July 2026: New Cybersecurity Evaluation Standard for ICT Products Enhances Information Technology Security

July 2026: New Cybersecurity Evaluation Standard for ICT Products Enhances Information Technology Security

The July 2026 release of EN 17640:2022+A1:2026 marks a significant advancement for the Information Technology sector. This new European standard introduces a comprehensive fixed-time cybersecurity evaluation methodology, designed to address the evolving threats, compliance demands, and product assurance requirements for ICT (Information and Communication Technology) products. With far-reaching implications for manufacturers, certification bodies, and developers, this methodology delivers practical pathways for both third-party certifications and streamlined self-assessment.


Overview / Introduction

The digital transformation journey of industries rests heavily on robust Information Technology foundations. ICT products, from everyday devices to critical infrastructure components, require reliable, repeatable, and transparent approaches to cybersecurity evaluation. Standards serve as the backbone for trust, interoperability, and legal compliance, especially as regulatory frameworks tighten in response to rising cyber threats.

This article explores the newly published EN 17640:2022+A1:2026 standard, released in July 2026, which provides organizations with a clear and actionable methodology for evaluating the cybersecurity of ICT products. Industry professionals will learn about the standard’s scope, evaluation tasks, assurance levels, and practical implications for compliance, product development, and market access.


Detailed Standards Coverage

EN 17640:2022+A1:2026 – Fixed-time Cybersecurity Evaluation Methodology for ICT Products

Full Standard Title: Fixed-time cybersecurity evaluation methodology for ICT products

EN 17640:2022+A1:2026 is a pioneering European standard developed by CEN, designed to introduce an actionable methodology for cybersecurity evaluation within fixed timeframes, tailored to ICT products. This methodology aligns with the requirements and assurance levels defined in the European Cybersecurity Act (CSA), applicable to Basic, Substantial, and High assurance levels. The standard provides both a generic and customizable framework for use by scheme developers, conformity assessment bodies, certification labs, and ICT product manufacturers.

Scope and Applicability

  • Describes a fixed-time evaluation methodology (i.e., evaluation carried out within pre-defined time and workload limits) for ICT products.
  • Structured to be flexible for diverse use cases, including self-assessment (particularly at CSA Basic level) and third-party (independent) certifications.
  • Clear mapping to all three assurance levels (Basic, Substantial, High) defined in the CSA, ensuring applicability across a wide range of products and risk environments.

Key Requirements and Specifications

  • Composed of modular evaluation "blocks," each representing a specific assessment activity aligned with CSA requirements.
  • Supports the creation and integration of domain-specific schemes, accommodating both general-purpose and vertical (sector-specific) needs.
  • Provides a step-by-step set of mandatory and recommended evaluation tasks for each assurance level, which include:
    • Completeness check
    • Review of security functionalities
    • FIT Security Target (FIT ST) evaluation
    • Development documentation analysis
    • Installation assessment
    • Conformance testing
    • Vulnerability review and testing
    • Penetration testing
    • Basic and extended cryptographic analysis
    • Composition evaluation for products containing pre-certified components
  • Accommodates both pure product-focused evaluation and (optionally) evaluation of the development process (e.g., secure software lifecycle, update management).
  • Details the competencies required for evaluators, the expected evidence at each evaluation stage, and the role of scheme developers in configuring and deploying the methodology.

Who Needs to Comply

  • ICT product manufacturers
  • Solution developers and integrators
  • Cybersecurity scheme developers and compliance managers
  • Conformity Assessment Bodies (CABs), accreditation agencies, and certification laboratories operating under the CSA or other sectoral requirements
  • Regulatory authorities and market surveillance organizations

Practical Implementation and Notable Changes

  • Integrates the latest amendment (A1:2026) to reflect evolving threat landscapes, assurance needs, and best practices—superseding the 2022 edition.
  • Offers practical tools, including evaluation checklists, risk assessment matrices, and documented workflows adaptable to various product types and certification schemes.
  • Clarifies composite evaluation approaches for products comprising certified components, optimizing assurance without duplicative testing.
  • Enables agile, scheme-specific tailoring—organizations can designate which evaluation tasks are mandatory or recommended at different assurance levels.
  • Reduces certification bottlenecks by balancing the need for rigorous evaluation with business realities such as time-to-market and resource constraints.
  • Encourages harmonization with other major standards (e.g., EN ISO/IEC 15408, EN ISO/IEC 18045) while introducing the essential fixed-time paradigm.

Key highlights:

  • Comprehensive, modular framework—tailored evaluation blocks support all CSA assurance levels
  • Explicit support for both self-assessment and third-party certification, facilitating broad adoption for ICT manufacturers and service providers
  • Enhanced guidance for integrating pre-certified components into composite products, streamlining multi-component evaluation across supply chains

Access the full standard:View EN 17640:2022+A1:2026 on iTeh Standards


Industry Impact & Compliance

Driving Security, Interoperability, and Market Access

The publication of EN 17640:2022+A1:2026 is a critical development for the Information Technology and ICT sectors. The fixed-time methodology introduces a standardized yet flexible approach to product cybersecurity evaluation, thus:

  • Supporting legal and regulatory compliance: Aligns with the European Cybersecurity Act (CSA) and other regulatory obligations, enabling organizations to demonstrate conformity and product safety in increasingly regulated markets.
  • Enabling risk-based assurance: The evaluation framework scales from basic to high assurance needs, allowing targeted allocation of effort and resources aligned with product risk profiles and market needs.
  • Streamlining certification: Reduces time-to-market for ICT products by providing predictable, transparent evaluation timelines and reducing the complexity of multi-country certification.
  • Encouraging supply chain security: Supports the evaluation and certification of multi-component (composite) products, critical for complex ICT solutions involving third-party components.
  • Facilitating global trade and interoperability: Harmonizes methodologies across European and international markets, opening doors for cross-border product acceptance.

Compliance Considerations and Timelines

  • Manufacturers must implement the new methodology for any certifications or recertifications falling under schemes that reference this standard after January 2027; adoption may be required earlier depending on the scheme.
  • Organizations should review scheme-specific requirements (including checklists, attack potential levels, and block selection) to ensure effective implementation.
  • Early alignment with the standard can yield a competitive advantage by demonstrating best-in-class, verifiable security to customers, regulators, and partners.
  • Non-compliance risks include market exclusion, increased liability, potential regulatory fines, and reduced customer trust.

Technical Insights

Common Technical Requirements and Industry Best Practices

EN 17640:2022+A1:2026 mandates rigorous evaluation steps for ICT product security, including:

  • Evidence-based evaluation: Product teams must supply comprehensive documentation, such as FIT Security Targets, Secure User Guides, and (where needed) source code or cryptographic specifications.
  • Multi-layered evaluation tasks: Ranging from document review and conformance testing to active vulnerability and penetration analysis, assuring both breadth and depth of cybersecurity.
  • Evaluator competence: Specifies skills and knowledge required for evaluators, including familiarity with product domains, secure development processes, and cryptography.
  • Risk-based sampling: Permits the design of test plans and sampling strategies proportional to the likelihood and impact of vulnerabilities or non-conformities.
  • Flexibility for product type and assurance level: Tasks, depth, and sampling are adapted based on product context and required assurance, supporting both basic consumer IoT and high-assurance infrastructure.

Implementation Best Practices

  • Early engagement with scheme requirements: Study and adapt to the scheme-specific checklists, attack potential matrices, and documentation demands.
  • Coordinate with accredited evaluators: Build partnerships with trusted assessment labs and ensure internal teams are equipped for required tasks and evidence production.
  • Thorough documentation: Prepare high-quality, traceable documentation—especially FIT Security Targets and Secure User Guides—to expedite evaluation.
  • Leverage composability: Take advantage of composition rules for integrating certified components, reducing redundant testing and expediting multi-part product certification.
  • Iterative vulnerability management: Regularly update vulnerability documentation, conduct internal reviews, and maintain a strong patch and remediation record as part of ongoing compliance.

Testing and Certification Considerations

  • Use validated, up-to-date testing tools wherever possible.
  • Capture all evidence, results, and rationales in the Evaluation Technical Report (ETR).
  • For high-assurance claims, anticipate and prepare for extended cryptographic evaluations and more thorough testing.
  • Anticipate periodic updates to process evaluations; for example, evidence older than two years may be invalid without further audit or review.

Conclusion / Next Steps

The release of EN 17640:2022+A1:2026 in July 2026 signals a new era in standardized, reliable cybersecurity evaluation for ICT products. By adopting this methodology, organizations can:

  • Demonstrate regulatory compliance and product assurance
  • Streamline certification and market access processes
  • Build stronger, more resilient products and supply chains
  • Align with the latest industry best practices and regulatory expectations

Recommendations:

  1. Review your current cybersecurity evaluation and certification strategies in light of the new standard.
  2. Assess scheme-specific adoption timelines and requirements that reference EN 17640:2022+A1:2026.
  3. Engage with accredited evaluation bodies, update internal documentation processes, and train teams on the standard’s expectations.
  4. Leverage the methodology's flexibility for both new product pipelines and existing product recertifications.

Stay proactive: monitor further regulatory developments and additional amendments to ensure your organization remains at the cutting edge of ICT product security and compliance.

For more information and to access the full text of the standard, visit:EN 17640:2022+A1:2026 on iTeh Standards

Loading...