General

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for software products 
with digital elements that detect or search for malicious software or code on a device, or remove or quarantine such 
software or code to prevent or mitigate system infection related to cybersecurity. The products with digital elements in 
scope, thereafter "the product": 
• are specified within the "technical description" of the "category of product" number "4" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: - 
"Software products with digital elements, typically referred to as antivirus or antimalware, that detect or 
search for malicious software or code on devices, or remove or quarantine such software or code, in 
order to maintain the integrity, confidentiality, or availability of such devices. 
In the context of this category of products, malicious software means software containing malicious 
features or capabilities that can cause harm directly or indirectly to the user and/or the computer system, 
such as viruses, worms, ransomware, spyware and trojans. 
This category includes but is not limited to software that detects or searches for malicious software in 
real-time or manually, rootkit detection and rescue disks with the core functionality of searching, 
removing or quarantining malicious software." 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A. 
The present document specifies technical characteristics and methods of assessment for Antivirus/Antimalware 
products. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 14 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for personal wearable 
products that have a health monitoring purpose or that are intended for the use by and for children, related to 
cybersecurity. The products with digital elements in scope, thereafter "personal wearable": 
• are specified within the "technical description" of the "category of product" number "19" by the Commission 
Implementing Regulation (EU) 2025/2392 of 28 November 2025 [i.2] as: 
"Personal wearable products to be worn or placed on a human body that have a health monitoring (such as 
tracking) purpose and to which Regulation (EU) 2017/745(2)or (EU) 2017/746 of the European Parliament 
and of the Council do not apply, or personal wearable products that are intended for the use by and for 
children". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.