Title:CRA;<br>Cybersecurity requirements for physical and virtual network interfaces
Title:Cybersecurity (CYBER); CRA; Cybersecurity requirements for physical and virtual network interfaces
Spec Number:304 625
Version:v0.0.14
Date:2025-12
Work Item:TC/WI-Number
Version:v0.0.15
Date:2026-07-03
Release:5
Work Item:DEN/CYBER-EUS-0017
keywords:CRA, Cybersecurity, Interfaces
Copyright Year:2025
Copyright Year:2026
---
# Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations pertaining to these essential IPRs, if any, are publicly available for **ETSI members and non-members**, and can be found in ETSI SR 000 314: _\"Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards\"_ , which is available from the ETSI Secretariat. Latest updates are available on the [ETSI IPR online database].
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations pertaining to these essential IPRs, if any, are publicly available for **ETSI members and non-members**, and can be found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the [ETSI IPR online database](https://ipr.etsi.org/).
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document.
[ETSI IPR online database]:https://ipr.etsi.org/
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners. ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
**DECT™** , **PLUGTESTS™** , **UMTS™** and the ETSI logo are trademarks of ETSI registered for the benefit of its Members. **3GPP™** , **LTE™** and **5G ™** logo are trademarks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. **oneM2M™** logo is a trademark of ETSI registered for the benefit of its Members and of the oneM2M Partners. **GSM**® and the GSM logo are trademarks registered and owned by the GSM Association.
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners. ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
**BLUETOOTH ®** is a trademark registered and owned by Bluetooth SIG, Inc.
**DECT™**, **PLUGTESTS™**, **UMTS™** and the ETSI logo are trademarks of ETSI registered for the benefit of its Members. **3GPP™** and **LTE™** are trademarks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. **oneM2M™** logo is a trademark of ETSI registered for the benefit of its Members and of the oneM2M Partners. **GSM®** and the GSM logo are trademarks registered and owned by the GSM Association.
# Foreword
> DRAFT FOREWORD - DO NOT CONSIDER THE CONTENT
This draft Harmonised European Standard (EN) has been produced by ETSI Technical Committee Cyber Security (CYBER), and is now submitted for the combined Public Enquiry and Vote phase of the ETSI Standardisation Request deliverable Approval Procedure (SRdAP).
```
The present document has been prepared under the Commission's standardisation request C(2025) 618 [ i.3 ] final to provide one voluntary means of conforming to the requirements of Regulation (EU) No 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)[ i.1 ].
```
The present document has been prepared under the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide one voluntary means of conforming to the requirements of Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828, known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under that Regulation, compliance with the normative clauses of the present document given in table A.1 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
Once the present document is cited in the Official Journal of the European Union under that Regulation, compliance with the normative clauses of the present document given in table A.1 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding requirements of that Regulation and associated EFTA regulations.
_The Harmonised Standard shall have appropriate transposition periods specified. A Harmonised Standard confers presumption of conformity when it has been published in the Official Journal of the European Union (OJEU) and transposed by a member state._
In the present document \"**shall**\", \"**shall not**\", \"**should**\", \"**should not**\", \"**may**\", \"**need not**\", "**will**\", \"**will not**\", \"**can**\" and \"**cannot**\" are to be interpreted as described in clause 3.2 of the [ETSI Drafting Rules] (Verbal forms for the expression of provisions).
In the present document "**shall**", "**shall not**", "**should**", "**should not**", "**may**", "**need not**", "**will**", "**will not**", "**can**" and "**cannot** are to be interpreted as described in clause 3.2 of the [ETSI Drafting Rules](https://portal.etsi.org/Services/editHelp/How-to-start/ETSI-Drafting-Rules)(Verbal forms for the expression of provisions).
"**must**" and "**must not**" are **NOT** allowed in ETSI deliverables except when used in direct citation.
# Introduction
<mark>Editor’s Note: "Introduction" clause should introduce the structure of the document, motivating the purpose of each subclause and clearly stating which parts of the standard are normative and which parts are informative.</mark>
<mark>Editor’s Note: The clause should furthermore explain how the standard should be used. Readers should be given a concrete path to ensuring conformity of their product by guiding them through the document. This path may start with identification of the product at hand within the product context clause, move on to the security analysis annex to determine applicable technical requirements, proceed with implementing those technical requirements, and then finally end with conformity assessment criteria to evaluate proper implementation.</mark>
<mark>Editor’s Note: Moreover, the “Introduction” clause should clarify the general role of vertical standards in the CRA landscape of resources supporting manufacturers, explaining which relevant content is not contained therein and shall instead be sourced from the CRA itself, legal guidance for the CRA, and related standards (adjacent and overlapping verticals, prEN 40000-1-4, prEN 40000-1-2, prEN 40000-1-3).</mark>
<mark>Editor’s Note: Ready to use text is provided below that may be included in all CRA Vertical standards or replaced by more relevant or specific content in each vertical. You may also only use the parts of the text that are relevant for each standard.</mark>
The present document provides the technical cybersecurity requirements for the products in scope, following a risk-based approach in support of the Cyber Resilience Act (CRA) [\[i.1\]](#_ref_i.1). The technical cybersecurity requirements are thereby proportionate to the intended purpose, reasonably foreseeable use, deployment context, and threat exposure of the products.
[Clause 4](#4-product-context) does not contain technical requirements; it describes the product context that is considered for the application of the present document.
Clause 4 also defines Use Cases (UCs) that represent the main deployment scenarios reflecting the intended purpose and reasonably foreseeable use of the product, which serve as the basis for identifying relevant cybersecurity risks.
[Clause 5](#5-technical-requirements-for-the-products) specifies technical cybersecurity requirements for the product to mitigate the identified risks, including their applicability conditions.
[Clause 6](#6-assessment-criteria-for-compliance-with-technical-requirements) specifies the assessment criteria and compliance verification procedures with the requirements of Clause 5.
[Annex A](#annex-a-informative-relationship-between-the-present-document-and-the-requirements-of-eu-regulation-eu-20242847---the-cyber-resilience-act) maps the technical requirements of the present document with the essential requirements of the CRA [\[i.1\]](#_ref_i.1) regulation.
[Annex B](#annex-b-informative-security-analysis) informs about the methodology used to assess the security risks of the products in their context.
<mark>Editor’s Note: Where the functionality of the product relies on cryptography, then Annex K shall be included and instantiated in the CRA Vertical standard to provide presumption of conformity with regards to cryptographic mechanisms embarked in the product.</mark>
[Annex K](#annex-k-normative-generic-cryptographic-requirements-and-assessment) supports the definition of the cryptographic requirements and assessment criteria used by the present document.
\"**must**\" and \"**must not**\" are **NOT** allowed in ETSI deliverables except when used in direct citation.
<mark>Editor’s Note: The following annexes are optional (may or may not be included in the vertical):</mark>
[Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps) provides supplementary requirements and assessment provisions where a product relies on remote data processing solutions (RDPS) for the provision or support of one or more product functions.
# Executive summary
<mark>Editor’s Note: Annex R may be used by vertical standards where RDPS-specific security considerations are relevant and are not already addressed by the core requirements of the concerned standard.</mark>
**Before commenting, please read Annex E for an informative explanation of the use and function of the present document.**
Further information on guidance for the application of the present document is provided in Annex G.