M/606 - CRA
on a standardisation request to European Standards Organisations in support of Union policy on cybersecurity requirements for products with digital elements
Mandate M/606 requests European Standards Organisations to develop standards supporting the European Union's cybersecurity policy for products with digital elements. The aim is to establish harmonized cybersecurity requirements ensuring the protection and resilience of digital products within the internal market. This standardisation effort facilitates compliance with EU legislation, enhancing product security, consumer trust, and market surveillance. The mandate was formalized through the CEN Board Decision CEN/BT C028/2025.
Purpose
The mandate M/606 aims to support the European Union's policy on cybersecurity requirements specifically for products that contain digital elements. It seeks to enhance the security and resilience of such products by establishing harmonised cybersecurity standards. This initiative aligns with the broader EU objective to strengthen cybersecurity measures across the internal market, thereby protecting users and digital infrastructure.
Standardisation request
The mandate requests European Standardisation Organisations to develop standards that define clear cybersecurity requirements for products with digital components. These standards are expected to facilitate compliance with Union legislation on digital product security by providing technical specifications that manufacturers and stakeholders can follow. The development of these standards is intended to harmonise requirements across member states and ensure a common level of cybersecurity.
Expected deliverables
- European Standards detailing cybersecurity requirements applicable to digital products.
- Supporting technical documents that provide guidance and criteria related to cybersecurity.
- Frameworks that assist in assessing product security in line with Union policies.
These deliverables will contribute to the implementation of EU cybersecurity policy by creating technical benchmarks that harmonise security expectations and foster trust in digital products.
Context
Mandate M/606 was adopted through a CEN BT Decision (resolution reference: CEN/BT C028/2025), reflecting the European Committee for Standardization’s commitment to supporting EU cybersecurity policies. The focus on products with digital elements corresponds to the increasing interconnectedness and digitisation of goods, which introduces new cybersecurity risks. By fostering standardisation in this area, the EU seeks to address these risks proactively and ensure that digital products placed on the market meet essential cybersecurity requirements.
The mandate covers standardisation work to support Union policy on cybersecurity requirements for products with digital elements, focusing on ensuring the security of such products within the EU market. It addresses standards related to the cybersecurity of digital products across various sectors.
General Information
Smart Cards
• Definition of a Smart Card that is in the scope of the Regulation (EU) 2024/2847, Annex 4, Category 41
o In reference to TC47X/WG3 work on Security MCU/MPU
• Distinction between applicative part and general part of the architecture that is essential for composite evaluation
• Expectation on applicative and composite evaluation in accordance with EUCC scheme
Similar Devices
• Definition of similar devices that are in- or out-of-scope of this standardisation category – for example:
o Products in-scope that fully comply with architectural description of a compliant Smart Card but do come in different packaging (e.g. SIM-card form factors, key fobs, tokens, IoT embedded ID elements), etc.
o Products out-of-scope that come packaged as a smart card but contain microcontrollers with security functions or tamper resistance appropriate for evaluation under other categories
Secure Elements
• Definition of a Secure Element that is on the scope of the Regulation (EU) 2024/2847, including description of possible architectures and required security capabilities, in alignment with TC47X
• Distinction between applicative part and general part of the architecture that is essential for composite evaluation
• Expectation on applicative and composite evaluation in accordance with EUCC scheme
• Alignment of security capabilities of secure elements with microcontrollers and microprocessors with security functions and/or tamper resistance capabilities
Related remote data processing
• Technical criteria characterizing a remote data processing
• Identification of remote data processing e.g. life cycle management, security update services….
• Standardized expectations on lifecycle management of Smart Cards and Secure Elements
As part of the work, the group will cover at least the types of PwDE and their intended purposes in relation to use cases described in the list below. In addition, for some types of PwDE, expertise from external organizations which are recognized will be leveraged to ensure the project is relevant and in line with the reality of markets.
Type of the Product with Digital Elements:
1. Secure element, Smart Cards and similar devices for critical use cases – high risk profile
2. Secure element, Smart Cards and similar devices for critical use cases – low risk profile
3. Remote data processing systems / services
The list above is not finite, it represents initial state.
The work of the group will first focus on delivering precise scope related to intended purpose and dependant use cases, in collaboration with other standardisation workgroups and industry representatives.
Note on the use cases
- Standard may cover specific aspects of particular use cases
Note on risk profile
- The mapping of compliance criteria with EUCC may be given
- Standard may cover aspects of newer version of Common Criteria CC:2022, and other established schemes
- Draft60 pagesEnglish languagee-Library read for1 day
This document specifies process requirements for the secure development of products used in industrial automation and control systems. It defines a secure development life-cycle (SDL) for the purpose of developing and maintaining secure products. This life-cycle includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. These requirements can be applied to new or existing processes for developing, maintaining and retiring hardware, software or firmware for new or existing products. These requirements apply to the developer and maintainer of the product, but not to the integrator or user of the product. A summary list of the requirements in this document can be found in Annex B.
- Draft80 pagesEnglish languagee-Library read for1 day
This document provides detailed technical control system component requirements (CRs) associated with seven foundational requirements (FRs) including defining the requirements for control system capability security levels and their components, SL-C(component). The seven foundational requirements (FRs) are: a) identification and authentication control (IAC), b) use control (UC), c) system integrity (SI), d) data confidentiality (DC), e) restricted data flow (RDF), f) timely response to events (TRE), and g) resource availability (RA).
- Draft193 pagesEnglish languagee-Library read for1 day
This project aims at covering the line 16 of the standardisation request and will provide:
• General description of the Product with digital elements belonging to that category and the product and/or components such Product with digital elements may integrate, including – amongst other:
o detailed description of that product category using in:
Identity management systems hardware and software are products with digital elements that provide mechanisms for identity lifecycle management, such as identity provisioning, maintenance, authentication, authorisation and deprovisioning, and including associated metadata.
Privileged access management hardware and software are products with digital elements that authenticate and authorise users or devices, granting or denying access to digital resources or to physical locations.
This category includes but is not limited to products (hardware, software and communication protocol) with digital elements that have the core functionality of either or both identity management and privileged access management; authentication and access control readers; biometric readers; single sign-on software; federated identity management software, protection and safety management (such as access control, intrusion alarm, CCTV and fire safety systems) and multi-factor authentication software.
o Intended product purpose and reasonably foreseeable use in the above categories;
o Identification of the various types of Products with digital elements;
o Delineation and interplay with the following other categories of Product with digital elements (identified by their line in the standardization request):
line 17
line 18
line 20
line 24
line 28
line 29
line 32
line 35
line 37
line 38
line 39
line 41
• Description of their life cycle;
• Relevance of cybersecurity essential requirements including the cybersecurity assessment requirements;
• Definition of applicable risk profiles to be considered for these Product with digital elements;
• Applicable cybersecurity requirements ensuring fulfillment of the essential requirements for each risk profile;
• Applicable cybersecurity assessment requirements for each risk profile.
A base document is provided
• Defining the risk profiles;
• Identifying initial cybersecurity security requirements.
- Draft150 pagesEnglish languagee-Library read for1 day
This document defines cyber security requirements for products with digital elements belonging to product category “Hardware Device with Security Boxes” (hereinafter called “Product” or “HWSB product”).
The technical description of “Hardware Devices with Security Boxes” can be found in Annex II of [CRA].
The Hardware Devices with Security Boxes in scope are designed for deployment in a range of environments and where the threat landscape includes attackers with various attack potential.
HWSB are hardware-based systems intended to provide secure storage, processing and use of sensitive data, including cryptographic assets, within a protected hardware boundary (envelope).
This document applies to the HWSB part of the product. The applicability of this document to specific products is determined based on their intended purpose, use case and risk assessment.
- Draft157 pagesEnglish languagee-Library read for1 day
This document specifies the technical requirements for general-purposes tamper-resistant microprocessors and microcontrollers intended for integration into products that rely on them as a foundational security component. The microprocessors and microcontrollers in scope are designed for deployment in environments where the security features of the product integrating the platform are of importance, and where the threat landscape includes attackers with low but non-negligeable attack potential, corresponding to AVA_VAN.2 to AVA_VAN.3 as defined in [13].
- Draft102 pagesEnglish languagee-Library read for1 day
The products with digital elements in the scope of this document are the platforms of smartcards and similar devices including secure elements, which consist of a tamper-resistant MCU/MPU and optionally an application environment or operating system. Platforms are designed to store and process sensitive data, and to protect it against physical and logical attacks by attackers with significant resources and skills, at AVA_VAN.4 (moderate attack potential) or AVA_VAN.5 (high attack potential) levels. Although platforms do not delegate data processing to remote entities, these can be involved in operations such as software update, configuration or key provisioning. The platform ensures the authentication of the remote entities before receiving/sending sensitive information and ensures this information is protected during the exchange. Platforms are intended for final products including, but not limited to, electronic identity cards, removable UICCs, eUICC, payment cards, physical access cards, digital tachograph cards or wrist bands with integrated payment secure elements, trust anchors in connected digital products and critical IT systems. This document defines technical requirements for platforms, which meet the essential requirements defined in Regulation (EU) 2024/2847 to the extent described in Annex ZZ. It also defines the methods for assessing the technical requirements. The expression of the technical requirements and the assessment methods use the Common Criteria (CC) formalism defined in the EN ISO/IEC 15408 series and EN ISO/IEC 18045:2023 supplemented by the EUCC state-of-the-art documents for the technical domain smart cards and similar devices. This document covers platforms conformant with the Protection Profiles (PPs) PP0084, PP0117, PP0104 and PP TPM, and identifies the gaps of these specifications against the CRA essential requirements. In this document, PP0104 also refers to the PP0104-based PP-Configuration 0107. The evaluation of platforms against PP0084, PP0117, PP0104 or PP TPM plus the applicable additional technical requirements which cover their gaps allow to demonstrate conformance with the CRA essential requirements. The technical requirements and the mappings against PP0084, PP0117, PP0104 and PP TPM are defined in Clause 7 and Annex B, respectively. This document also covers platforms consisting of a hardware layer and either an application environment, e.g. Java Card platform, or firmware/software. Annex C contains an informative mapping of Java Card platforms towards PP0099. Platforms can have discrete, integrated or embedded form factors, and employ technologies such as integrated circuits, programmable macros or system-in-package or system-on-chip. These do not affect the requirements or the assessment methods. Unless specified, clauses apply to all platforms, from pure hardware to platforms consisting of hardware, firmware and/or software. Platforms are accompanied by guidance which contains all the requirements and recommendations for the secure integration of the platform into further intermediate or final products and the secure usage of the platform by the external entities. The guidance covers all the non-platform aspects which can impact the security of the platform assets. The applications stored and/or running on the platforms, which are an integral part of the final products, are outside the scope of this document. prEN 18330:2026 applies to products composed of a platform and a set of applications.
- Draft144 pagesEnglish languagee-Library read for1 day
This document specifies the security assessment requirements for platforms that include microprocessors and microcontrollers with security-related functionalities. These platforms aim to secure other products/networks/services beyond the microprocessors and microcontrollers themselves and are intended to provide assurance at a level AVA_VAN.1 as defined in [2], or without AVA_VAN claim.
- Draft95 pagesEnglish languagee-Library read for1 day
This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.
- Draft57 pagesEnglish languagee-Library read for1 day
This document provides the terms and definitions commonly used in the cybersecurity requirements for products with digital elements family of standards.
- Draft8 pagesEnglish languagee-Library read for1 day
This document defines cyber security requirements for products with digital elements belonging to product category “Hardware Device with Security Boxes” (hereinafter called “Product” or “HWSB product”).
The technical description of “Hardware Devices with Security Boxes” can be found in Annex II of [CRA].
The Hardware Devices with Security Boxes in scope are designed for deployment in a range of environments and where the threat landscape includes attackers with various attack potential.
HWSB are hardware-based systems intended to provide secure storage, processing and use of sensitive data, including cryptographic assets, within a protected hardware boundary (envelope).
This document applies to the HWSB part of the product. The applicability of this document to specific products is determined based on their intended purpose, use case and risk assessment.
- Draft157 pagesEnglish languagee-Library read for1 day
This project aims at covering the line 16 of the standardisation request and will provide:
• General description of the Product with digital elements belonging to that category and the product and/or components such Product with digital elements may integrate, including – amongst other:
o detailed description of that product category using in:
Identity management systems hardware and software are products with digital elements that provide mechanisms for identity lifecycle management, such as identity provisioning, maintenance, authentication, authorisation and deprovisioning, and including associated metadata.
Privileged access management hardware and software are products with digital elements that authenticate and authorise users or devices, granting or denying access to digital resources or to physical locations.
This category includes but is not limited to products (hardware, software and communication protocol) with digital elements that have the core functionality of either or both identity management and privileged access management; authentication and access control readers; biometric readers; single sign-on software; federated identity management software, protection and safety management (such as access control, intrusion alarm, CCTV and fire safety systems) and multi-factor authentication software.
o Intended product purpose and reasonably foreseeable use in the above categories;
o Identification of the various types of Products with digital elements;
o Delineation and interplay with the following other categories of Product with digital elements (identified by their line in the standardization request):
line 17
line 18
line 20
line 24
line 28
line 29
line 32
line 35
line 37
line 38
line 39
line 41
• Description of their life cycle;
• Relevance of cybersecurity essential requirements including the cybersecurity assessment requirements;
• Definition of applicable risk profiles to be considered for these Product with digital elements;
• Applicable cybersecurity requirements ensuring fulfillment of the essential requirements for each risk profile;
• Applicable cybersecurity assessment requirements for each risk profile.
A base document is provided
• Defining the risk profiles;
• Identifying initial cybersecurity security requirements.
- Draft150 pagesEnglish languagee-Library read for1 day
This document provides detailed technical control system component requirements (CRs) associated with seven foundational requirements (FRs) including defining the requirements for control system capability security levels and their components, SL-C(component).
The seven foundational requirements (FRs) are:
a) identification and authentication control (IAC),
b) use control (UC),
c) system integrity (SI),
d) data confidentiality (DC),
e) restricted data flow (RDF),
f) timely response to events (TRE), and
g) resource availability (RA).
- Draft193 pagesEnglish languagee-Library read for1 day
This document specifies process requirements for the secure development of products used in industrial automation and control systems. It defines a secure development life-cycle (SDL) for the purpose of developing and maintaining secure products. This life-cycle includes security requirements definition, secure design, secure implementation (including coding guidelines), verification and validation, defect management, patch management and product end-of-life. These requirements can be applied to new or existing processes for developing, maintaining and retiring hardware, software or firmware for new or existing
products. These requirements apply to the developer and maintainer of the product, but not to the integrator or user of the product. A summary list of the requirements in this document can be found in Annex B.
- Draft80 pagesEnglish languagee-Library read for1 day
Smart Cards
• Definition of a Smart Card that is in the scope of the Regulation (EU) 2024/2847, Annex 4, Category 41
o In reference to TC47X/WG3 work on Security MCU/MPU
• Distinction between applicative part and general part of the architecture that is essential for composite evaluation
• Expectation on applicative and composite evaluation in accordance with EUCC scheme
Similar Devices
• Definition of similar devices that are in- or out-of-scope of this standardisation category – for example:
o Products in-scope that fully comply with architectural description of a compliant Smart Card but do come in different packaging (e.g. SIM-card form factors, key fobs, tokens, IoT embedded ID elements), etc.
o Products out-of-scope that come packaged as a smart card but contain microcontrollers with security functions or tamper resistance appropriate for evaluation under other categories
Secure Elements
• Definition of a Secure Element that is on the scope of the Regulation (EU) 2024/2847, including description of possible architectures and required security capabilities, in alignment with TC47X
• Distinction between applicative part and general part of the architecture that is essential for composite evaluation
• Expectation on applicative and composite evaluation in accordance with EUCC scheme
• Alignment of security capabilities of secure elements with microcontrollers and microprocessors with security functions and/or tamper resistance capabilities
Related remote data processing
• Technical criteria characterizing a remote data processing
• Identification of remote data processing e.g. life cycle management, security update services….
• Standardized expectations on lifecycle management of Smart Cards and Secure Elements
As part of the work, the group will cover at least the types of PwDE and their intended purposes in relation to use cases described in the list below. In addition, for some types of PwDE, expertise from external organizations which are recognized will be leveraged to ensure the project is relevant and in line with the reality of markets.
Type of the Product with Digital Elements:
1. Secure element, Smart Cards and similar devices for critical use cases – high risk profile
2. Secure element, Smart Cards and similar devices for critical use cases – low risk profile
3. Remote data processing systems / services
The list above is not finite, it represents initial state.
The work of the group will first focus on delivering precise scope related to intended purpose and dependant use cases, in collaboration with other standardisation workgroups and industry representatives.
Note on the use cases
- Standard may cover specific aspects of particular use cases
Note on risk profile
- The mapping of compliance criteria with EUCC may be given
- Standard may cover aspects of newer version of Common Criteria CC:2022, and other established schemes
- Draft60 pagesEnglish languagee-Library read for1 day
This document specifies the technical requirements for general-purposes tamper-resistant microprocessors and microcontrollers intended for integration into products that rely on them as a foundational security component. The microprocessors and microcontrollers in scope are designed for deployment in environments where the security features of the product integrating the platform are of importance, and where the threat landscape includes attackers with low but non-negligeable attack potential, corresponding to AVA_VAN.2 to AVA_VAN.3 as defined in [13].
- Draft102 pagesEnglish languagee-Library read for1 day
This document specifies the security assessment requirements for platforms that include microprocessors and microcontrollers with security-related functionalities. These platforms aim to secure other products/networks/services beyond the microprocessors and microcontrollers themselves and are intended to provide assurance at a level AVA_VAN.1 as defined in [2], or without AVA_VAN claim.
- Draft95 pagesEnglish languagee-Library read for1 day
The products with digital elements in the scope of this document are the platforms of smartcards and similar devices including secure elements, which consist of a tamper-resistant MCU/MPU and optionally an application environment or operating system. Platforms are designed to store and process sensitive data, and to protect it against physical and logical attacks by attackers with significant resources and skills, at AVA_VAN.4 (moderate attack potential) or AVA_VAN.5 (high attack potential) levels. Although platforms do not delegate data processing to remote entities, these can be involved in operations such as software update, configuration or key provisioning. The platform ensures the authentication of the remote entities before receiving/sending sensitive information and ensures this information is protected during the exchange.
Platforms are intended for final products including, but not limited to, electronic identity cards, removable UICCs, eUICC, payment cards, physical access cards, digital tachograph cards or wrist bands with integrated payment secure elements, trust anchors in connected digital products and critical IT systems.
This document defines technical requirements for platforms, which meet the essential requirements defined in Regulation (EU) 2024/2847 to the extent described in Annex ZZ. It also defines the methods for assessing the technical requirements.
The expression of the technical requirements and the assessment methods use the Common Criteria (CC) formalism defined in the EN ISO/IEC 15408 series and EN ISO/IEC 18045:2023 supplemented by the EUCC state-of-the-art documents for the technical domain smart cards and similar devices.
This document covers platforms conformant with the Protection Profiles (PPs) PP0084, PP0117, PP0104 and PP TPM, and identifies the gaps of these specifications against the CRA essential requirements. In this document, PP0104 also refers to the PP0104-based PP-Configuration 0107. The evaluation of platforms against PP0084, PP0117, PP0104 or PP TPM plus the applicable additional technical requirements which cover their gaps allow to demonstrate conformance with the CRA essential requirements. The technical requirements and the mappings against PP0084, PP0117, PP0104 and PP TPM are defined in Clause 7 and Annex B, respectively.
This document also covers platforms consisting of a hardware layer and either an application environment, e.g. Java Card platform, or firmware/software. Annex C contains an informative mapping of Java Card platforms towards PP0099.
Platforms can have discrete, integrated or embedded form factors, and employ technologies such as integrated circuits, programmable macros or system-in-package or system-on-chip. These do not affect the requirements or the assessment methods. Unless specified, clauses apply to all platforms, from pure hardware to platforms consisting of hardware, firmware and/or software.
Platforms are accompanied by guidance which contains all the requirements and recommendations for the secure integration of the platform into further intermediate or final products and the secure usage of the platform by the external entities. The guidance covers all the non-platform aspects which can impact the security of the platform assets.
The applications stored and/or running on the platforms, which are an integral part of the final products, are outside the scope of this document. prEN 18330:2026 applies to products composed of a platform and a set of applications.
- Draft144 pagesEnglish languagee-Library read for1 day
This standards shall provide specifications applicable to vulnerability handling processes, covering all relevant product categories, to
be put in place by manufacturers of the products with digital elements. Those processes shall at least allow to:
(a) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machinereadable format covering at the very least the top-level dependencies of the product;
(b) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;
(c) apply effective and regular tests and reviews of the security of the product with digital elements;
(d) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;
(e) put in place and enforce a policy on coordinated vulnerability disclosure;
(f) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a standardised contact address for the reporting of the
vulnerabilities discovered in the product with digital elements;
(g) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner, and, where applicable for security updates, in an automatic manner;
(h) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
- Draft37 pagesEnglish languagee-Library read for1 day
This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.
- Draft57 pagesEnglish languagee-Library read for1 day
This document provides the terms and definitions commonly used in the cybersecurity requirements for products with digital elements family of standards.
- Draft8 pagesEnglish languagee-Library read for1 day
This standards shall provide specifications applicable to vulnerability handling processes, covering all relevant product categories, to
be put in place by manufacturers of the products with digital elements. Those processes shall at least allow to:
(a) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machinereadable format covering at the very least the top-level dependencies of the product;
(b) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;
(c) apply effective and regular tests and reviews of the security of the product with digital elements;
(d) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;
(e) put in place and enforce a policy on coordinated vulnerability disclosure;
(f) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a standardised contact address for the reporting of the
vulnerabilities discovered in the product with digital elements;
(g) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner, and, where applicable for security updates, in an automatic manner;
(h) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
- Draft37 pagesEnglish languagee-Library read for1 day
Frequently Asked Questions
A European Standardization Mandate is a formal request from the European Commission to the European Standardization Organizations (CEN, CENELEC, and ETSI) to develop European standards (ENs) in support of EU legislation and policies. Mandates are issued under Regulation (EU) No 1025/2012 and help ensure that products and services meet the essential requirements set out in EU directives and regulations.
M/606 is a European Standardization Mandate titled "on a standardisation request to European Standards Organisations in support of Union policy on cybersecurity requirements for products with digital elements". on a standardisation request to European Standards Organisations in support of Union policy on cybersecurity requirements for products with digital elements There are 22 standards developed under this mandate.
Standards developed in response to a mandate and cited in the Official Journal of the European Union become "harmonized standards". Products manufactured in compliance with harmonized standards benefit from a presumption of conformity with the essential requirements of the corresponding EU directive or regulation, facilitating CE marking and market access across the European Economic Area.