@@ -3320,10 +3320,10 @@ For every security mechanism identified under the preceding clause, the assessor
### K.2.4 Assessment evidence
1. For each cryptographic algorithm in use, a reference to a publicly available catalogue entry or to the relevant clause of the present document, in accordance with one of the paths of clause K.1. Acceptable references include:
a) the entry in the ACM catalogue (path i);
b) the entry in any of the recognized catalogues listed under K.1.1 (ii) (path ii); for example a national cryptographic catalogue published by a Member State authority, a sector-specific catalogue published by a recognized standards-development organization, or an industry catalogue, where the catalogue is publicly available and is maintained under a documented revision and retirement process;
c) the clause of the present document listing the algorithm as part of the vertical-specific cryptographic content for routers, modems and switches (path iii);
d) where an algorithm is referenced under path ii) or path iii) but is not present in the ACM, the documentation shall in addition identify the publicly available specification (e.g. an IETF Request for Comments, an IEEE standard, an ETSI deliverable, a NIST publication) under which the algorithm is implemented.
-a) the entry in the ACM catalogue (path i);
-b) the entry in any of the recognized catalogues listed under K.1.1 (ii) (path ii); for example a national cryptographic catalogue published by a Member State authority, a sector-specific catalogue published by a recognized standards-development organization, or an industry catalogue, where the catalogue is publicly available and is maintained under a documented revision and retirement process;
-c) the clause of the present document listing the algorithm as part of the vertical-specific cryptographic content for routers, modems and switches (path iii);
-d) where an algorithm is referenced under path ii) or path iii) but is not present in the ACM, the documentation shall in addition identify the publicly available specification (e.g. an IETF Request for Comments, an IEEE standard, an ETSI deliverable, a NIST publication) under which the algorithm is implemented.
2. Where a non-CRY-SOTA algorithm is offered by the product to support interoperability with a specifically identified legacy system, in accordance with recital (55) of Regulation (EU) 2024/2847 [i.1] and section 2.5 of the Commission Guidance on its application, the documentation shall demonstrate that all of the following conditions are met: