Commit 7051228a authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Update Clause 1 Scope to revised structure

parent ee4152b9
Loading
Loading
Loading
Loading
+15 −18
Original line number Diff line number Diff line
@@ -92,35 +92,32 @@ Further information on guidance for the application of the present document is p

# 1 Scope

## 1.1 General
The present document specifies technical requirements and corresponding assessment criteria for physical and virtual network interfaces related to cybersecurity. 
The products with digital elements in scope, thereafter "network interfaces":

The present document specifies cybersecurity requirements and related assessment criteria for physical and virtual network interfaces.
- are specified within the "technical description" of the "category of product" number "10" by the Commission Implementing Regulation (EU) 2025/2392 [\[i.2\]](#_ref_i.2) as: "Physical and virtual network interfaces"

## 1.2 Products in scope
-  are only covered within the product context described in clause 4.

Products in scope include products whose purpose is to serve as a virtual or physical network interface intended to enable the connection of a computing device to a network. A network interface provides connectivity via a device driver API operating at the data link layer.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1) Annex I Part I under the conditions identified in annex A.

Physical network interfaces are products that directly connect a device to a network via an application programming interface (API) provided by device drivers. This connection may be wired or wireless and feature hardware adapters to transmission media with corresponding firmware, typically physical network interfaces operate at the physical and data link layer.
Products that are connected to a host system by a communications bus, such as PCIe or USB are physical network interfaces, though they may use a wide variety of technologies to enable this connection including both direct physical connections and wireless connections.
The category of physical network interfaces is broad and composed of wired and wireless network interface cards, controllers and adapters, and network interface hardware modules, such as for Wi-Fi™, Ethernet, cellular modems, IrDA, USB, Bluetooth®, NearLink, Zigbee®, Fieldbus, or Infiniband.
> NOTE: This reduces the scope of the vertical. Full presumption of conformity of the product will be given by complying with both the CRA Vertical standard and PT3, once they are cited in the EUOJ. 

Virtual network interfaces are products that directly or indirectly connect a device to a network via an API that emulates that of device drivers or physical network interfaces, typically operating at the data link layer. These virtual network interfaces consist of software running on a host system, and communicate via the device driver interface of that host.
As purely virtual, standalone products, a virtual network interface remains a product whose core function is that of a network interface and that provides a remote management interface for the network interface or the host system.
Examples of virtual network interfaces also include: container network interfaces, VPN interfaces, and loopback interfaces.
<mark>Editor's Note: it is ok to quote the definitions from the CRA legal text  but only definitions, no other parts of the text.</mark>

For the purposes of the present document, network interfaces will be split up into the following groups, due to their distinct threat models:
<mark>Editor’s Note: For products that are part of broader categories, the scope should list the product types that are covered.</mark>

* Wired network interfaces
* Wireless network interfaces
* Virtual network interfaces
<mark>Editor’s Note: Explain which products are covered by other vertical standards that have an overlap with the product category targeted by this standard. Where applicable, the scope could include the following exclusion:</mark>

Network interfaces are closely related to what is commonly called a \"modem\", but this general term is used for two different kinds of products:
Network interfaces intended for use in the industrial OT (Operational Technology) domain are excluded from the scope of the present document, see prEN 50770 series [\[i.8\]](#_ref_i.8).

1. \"Modem interface\": A single network interface that connects a physical transmission adapter to a system bus, as for example a 5G modem interface or Power Line Communication device
<mark>Editor’s Note: Avoid paraphrasing the technical description itself, because that risks narrowing down or broadening the product category unintentionally</mark>

2. \"Standalone modem\": A device with two or more network interfaces that routes network data between two different networks, relaying data from one type of physical transmission media to another, such as a cable modem
<mark>Editor’s Note: Products can optionally offer additional functions, some of which may be addressed in other vertical standards. The scope may include examples of such commonly available additional functions that are not in the scope of the present document, and possibly references to other specific standards.</mark>

\"Modem interfaces\" are included in the present document. \"Standalone modems\" are excluded from the present document, but may be found in the vertical CRA standard for Routers Modems & Switches [i.7]
Network interfaces whose intended purpose includes management or configuration of the product over the attached network are excluded from the present document.

Network interfaces whose intended purpose includes routing, switching, or transfer of information from one attached network to a different attached network are excluded from the present document.

# 2 References