3| Annex I, Part 1, (2)(b)| “Products with digital elements shall be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state.”| Clause 5.3| U/C| |
|4| Annex I, Part 1, (2)(c)| “Products with digital elements shall ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them”| Clause 5.4| U/C| |
|5| Annex I, Part 1, (2)(d)| “Products with digital elements shall ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access”| Clause 5.5 | U/C | |
|6| Annex I, Part 1, (2)(e)| “Products with digital elements shall protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by best practice mechanisms, and by using other technical means.”| Clause 5.6 | U/C | |
|7| Annex I, Part 1, (2)(f)| “Products with digital elements shall protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions.” | Clause 5.7 | U/C | |
|8| Annex I, Part 1, (2)(g)| “Products with digital elements shall process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation).”| Clause 5.8| U/C | |
|9| Annex I, Part 1, (2)(h)| “Products with digital elements shall protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks.”| Clause 5.9| U/C| |
|10| Annex I, Part 1, (2)(i)| “Products with digital elements shall minimise the negative impact by the products themselves or connected products on the availability of services provided by other products or networks.” | Clause 5.10 | U/C | |
|11| Annex I, Part 1, (2)(j)| “Products with digital elements shall be designed, developed and produced to limit attack surfaces, including external interfaces.”| Clause 5.11 | U/C | |
|12| Annex I, Part 1, (2)(k)| “Products with digital elements shall be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques.”| Clause 5.12 | U/C | |
|13| Annex I, Part 1, (2)(l)| “Products with digital elements shall provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user.”| Clause 5.13 | U/C | |
|14| Annex I, Part 1, (2)(m)| “Products with digital elements shall provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.”| Clause 5.14 | U/C | |
|15| Annex I, Part 2| |Clause 5.15 | U | |
**Key to columns:**
**Requirement:**
**No** A unique identifier for one row of the table which may be used to identify a requirement.
**Description** A textual reference to the requirement.
**Requirements of Regulation** Identification of article(s) defining the requirement in the Regulation.
**Clause(s) of the present document** Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.
**Requirement Conditionality:**
**U/C** Indicates whether the requirement is unconditionally applicable (U) or is conditional upon the manufacturer's claimed functionality of the equipment (C).
**Condition** Explains the conditions when the requirement is or is not applicable for a requirement which is classified "conditional".
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.
# Annex B (informative): Cybersecurity threat landscape, risk identification and assessment methodology
This Annex applies a “state of the art” risk assessment methodology to the Product in scope of the present document, to identify threats, evaluate the risks and define security profiles applicable to the different use cases of the product context.
The general approach in the present document is taken from ETSI TS 102 165-1 [] (the TVRA method) with some refinements for the specific product.
## B.1 Risk calculation
Risk is calculated as the product of impact and likelihood. The metrics are derived from those given in clauses 5a and 6 of ETSI TS 102 165-1 [] modified as shown in tables B.1, B.2 and B.3 below.
In assessing impact reasonable consideration has to be made for the use case in which the product is deployed which should include assessment of the following factors and as these are dependent on the specific use case the mitigations primarily consider limiting the likelihood of an attack:
- Deployment factors
- Network security factors
- User Expertise
- Operational security procedures
- Interfaces exposure
<divalign="center">
**Table B.1: Impact metric for use in risk calculation modified from Table 3 of TS 102 165-1 []**
</br>
| Impact | Explanation | Value |
|---|---|---|
|(1)| identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products;| 6.1
|(2)| in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; | 6.1
|(3)| Apply effective and regular tests and reviews of the security of the product with digital elements; | 6.1
|(4)| Donce a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch; | 6.1
|(5)| Put in place and enforce a policy on coordinated vulnerability disclosure; | 6.1
|(6)| Take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements; | 6.1
|(7)| Provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner; | 6.1
|(8)| Ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.| 6.1
| Low | The concerned party is not harmed very strongly; the possible damage is low. For the product this is modified to mean "negligible impact to the organisation" | 1 |
| Medium |The threat addresses the interests of providers/subscribers and cannot be neglected. For the product this is modified to mean "significant impact to the organisation, negligible impact to the sector"| 2 |
|High| A basis of business is threatened and severe damage might occur in this context. For the product this is modified to mean "Severe impact to the organisation, significant impact to the sector" | 3 |
</div>
| No | Description | Clause(s) of the present document |
| (1) | Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. | Annex C |
| (2)(a) | Be made available on the market without known exploitable vulnerabilities. |6.1|
| (2)(b) | Be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state;|5|
| (2)(c) | Ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them; | 6.1|
| (2)(d) | Ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access; | 5.1, 5.3, 6.2 & 6.4|
| (2)(e) | Protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means;| 5.2, 6.2 & 6.3|
| (2)(f) | Protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions;| 5.1, 5.2, 5.3, 5.4, 5.7, 5.9 |
| (2)(g) | Process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation);| 5 |
| (2)(h) | Protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks;| 5.1, 6.2 & 6.3 |
| (2)(i) | Minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks; | 5 & 6 |
| (2)(j) | Be designed, developed and produced to limit attack surfaces, including external interfaces; | 5, 6 & Annex B |
| (2)(k) | Be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques; | 5, 6 & Annex B |
| (2)(l) | Provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user; | 5.1 & 6.2 |
| (2)(m) | Provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.|5.8|
The core technical metrics for determination of the likelihood of a particular cyber-attack are defined in clause B.6 of the Common Criteria Evaluation methodology [] and further developed in clause 6.7 of TS §102 165-1 [] and then updated as shown in table B.2 of the present document. As identified in both the Common Criteria Evaluation methodology [] and in TS 102 165-1 [] an assessment of the likelihood of an attack is assessed from evaluation of a number of attributes of the attack and attacker including Time, Expertise, Knowledge, Opportunity, Equipment and motivation.
Key to columns:
Requirement:
<divalign="center">
No A unique identifier for one row of the table which may be used to identify a requirement.
Description A textual reference to the requirement.
**Table B.2: likelihood metric for use in risk calculation modified from table 4 of TS 102 165-1 []**
</br>
Requirements of Regulation
- Identification of article(s) defining the requirement in the Regulation.
Clause(s) of the present document
- Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.
Requirement Conditionality:
- U/C Indicates whether the requirement is unconditionally applicable (U) or is conditional upon the manufacturer's claimed functionality of the equipment (C). Condition Explains the conditions when the requirement is or is not applicable for a requirement which is classified "conditional".
| Value | Likelihood of occurrence | Modified likelihood | Explanation |
|---|---|---|---|
|1 (note)| Very unlikely to | Low | According to up-to-date knowledge, there are no means of solving the technical difficulties to state the threat irrespective of the motivation or resources available to the attacker. |
|1| Unlikely to succeed | Low | According to up-to-date knowledge, a possible attacker needs to solve strong technical difficulties to state the threat or the motivation for an attacker is very low. |
|2| Possible (could succeed) | Medium | The technical requirements necessary to state this threat are not high and could be solved without significant effort; furthermore, there is a reasonable motivation for an attacker to perform the threat. |
|3| Likely to succeed | High | There are no sufficient mechanisms installed to counteract this threat and the motivation for an attacker is quite high. |
|3 (note)| Very likely to succeed | High | As for very likely but the threat is considered more imminent. |
|NOTE: The values assigned to "Very unlikely" and "Unlikely" are identical, similarly the values assigned to "Likely" and "Very likely" are identical. The rationale is that they represent extreme poles but, in each case, do not equate to risk escalation.|
# Annex B Mappings
## B.1 Mapping of threats to technical security requirements and their associated assessment requirements
</div>

Mitigations often concentrate on minimising the likelihood of a successful attack by strategies including attack surface minimisation, data minimisation and general strategies of least privilege access to product functionality.
**Figure B.1-1: Mapping of threats to technical and assessement requirement part 1**
Risk, as per TS 102 165-1 [] is calculated as the product of impact and likelihood and shown in Table B.3.

<divalign="center">
**Figure B.1-2: Mapping of threats to technical and assessement requirement part 2**
**Table B.3: Risk as product of likelihood and impact from TS 102 165-1 []**
</br>
| Value | Risk | Explanation |
|---|---|---|
| 1, 2 | Minor | No essential assets are concerned, or the attack is unlikely. Threats causing minor risks have no primary need for counter measures. |
| 3, 4 | Major | Threats on relevant assets are likely to occur although their impact is unlikely to be fatal. Major risks should be handled seriously and should be minimized by the appropriate use of countermeasures. |
| 6, 9 | Critical | The primary interests of the providers and/or subscribers are threatened and the effort required from a potential attacker's to implement the threat(s) is not high. Critical risks should be minimized with highest priority. |
</div>
> NOTE: Because risk is calculated as the product of likelihood and impact the values 5, 7 and 8 cannot occur.

**Figure B.1-3: Mapping of threats to technical and assessement requirement part 3**

**Figure B.1-4: Mapping of threats to technical and assessement requirement part 4**
## B.2 Risk Assessment
# Annex C Risk acceptance criteria and risk management methodology (informative) (PT1 6.3)
## B.3 Impact risk factors
## B.2 Evaluate Risks
# Annex C (Informative) Relationship between the present document and any related ETSI standards (if any, e.g. EN 303 645)
Add reference to mappings for eIDAS and C-ITS from each of ETSI TC ESI and ETSI TC ITS (WG5)