@@ -3250,14 +3250,53 @@ The risk and their applicability to use cases defined in Annex U are presented i
**Figure B.5-6: Threat mapping rational part 6**
# Annex K (normative): Generic requirements and assessment criteria for the use of state of the art cryptography V 0.51 (2025-02-16)
# Annex K (normative):
# Vertical specific state of the art cryptography
## K.1 General
This annex provides additional vertical-specific generic requirements around the use of state of the art cryptography in routers, modems intended for the connection to the internet, and switches. It lists, by reference to the relevant normative clauses elsewhere in the present document, the cryptographic algorithm primitives, schemes and protocols that are commonly deployed on the market for these product categories and that are classified as CRY-SOTA for the purposes of the present document.
### K.1.1 Classification of cryptographic algorithms as CRY-SOTA
For the purposes of the present document, a cryptographic algorithm, scheme or protocol is classified as CRY-SOTA where it is admitted under one of the ACM-listed or ACM-extended routes defined in items i), ii) or iii) below. A cryptographic algorithm, scheme or protocol that is not CRY-SOTA may nonetheless be used where it is admitted under the interoperability-based route defined in item iv) below.
A cryptographic algorithm, scheme or protocol is CRY-SOTA where at least one of the following applies:
1. ACM-listed: it is listed as Recommended (or equivalent) in the European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms catalogue (ACM) [1];
2. ACM-extended (recognized catalogue): it is not listed in the ACM, and it is listed as Recommended (or equivalent), and is not marked as deprecated, legacy-only or disallowed at the time of the conformity assessment, in any of the following recognized public cryptographic catalogues:
- NIST publications in the Special Publication 800 series, the FIPS series, and the associated CAVP/ACVP test-vector programmes;
- BSI TR-02102 series [2];
- ANSSI Référentiel Général de Sécurité, Annex B2 [3];
- ANSSI Référentiel Général de Sécurité, Annex B2 [3];
- a sector-specific cryptographic algorithm catalogue maintained by a recognized standards-development organization such as ETSI, 3GPP, ITU-T, IEEE and IETF (see EXAMPLE 2);
3. iii) ACM-extended (vertical content): it is listed in the normative cryptographic content of the present document for routers, modems and switches (see clauses K.3 through K.8).
A cryptographic algorithm, scheme or protocol that is not CRY-SOTA under items i), ii) or iii) may be used only as follows:
4. Interoperability-based: it is required for a specific product function to comply with a well-defined external specification or external requirement, and its use meets all of the conditions for legacy interoperability set out in clause K.2.4 (2). Inclusion of a cryptographic algorithm, scheme or protocol under this route does not classify it as CRY-SOTA.
ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will have to be deleted or replaced by relevant references and notes before publication.
Note for Gisela, Clauses have been renumbered for consistency.
## K.1 State of the Art Cryptography (SOTA)
### K.1.1 Requirement
The product shall, by default, use State-of-the-Art cryptography algorithms listed in (CRY-SOTA), to be used for the supported security mechanism of the product where applicable.