General Information

Abstract

DEN/CYBER-EUS-0018

Status
Not Published
Public Enquiry End Date
30-Sep-2026
Current Stage
4020 - Public enquire (PE) (Adopted Project)
Start Date
03-Aug-2026
Due Date
21-Dec-2026

Buy Documents

Standard

ETSI EN 304 619 V1.0.0 (2026-07) - Cyber Security (CYBER); CRA; Cybersecurity requirements for software that searches for, removes, or quarantines malicious software

English language (194 pages)
sale 15% off
Preview
sale 15% off
Preview
Draft

oSIST prEN 304 619 V1.0.0:2026 - BARVE

English language (194 pages)
Preview
Preview
e-Library read for
×1 day

Overview

oSIST prEN 304 619 V1.0.0:2026, developed by SIST and harmonized by ETSI, defines the cybersecurity requirements for software products that search for, remove, or quarantine malicious software, including antivirus and antimalware solutions. This standard addresses technical and organizational measures to strengthen the protection against cyber threats, ensuring software handling threats operates securely and complies with the Cyber Resilience Act (CRA) and relevant European Union regulations.

The scope includes all software that detects, neutralizes, or isolates malware, with direct implications for software developers, vendors, integrators, and security professionals seeking compliance with European cybersecurity mandates.

Key Topics

  • Cybersecurity Requirements: Details essential security characteristics for antimalware and antivirus solutions, covering threat detection, removal, and quarantine functionalities.
  • Risk and Threat Analysis: Outlines methodologies to identify and mitigate risks such as vulnerabilities in updates, supply chain threats, core component exploits, and communication security.
  • Operational Contexts and Use Cases: Maps varied operational scenarios from limited to critical impact, recommending appropriate levels of protection for different environments.
  • Technical Controls: Specifies direct product requirements, including:
    • Secure default configurations
    • Regular security updates and patch management
    • Authentication and access control
    • Data confidentiality, integrity, and minimization
    • Availability and resilience
    • Attack surface reduction and exploit mitigation
    • Monitoring and audit trails
    • Factory reset and data portability
  • Assessment and Compliance: Provides guidelines for demonstrating adherence to the standard via structured assessment criteria.
  • Cryptographic Requirements: Specifies requirements for cryptography and crypto agility, ensuring resilience against evolving cryptographic threats.
  • Interoperability and Integration: Addresses security for software that integrates with third-party products or remote detection and protection services (RDPS).

Applications

Organizations and stakeholders can apply oSIST prEN 304 619 V1.0.0:2026 to:

  • Product Development: Guide the secure design and implementation of antimalware, antivirus, and endpoint protection software, focusing on minimizing exploitable vulnerabilities and ensuring robust protection mechanisms.
  • Compliance and Regulatory Alignment: Meet EU cybersecurity regulations, such as the Cyber Resilience Act, by adopting standardized security requirements and assessment processes.
  • Procurement and Vendor Assurance: Evaluate and compare security profiles of security software prior to purchase or integration, supporting transparent supplier relationships.
  • Risk Management: Conduct threat and risk analysis for operational environments, mapping recommended security controls to expected threat levels and impact contexts-critical for regulated sectors such as finance, healthcare, or energy.
  • Security Auditing and Certification: Use standardized assessment criteria to audit security software, facilitate certification, and drive continuous improvement in cybersecurity practices.

Related Standards

  • ETSI EN 303 645: Cybersecurity for consumer IoT devices, offering related guidance on product security.
  • EN ISO/IEC 27001: Information security management systems, framework for overarching organizational security controls.
  • EN ISO/IEC 15408 (Common Criteria): International standard for IT security evaluation, referenced for security functional requirements.
  • EU Regulation 2024/2847 (Cyber Resilience Act): Sets the essential cybersecurity requirements for products with digital elements in the European Union.
  • ISO/IEC 29147 and ISO/IEC 30111: Standards for vulnerability disclosure and security incident handling processes.

Adopting oSIST prEN 304 619 V1.0.0:2026 enables organizations to build, procure, and operate malware defence solutions with robust, harmonized cybersecurity postures, ensuring compliance, trustworthiness, and resilience in digital operations across multiple sectors. For the latest authoritative text and updates, refer to the official ETSI standards repository.

Buy Documents

Standard

ETSI EN 304 619 V1.0.0 (2026-07) - Cyber Security (CYBER); CRA; Cybersecurity requirements for software that searches for, removes, or quarantines malicious software

English language (194 pages)
sale 15% off
Preview
sale 15% off
Preview
Draft

oSIST prEN 304 619 V1.0.0:2026 - BARVE

English language (194 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

oSIST prEN 304 619 V1.0.0:2026 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Cyber Security (CYBER) - CRA - Cybersecurity requirements for software that searches for, removes, or quarantines malicious software". This standard covers: DEN/CYBER-EUS-0018

DEN/CYBER-EUS-0018

oSIST prEN 304 619 V1.0.0:2026 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security. The ICS classification helps identify the subject area and facilitates finding related standards.

oSIST prEN 304 619 V1.0.0:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Draft ETSI EN 304 619 V1.0.0 (2026-07)

HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements for software that searches for,
removes, or quarantines malicious software

2 Draft ETSI EN 304 619 V1.0.0 (2026-07)

Reference
DEN/CYBER-EUS-0018
Keywords
antimalware, antivirus, CRA, cybersecurity,
security analysis, security profiles,
security requirements, threat analysis, use cases

ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.

© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 619 V1.0.0 (2026-07)
Contents
Intellectual Property Rights . 8
Foreword . 8
Modal verbs terminology . 9
Introduction . 9
1 Scope . 10
2 References . 10
2.1 Normative references . 10
2.2 Informative references . 11
3 Definition of terms, symbols and abbreviations . 12
3.1 Terms . 12
3.2 Symbols . 13
3.3 Abbreviations . 13
4 Product context . 16
4.0 Introduction . 16
4.1 Product Functions . 16
4.2 Product Architecture. 16
4.3 Operational Environment . 17
4.3.1 General description . 17
4.3.2 Physical/Hardware environment . 18
4.3.3 Logical/Software environment. 18
4.3.4 Connectivity aspects . 19
4.4 Distribution of Security Functions . 20
4.4.1 Cybersecurity Functionalities Offered to Other Products . 20
4.4.2 Cybersecurity Functionalities Required from Other Products . 20
4.5 Users . 20
4.6 Use Cases . 21
4.6.1 Introduction. 21
4.6.2 UC1: Limited Operational Context . 21
4.6.3 UC2: Baseline Operational Context . 22
4.6.4 UC3: Elevated Operational Context . 22
4.6.5 UC4: High Value Operational Context . 22
4.6.6 UC5: Critical Operational Context . 22
4.6.7 Use cases to risk factors and risk levels mapping . 22
5 Technical requirements for products . 23
5.1 Introduction - Applicability of the requirements . 23
5.2 Appropriate level of cybersecurity . 23
5.3 No known exploitable vulnerabilities . 23
5.4 Secure by default configuration . 24
5.5 Security updates . 24
5.6 Authentication and access control . 26
5.7 Confidentiality protection . 27
5.8 Integrity protection . 28
5.9 Data minimisation . 28
5.10 Availability protection . 28
5.11 Non-interference . 29
5.12 Attack surface minimisation . 30
5.13 Exploit mitigation . 30
5.14 Monitoring . 31
5.15 Factory reset and data portability . 31
6 Assessment criteria for compliance with technical requirements . 32
6.1 Introduction to the assessment and compliance criteria . 32
6.1.0 Assessment guide . 32
ETSI
4 Draft ETSI EN 304 619 V1.0.0 (2026-07)
6.1.1 Inability to comply with assessment methodology . 33
6.2 Appropriate level of cybersecurity . 34
6.3 No known exploitable vulnerabilities . 34
6.3.1 REQ-KEV-01 . 34
6.4 Secure by default configuration . 36
6.4.1 REQ-SBD-01 . 36
6.4.2 REQ-SBD-02 . 38
6.4.3 REQ-SBD-03 . 39
6.4.4 REQ-SBD-04 . 41
6.4.5 REQ-SBD-05 . 43
6.5 Security updates . 43
6.5.1 REQ-SU-01. 43
6.5.2 REQ-SU-02. 45
6.5.3 REQ-SU-03. 48
6.5.4 REQ-SU-04. 49
6.5.5 REQ-SU-05. 52
6.5.6 REQ-SU-06. 54
6.5.7 REQ-SU-07. 56
6.5.8 REQ-SU-08. 58
6.5.9 REQ-SU-09. 60
6.6 Authentication and access control . 61
6.6.1 REQ-AAC-01 . 61
6.6.2 REQ-AAC-02 . 63
6.6.3 REQ-AAC-03 . 65
6.6.4 REQ-AAC-04 . 66
6.6.5 REQ-AAC-05 . 68
6.6.6 REQ-AAC-06 . 70
6.6.7 REQ-AAC-07 . 71
6.6.8 REQ-AAC-08 . 73
6.6.9 REQ-AAC-09 . 75
6.6.10 REQ-AAC-10 . 76
6.6.11 REQ-AAC-11 . 78
6.7 Confidentiality protection . 80
6.7.1 REQ-CON-01 . 80
6.7.2 REQ-CON-02 . 82
6.7.3 REQ-CON-03 . 85
6.7.4 REQ-CON-04 . 87
6.8 Integrity protection . 88
6.8.1 REQ-INT-01 . 88
6.8.2 REQ-INT-02 . 90
6.9 Data minimisation . 92
6.9.1 REQ-DM-01 . 92
6.10 Availability protection . 93
6.10.1 REQ-AP-01. 93
6.10.2 REQ-AP-02. 95
6.10.3 REQ-AP-03. 97
6.10.4 REQ-AP-04. 98
6.11 Non-interference . 101
6.11.1 REQ-NI-01 . 101
6.11.2 REQ-NI-02 . 102
6.12 Attack surface minimisation . 104
6.12.1 REQ-ASM-01 . 104
6.12.2 REQ-ASM-02 . 106
6.12.3 REQ-ASM-03 . 107
6.13 Exploit mitigation . 109
6.13.1 REQ-EM-01 . 109
6.13.2 REQ-EM-02 . 111
6.14 Monitoring . 112
6.14.1 REQ-MON-01 . 112
6.14.2 REQ-MON-02 . 114
6.14.3 REQ-MON-03 . 116
6.14.4 REQ-MON-04 . 117
ETSI
5 Draft ETSI EN 304 619 V1.0.0 (2026-07)
6.14.5 REQ-MON-05 . 119
6.14.6 REQ-MON-06 . 121
6.15 Factory reset and data portability . 122
6.15.1 REQ-FRD-01 . 122
6.15.2 REQ-FRD-02 . 124
Annex A (informative): Relationship between the present document and the essential
cybersecurity requirements of EU Regulation (EU) 2024/2847 . 126
Annex B (informative): Security analysis . 130
B.0 Introduction . 130
B.1 Threats and Risk Factors Landscape . 130
B.1.1 Threats . 130
B.1.1.1 Introduction. 130
B.1.1.2 TH1 - Threats related to Updates and Signatures . 130
B.1.1.3 TH2 - Threats to Core Components and Self-Protection . 130
B.1.1.4 TH3 - Threats to Communication and Data Exchange . 131
B.1.1.5 TH4 - Supply Chain and Third-Party Component Threats . 131
B.1.1.6 TH5 - Advanced Threat Actor Techniques . 131
B.1.1.7 TH6 - User-Facing Threats . 131
B.1.2 Risks Factors . 132
B.1.2.1 Introduction. 132
B.1.2.2 Likelihood-related Risk Factors . 132
B.1.2.3 Magnitude-related Risk Factors . 133
B.1.3 Threat justification and mitigation . 134
B.2 Security Profiles . 135
B.2.1 General . 135
B.2.2 Minimal Cybersecurity . 135
B.2.3 Medium Cybersecurity . 136
B.2.4 High Cybersecurity. 136
B.3 Information on the methodology for the security analysis of cybersecurity risks used to develop
the present document . 136
B.3.1 Principles and references . 136
B.3.2 Risk model. 137
B.3.3 Risk criteria . 137
B.3.3.1 Introduction. 137
B.3.3.2 Risk Likelihood (L) . 137
B.3.3.3 Magnitude of loss or disruption (M) . 137
B.3.3.4 Qualitative risk matrix . 138
B.3.4 Process . 138
B.3.5 Risk computation and mapping . 138
B.3.6 Example of Risk Analysis . 139
B.4 Use Cases Security Analysis . 140
B.4.1 Introduction . 140
B.4.2 UC1: Limited Impact Context . 140
B.4.3 UC2: Baseline Impact Context . 141
B.4.4 UC3: Elevated Impact Context . 142
B.4.5 UC4: High Impact Context . 143
B.4.6 UC5: Critical Impact Context . 144
Annex C (informative): Relationship between the present document and any related ETSI
standards . 146
Annexes D to F: Void . 147
Annex G (informative): Guidelines on the implementation of the present document . 148
Annexes H to J: Void . 150
ETSI
6 Draft ETSI EN 304 619 V1.0.0 (2026-07)
Annex K (normative): Generic cryptographic requirements and assessment . 151
K.1 Cryptography . 151
K.1.1 Requirement . 151
K.1.2 Assessment of product cryptographic configuration . 152
K.1.2.0 General . 152
K.1.2.1 Assessment of ACM-listed cryptographic mechanisms. 152
K.1.2.1.1 Assessment objective . 152
K.1.2.1.2 Assessment preparation . 152
K.1.2.1.3 Assessment activities . 152
K.1.2.1.4 Assessment evidence . 153
K.1.2.1.5 Assessment verdict . 153
K.1.2.2 Assessment of ACM-extended cryptographic mechanisms . 153
K.1.2.2.1 Assessment objective . 153
K.1.2.2.2 Assessment preparation . 153
K.1.2.2.3 Assessment activities . 153
K.1.2.2.4 Assessment evidence . 154
K.1.2.2.5 Assessment verdict . 154
K.1.2.3 Assessment of interoperability-based cryptographic mechanisms . 154
K.1.2.3.1 Assessment objective . 154
K.1.2.3.2 Assessment preparation . 154
K.1.2.3.3 Assessment activities . 154
K.1.2.3.4 Assessment evidence . 155
K.1.2.3.5 Assessment verdict . 155
K.2 Crypto agility . 155
K.2.1 Requirement . 155
K.2.2 Assessment of crypto-agility . 156
K.2.2.1 Assessment objective . 156
K.2.2.2 Assessment preparation . 156
K.2.2.3 Assessment activities . 157
K.2.2.4 Assessment evidence . 157
K.2.2.5 Assessment verdict . 157
K.3 ACM-extended cryptographic mechanisms . 157
K.3.1 Requirement . 157
K.3.2 List of ACM-extended cryptographic mechanisms . 157
K.3.3 Assessment . 158
K.4 Interoperability-based cryptographic mechanisms . 159
K.4.1 Requirement . 159
K.4.2 List of interoperability-based cryptographic mechanisms . 159
K.4.3 Assessment . 159
Annexes L to Q: Void . 160
Annex R (normative): Requirements on RDPS . 161
R.0 Introduction . 161
R.1 RDPS as a product-boundary extension . 161
R.2 Threat Model . 162
R.2.0 Introduction . 162
R.2.1 Assets . 162
R.2.2 Threat catalogue . 163
R.2.3 Assets and Threats Mapping . 164
R.3 Security Requirements . 164
R.3.1 General . 164
R.3.2 Applicability of Annex R requirements . 164
R.3.3 Local product side requirements . 165
R.3.3.1 Data authenticity of interactions received from the RDPS side . 165
R.3.3.2 Integrity of interactions received from the RDPS side . 166
R.3.3.3 Confidentiality of data exchanged with the RDPS side . 166
ETSI
7 Draft ETSI EN 304 619 V1.0.0 (2026-07)
R.3.3.4 Availability . 167
R.3.4 RDPS side requirements . 167
R.3.4.1 Data authenticity of interactions received from the local product side . 167
R.3.4.2 Integrity of interactions received from the local product side. 168
R.3.4.3 Confidentiality of data exchanged with the local product side . 168
R.3.4.4 Availability . 169
R.3.5 Mapping of Threats and Requirements . 170
R.4 Conformity assessment. 170
R.4.1 Local product side requirements . 170
R.4.1.1 REQ-RDPS-L-AUTH-001 . 170
R.4.1.2 REQ-RDPS-L-AUTH-002 . 171
R.4.1.3 REQ-RDPS-L-AUTH-003 . 172
R.4.1.4 REQ-RDPS-L-INTEG-001 . 173
R.4.1.5 REQ-RDPS-L-INTEG-002 . 174
R.4.1.6 REQ-RDPS-L-INTEG-003 . 174
R.4.1.7 REQ-RDPS-L-CONF-001 . 175
R.4.1.8 REQ-RDPS-L-CONF-002 . 176
R.4.1.9 REQ-RDPS-L-CONF-003 . 177
R.4.1.10 REQ-RDPS-L-AVAIL-001 . 178
R.4.1.11 REQ-RDPS-L-AVAIL-002 . 179
R.4.1.12 REQ-RDPS-L-AVAIL-003 . 180
R.4.2 RDPS side requirements . 181
R.4.2.1 REQ-RDPS-R-AUTH-001 . 181
R.4.2.2 REQ-RDPS-R-AUTH-002 . 182
R.4.2.3 REQ-RDPS-R-AUTH-003 . 183
R.4.2.4 REQ-RDPS-R-INTEG-001 . 184
R.4.2.5 REQ-RDPS-R-INTEG-002 . 184
R.4.2.6 REQ-RDPS-R-INTEG-003 . 185
R.4.2.7 REQ-RDPS-R-CONF-001 . 186
R.4.2.8 REQ-RDPS-R-CONF-002 . 187
R.4.2.9 REQ-RDPS-R-CONF-003 . 188
R.4.2.10 REQ-RDPS-R-AVAIL-001 . 189
R.4.2.11 REQ-RDPS-R-AVAIL-002 . 190
R.4.2.12 REQ-RDPS-R-AVAIL-003 . 190
Annex S (informative): Change history . 192
History . 194

ETSI
8 Draft ETSI EN 304 619 V1.0.0 (2026-07)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables (European Standard (EN), Technical Specification (TS),
Group Specification (GS) or ETSI Standard (ES)) may have been declared to ET
...


SLOVENSKI STANDARD
01-september-2026
Kibernetska varnost (CYBER) - CRA - Zahteve za kibernetsko varnost za
programsko opremo, ki išče, odstranjuje ali daje zlonamerno programsko opremo
v karanteno
Cyber Security (CYBER) - CRA - Cybersecurity requirements for software that searches
for, removes, or quarantines malicious software
Ta slovenski standard je istoveten z: ETSI EN 304 619 V1.0.0 (2026-07)
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

Draft ETSI EN 304 619 V1.0.0 (2026-07)

HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements for software that searches for,
removes, or quarantines malicious software

2 Draft ETSI EN 304 619 V1.0.0 (2026-07)

Reference
DEN/CYBER-EUS-0018
Keywords
antimalware, antivirus, CRA, cybersecurity,
security analysis, security profiles,
security requirements, threat analysis, use cases

ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.

© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 619 V1.0.0 (2026-07)
Contents
Intellectual Property Rights . 8
Foreword . 8
Modal verbs terminology . 9
Introduction . 9
1 Scope . 10
2 References . 10
2.1 Normative references . 10
2.2 Informative references . 11
3 Definition of terms, symbols and abbreviations . 12
3.1 Terms . 12
3.2 Symbols . 13
3.3 Abbreviations . 13
4 Product context . 16
4.0 Introduction . 16
4.1 Product Functions . 16
4.2 Product Architecture. 16
4.3 Operational Environment . 17
4.3.1 General description . 17
4.3.2 Physical/Hardware environment . 18
4.3.3 Logical/Software environment. 18
4.3.4 Connectivity aspects . 19
4.4 Distribution of Security Functions . 20
4.4.1 Cybersecurity Functionalities Offered to Other Products . 20
4.4.2 Cybersecurity Functionalities Required from Other Products . 20
4.5 Users . 20
4.6 Use Cases . 21
4.6.1 Introduction. 21
4.6.2 UC1: Limited Operational Context . 21
4.6.3 UC2: Baseline Operational Context . 22
4.6.4 UC3: Elevated Operational Context . 22
4.6.5 UC4: High Value Operational Context . 22
4.6.6 UC5: Critical Operational Context . 22
4.6.7 Use cases to risk factors and risk levels mapping . 22
5 Technical requirements for products . 23
5.1 Introduction - Applicability of the requirements . 23
5.2 Appropriate level of cybersecurity . 23
5.3 No known exploitable vulnerabilities . 23
5.4 Secure by default configuration . 24
5.5 Security updates . 24
5.6 Authentication and access control . 26
5.7 Confidentiality protection . 27
5.8 Integrity protection . 28
5.9 Data minimisation . 28
5.10 Availability protection . 28
5.11 Non-interference . 29
5.12 Attack surface minimisation . 30
5.13 Exploit mitigation . 30
5.14 Monitoring . 31
5.15 Factory reset and data portability . 31
6 Assessment criteria for compliance with technical requirements . 32
6.1 Introduction to the assessment and compliance criteria . 32
6.1.0 Assessment guide . 32
ETSI
4 Draft ETSI EN 304 619 V1.0.0 (2026-07)
6.1.1 Inability to comply with assessment methodology . 33
6.2 Appropriate level of cybersecurity . 34
6.3 No known exploitable vulnerabilities . 34
6.3.1 REQ-KEV-01 . 34
6.4 Secure by default configuration . 36
6.4.1 REQ-SBD-01 . 36
6.4.2 REQ-SBD-02 . 38
6.4.3 REQ-SBD-03 . 39
6.4.4 REQ-SBD-04 . 41
6.4.5 REQ-SBD-05 . 43
6.5 Security updates . 43
6.5.1 REQ-SU-01. 43
6.5.2 REQ-SU-02. 45
6.5.3 REQ-SU-03. 48
6.5.4 REQ-SU-04. 49
6.5.5 REQ-SU-05. 52
6.5.6 REQ-SU-06. 54
6.5.7 REQ-SU-07. 56
6.5.8 REQ-SU-08. 58
6.5.9 REQ-SU-09. 60
6.6 Authentication and access control . 61
6.6.1 REQ-AAC-01 . 61
6.6.2 REQ-AAC-02 . 63
6.6.3 REQ-AAC-03 . 65
6.6.4 REQ-AAC-04 . 66
6.6.5 REQ-AAC-05 . 68
6.6.6 REQ-AAC-06 . 70
6.6.7 REQ-AAC-07 . 71
6.6.8 REQ-AAC-08 . 73
6.6.9 REQ-AAC-09 . 75
6.6.10 REQ-AAC-10 . 76
6.6.11 REQ-AAC-11 . 78
6.7 Confidentiality protection . 80
6.7.1 REQ-CON-01 . 80
6.7.2 REQ-CON-02 . 82
6.7.3 REQ-CON-03 . 85
6.7.4 REQ-CON-04 . 87
6.8 Integrity protection . 88
6.8.1 REQ-INT-01 . 88
6.8.2 REQ-INT-02 . 90
6.9 Data minimisation . 92
6.9.1 REQ-DM-01 . 92
6.10 Availability protection . 93
6.10.1 REQ-AP-01. 93
6.10.2 REQ-AP-02. 95
6.10.3 REQ-AP-03. 97
6.10.4 REQ-AP-04. 98
6.11 Non-interference . 101
6.11.1 REQ-NI-01 . 101
6.11.2 REQ-NI-02 . 102
6.12 Attack surface minimisation . 104
6.12.1 REQ-ASM-01 . 104
6.12.2 REQ-ASM-02 . 106
6.12.3 REQ-ASM-03 . 107
6.13 Exploit mitigation . 109
6.13.1 REQ-EM-01 . 109
6.13.2 REQ-EM-02 . 111
6.14 Monitoring . 112
6.14.1 REQ-MON-01 . 112
6.14.2 REQ-MON-02 . 114
6.14.3 REQ-MON-03 . 116
6.14.4 REQ-MON-04 . 117
ETSI
5 Draft ETSI EN 304 619 V1.0.0 (2026-07)
6.14.5 REQ-MON-05 . 119
6.14.6 REQ-MON-06 . 121
6.15 Factory reset and data portability . 122
6.15.1 REQ-FRD-01 . 122
6.15.2 REQ-FRD-02 . 124
Annex A (informative): Relationship between the present document and the essential
cybersecurity requirements of EU Regulation (EU) 2024/2847 . 126
Annex B (informative): Security analysis . 130
B.0 Introduction . 130
B.1 Threats and Risk Factors Landscape . 130
B.1.1 Threats . 130
B.1.1.1 Introduction. 130
B.1.1.2 TH1 - Threats related to Updates and Signatures . 130
B.1.1.3 TH2 - Threats to Core Components and Self-Protection . 130
B.1.1.4 TH3 - Threats to Communication and Data Exchange . 131
B.1.1.5 TH4 - Supply Chain and Third-Party Component Threats . 131
B.1.1.6 TH5 - Advanced Threat Actor Techniques . 131
B.1.1.7 TH6 - User-Facing Threats . 131
B.1.2 Risks Factors . 132
B.1.2.1 Introduction. 132
B.1.2.2 Likelihood-related Risk Factors . 132
B.1.2.3 Magnitude-related Risk Factors . 133
B.1.3 Threat justification and mitigation . 134
B.2 Security Profiles . 135
B.2.1 General . 135
B.2.2 Minimal Cybersecurity . 135
B.2.3 Medium Cybersecurity . 136
B.2.4 High Cybersecurity. 136
B.3 Information on the methodology for the security analysis of cybersecurity risks used to develop
the present document . 136
B.3.1 Principles and references . 136
B.3.2 Risk model. 137
B.3.3 Risk criteria . 137
B.3.3.1 Introduction. 137
B.3.3.2 Risk Likelihood (L) . 137
B.3.3.3 Magnitude of loss or disruption (M) . 137
B.3.3.4 Qualitative risk matrix . 138
B.3.4 Process . 138
B.3.5 Risk computation and mapping . 138
B.3.6 Example of Risk Analysis . 139
B.4 Use Cases Security Analysis . 140
B.4.1 Introduction . 140
B.4.2 UC1: Limited Impact Context . 140
B.4.3 UC2: Baseline Impact Context . 141
B.4.4 UC3: Elevated Impact Context . 142
B.4.5 UC4: High Impact Context . 143
B.4.6 UC5: Critical Impact Context . 144
Annex C (informative): Relationship between the present document and any related ETSI
standards . 146
Annexes D to F: Void . 147
Annex G (informative): Guidelines on the implementation of the present document . 148
Annexes H to J: Void . 150
ETSI
6 Draft ETSI EN 304 619 V1.0.0 (2026-07)
Annex K (normative): Generic cryptographic requirements and assessment . 151
K.1 Cryptography . 151
K.1.1 Requirement . 151
K.1.2 Assessment of product cryptographic configuration . 152
K.1.2.0 General . 152
K.1.2.1 Assessment of ACM-listed cryptographic mechanisms. 152
K.1.2.1.1 Assessment objective . 152
K.1.2.1.2 Assessment preparation . 152
K.1.2.1.3 Assessment activities . 152
K.1.2.1.4 Assessment evidence . 153
K.1.2.1.5 Assessment verdict . 153
K.1.2.2 Assessment of ACM-extended cryptographic mechanisms . 153
K.1.2.2.1 Assessment objective . 153
K.1.2.2.2 Assessment preparation . 153
K.1.2.2.3 Assessment activities . 153
K.1.2.2.4 Assessment evidence . 154
K.1.2.2.5 Assessment verdict . 154
K.1.2.3 Assessment of interoperability-based cryptographic mechanisms . 154
K.1.2.3.1 Assessment objective . 154
K.1.2.3.2 Assessment preparation . 154
K.1.2.3.3 Assessment activities . 154
K.1.2.3.4 Assessment evidence . 155
K.1.2.3.5 Assessment verdict . 155
K.2 Crypto agility . 155
K.2.1 Requirement . 155
K.2.2 Assessment of crypto-agility . 156
K.2.2.1 Assessment objective . 156
K.2.2.2 Assessment preparation . 156
K.2.2.3 Assessment activities . 157
K.2.2.4 Assessment evidence . 157
K.2.2.5 Assessment verdict . 157
K.3 ACM-extended cryptographic mechanisms . 157
K.3.1 Requirement . 157
K.3.2 List of ACM-extended cryptographic mechanisms . 157
K.3.3 Assessment . 158
K.4 Interoperability-based cryptographic mechanisms . 159
K.4.1 Requirement . 159
K.4.2 List of interoperability-based cryptographic mechanisms . 159
K.4.3 Assessment . 159
Annexes L to Q: Void . 160
Annex R (normative): Requirements on RDPS . 161
R.0 Introduction . 161
R.1 RDPS as a product-boundary extension . 161
R.2 Threat Model . 162
R.2.0 Introduction . 162
R.2.1 Assets . 162
R.2.2 Threat catalogue . 163
R.2.3 Assets and Threats Mapping . 164
R.3 Security Requirements . 164
R.3.1 General . 164
R.3.2 Applicability of Annex R requirements . 164
R.3.3 Local product side requirements . 165
R.3.3.1 Data authenticity of interactions received from the RDPS side . 165
R.3.3.2 Integrity of interactions received from the RDPS side . 166
R.3.3.3 Confidentiality of data exchanged with the RDPS side . 166
ETSI
7 Draft ETSI EN 304 619 V1.0.0 (2026-07)
R.3.3.4 Availability . 167
R.3.4 RDPS side requirements . 167
R.3.4.1 Data authenticity of interactions received from the local product side . 167
R.3.4.2 Integrity of interactions received from the local product side. 168
R.3.4.3 Confidentiality of data exchanged with the local product side . 168
R.3.4.4 Availability . 169
R.3.5 Mapping of Threats and Requirements . 170
R.4 Conformity assessment. 170
R.4.1 Local product side requirements . 170
R.4.1.1 REQ-RDPS-L-AUTH-001 . 170
R.4.1.2 REQ-RDPS-L-AUTH-002 . 171
R.4.1.3 REQ-RDPS-L-AUTH-003 . 172
R.4.1.4 REQ-RDPS-L-INTEG-001 . 173
R.4.1.5 REQ-RDPS-L-INTEG-002 . 174
R.4.1.6 REQ-RDPS-L-INTEG-003 . 174
R.4.1.7 REQ-RDPS-L-CONF-001 . 175
R.4.1.8 REQ-RDPS-L-CONF-002 . 176
R.4.1.9 REQ-RDPS-L-CONF-003 . 177
R.4.1.10 REQ-RDPS-L-AVAIL-001 . 178
R.4.1.11 REQ-RDPS-L-AVAIL-002 . 179
R.4.1.12 REQ-RDPS-L-AVAIL-003 . 180
R.4.2 RDPS side requirements . 181
R.4.2.1 REQ-RDPS-R-AUTH-001 . 181
R.4.2.2 REQ-RDPS-R-AUTH-002 . 182
R.4.2.3 REQ-RDPS-R-AUTH-003 . 183
R.4.2.4 REQ-RDPS-R-INTEG-001 . 184
R.4.2.5 REQ-RDPS-R-INTEG-002 . 184
R.4.2.6 REQ-RDPS-R-INTEG-003 . 185
R.4.2.7 REQ-RDPS-R-CONF-001 . 186
R.4.2.8 REQ-RDPS-R-CONF-002 . 187
R.4.2.9 REQ-RDPS-R-CONF-003 . 188
R.4.2.10 REQ-RDPS-R-AVAIL-001 .
...