@@ -123,35 +123,50 @@ Network interfaces whose intended purpose includes routing, switching, or transf
## 2.1 Normative references
The following referenced documents are necessary for the application of the present document.
<mark>Editor's Note: _**In Harmonised Standards these references shall be specific** (identified by date of publication and/or edition number or version number) **publicly available and in English, **except in exceptional circumstances making sure that impacts have been evaluated and explanations have been given on how any negative implications should be avoided**. See clauses 2.10.1 and 8.4 of the [EDRs](https://portal.etsi.org/Services/editHelp/How-to-start/ETSI-Drafting-Rules)._</mark>
<mark>Editor’s Note: Chains of normative references should be as short as possible or avoided altogether. Where references themselves include further references, authors should, as appropriate, attempt to resolve intermediate references and directly include the final target of referencing in this document.</mark>
<mark>Editor’s Note: Normative references must be limited to European standards (EN), except where those references are without alternative, essential to the standard. In that case, it is strongly advised to seek feedback from the European Commission (e.g., ENISA ACM document has been flagged as adequate by the European Commission). Publicly available ISO/IEC standards can be considered appropriate; contact the European Commission for feedback of any reference that is not an EN or an ISO/IEC standard.</mark>
<mark>Editor's Note: _**Legal acts can never be used as normative references.**_</mark>
References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies.
Referenced documents which are not found to be publicly available in the expected location might be found in the [ETSI docbox](https://docbox.etsi.org/Reference/).
> NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity.
The following referenced documents are necessary for the application of the present document.
<spanid="_ref_1"></span><aname="_ref_1">[1]</a> [ENISA Report 1747792503](https://certification.enisa.europa.eu/document/download/a845662b-aee0-484e-9191-890c4cfa7aaa_en?filename=ECCG%20Agreed%20Cryptographic%20Mechanisms%20version%202.pdf)(version 2 - April 2025) "European Cybersecurity Certification Group Sub-group on Cryptography Agreed Cryptographic Mechanisms" [ACM]
<spanid="_ref_3"></span><aname="_ref_3">[1] prEN 40000-1-3: "Cybersecurity requirements for products with digital elements -
Part 1-3: Vulnerability Handling", (produced by CEN).</a>
## 2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or nonspecific. For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies.
References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non‑specific references, the latest version of the referenced document (including any amendments) applies.
> NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's understanding but are not required for conformance to the present document.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's understanding, but are not required for conformance to the present document.
<spanid="_ref_i.1"></span><aname="_ref_i.1">[i.1]</a> [Regulation \(EU\) 2024/2847](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202402847) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).
<spanid="_ref_i.2"></span><aname="_ref_i.2">[i.2]</a> [Commission Implementing Regulation \(EU\) 2025/2392](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202502392) of 28 November 2025 on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council.
<spanid="_ref_i.1"></span><aname="_ref_i.1">[i.1]</a> Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020and Directive (EU) 2020/1828 (Cyber Resilience Act)
<spanid="_ref_i.3"></span><aname="_ref_i.3">[i.3]</a> [Standardisation request M/606 - C\(2025\)618](https://ec.europa.eu/growth/tools-databases/enorm/mandate/606_en): "Commission Implementing decision of 3.2.2025 on a standardisation request to the European Committee for Standardisation (CEN), the European Committee for Electrotechnical Standardisation (Cenelec) and the European Telecommunications Standards Institute (ETSI) as regards products with digital elements in support of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020and Directive (EU) 2020/1828 (Cyber Resilience Act)".
<spanid="_ref_i.2"></span><aname="_ref_i.2">[i.2]</a> EN 18031-1 (2024): \"Common security requirements for radio equipment - Part 1: Internet connected radio equipment\", , (produced by CEN).
<spanid="_ref_i.4"></span><aname="_ref_i.4">[i.4]</a>prEN 40000-1-1: "Cybersecurity requirements for products with digital elements – Vocabulary"
<spanid="_ref_i.3"></span><aname="_ref_i.3">[i.3]</a>C(2025)618 – Standardisation request M/606: Commission Implementing decision of 3.2.2025 on a standardisation request to the European Committee for Standardisation (CEN), the European Committee for Electrotechnical Standardisation (Cenelec) and the European Telecommunications Standards Institute (ETSI) as regards products with digital elements in support of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).
<spanid="_ref_i.5"></span><aname="_ref_i.5">[i.5]</a>prEN 40000-1-2: "Cybersecurity requirements for products with digital elements – Part 1-2: Principles, product risk management, and lifecycle activities”
<spanid="_ref_i.4"></span><aname="_ref_i.4">[i.6]</a> CEN/CLC JTC13: \"Cybersecurity and Data Protection\".
<spanid="_ref_i.6"></span><aname="_ref_i.6">[i.6]</a> prEN 40000-1-3: "Cybersecurity requirements for products with digital elements – Part 1-3: Vulnerability handling“
<spanid="_ref_i.5"></span><aname="_ref_i.5">[i.5]</a> ETSI TS 103 732 \"Consumer Mobile Device Protection Profile\".
<spanid="_ref_i.7"></span><aname="_ref_i.6">[i.7]</a> prEN 40000-1-4: "Cybersecurity requirements for products with digital elements – Part 1-4: Security controls – Generic security requirements”
<spanid="_ref_i.6"></span><aname="_ref_i.6">[i.6]</a> prEN 40000-1-1: "Cybersecurity requirements for products with digital elements – Vocabulary", (produced by CEN).</a>
<spanid="_ref_i.8"></span><aname="_ref_">[i.8]</a> prEN 50770 series: "Security for operational technologies" (produced by CENELEC).
<spanid="_ref_i.7"></span><aname="_ref_i.7">[i.7]</a> ETSI EN 304 627 \"Essential cybersecurity requirements for routers, modems
intended for the connection to the internet, and switches\".
<spanid="_ref_i.9"></span><aname="_ref_i.9">[i.9]</a> ETSI EN 304 627 \"Essential cybersecurity requirements for routers, modems intended for the connection to the internet, and switches\".
# 3 Definition of terms, symbols and abbreviations