General
The present document specifies technical requirements and corresponding assessment criteria for software products
with digital elements that detect or search for malicious software or code on a device, or remove or quarantine such
software or code to prevent or mitigate system infection related to cybersecurity. The products with digital elements in
scope, thereafter "the product":
• are specified within the "technical description" of the "category of product" number "4" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: -
"Software products with digital elements, typically referred to as antivirus or antimalware, that detect or
search for malicious software or code on devices, or remove or quarantine such software or code, in
order to maintain the integrity, confidentiality, or availability of such devices.
In the context of this category of products, malicious software means software containing malicious
features or capabilities that can cause harm directly or indirectly to the user and/or the computer system,
such as viruses, worms, ransomware, spyware and trojans.
This category includes but is not limited to software that detects or searches for malicious software in
real-time or manually, rootkit detection and rescue disks with the core functionality of searching,
removing or quarantining malicious software."
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A.
The present document specifies technical characteristics and methods of assessment for Antivirus/Antimalware
products.
The present document specifies vulnerability handling activities, technical requirements and corresponding assessment
criteria for smart home general purpose virtual assistants related to cybersecurity. The products with digital elements in
scope, thereafter "smart home general purpose virtual assistants":
• are specified within the "technical description" of the "category of product" number "16." by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements that communicate on the public Internet, whether directly or via other
equipment, that process demands, tasks or questions based on natural language prompts, such as through audio
or written input, and that, based on those demands, tasks or questions, provide access to other services or
control the functions of connected devices in residential settings.
This category includes but is not limited to smart speakers with an integrated virtual assistant, and standalone
virtual assistants that meet this description"; and
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A
The present document specifies vulnerability handling activities, technical requirements and corresponding assessment
criteria for smart home products with security functionalities related to cybersecurity. The products with digital
elements in scope, thereafter "smart home products with security functionalities":
• are specified within the "technical description" of the "category of product" number "17." by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements that protect the physical security of consumers in a residential setting and
which can be controlled or managed remotely from other systems, as well as hardware and software that
centrally control such products.
This category includes but is not limited to smart door locking devices, baby monitoring systems, alarm
systems and home security cameras"; and
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in clause A.
The present document specifies vulnerability handling activities, technical requirements and corresponding assessment
criteria for internet connected toys related to cybersecurity. The products with digital elements in scope, thereafter
"internet connected toys":
• are specified within the "technical description" of the "category of product" number "18." by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Internet connected toys that have social interactive features are products with digital elements that are
covered by Directive 2009/48/EC, that communicate on the public Internet, whether directly or via any other
equipment, and that have embedded technologies that enable inbound and outbound communication, such as
keyboard, microphone, speaker or camera." or "Internet connected toys that have location tracking features are
products with digital elements that are covered by Directive 2009/48/EC, that communicate on the public
Internet, whether directly or via any other equipment, and that have technologies that enable tracking or
inferring of the geographical location of the toy or its user. Where the toy merely detects the proximity of the
user or of other toys by using sensing technologies, the toy is not to be considered to have location tracking
features." and
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] under the conditions identified in annex A.
The present document specifies technical requirements and corresponding assessment criteria for personal wearable
products that have a health monitoring purpose or that are intended for the use by and for children, related to
cybersecurity. The products with digital elements in scope, thereafter "personal wearable":
• are specified within the "technical description" of the "category of product" number "19" by the Commission
Implementing Regulation (EU) 2025/2392 of 28 November 2025 [i.2] as:
"Personal wearable products to be worn or placed on a human body that have a health monitoring (such as
tracking) purpose and to which Regulation (EU) 2017/745(2)or (EU) 2017/746 of the European Parliament
and of the Council do not apply, or personal wearable products that are intended for the use by and for
children".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
The present document specifies technical requirements and corresponding assessment criteria for public key
infrastructure and digital certificate issuance software related to cybersecurity. The products with digital elements in
scope, thereafter "the Products":
• are specified within the "technical description" of the "category of product" number "9" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements used as part of a public key infrastructure (PKI) that manage the validation,
creation, issuance, distribution, status publication, renewal or revocation of digital certificates, or the
generation, storage, escrow, exchange, destruction or rotation of cryptographic keys associated with such
digital certificates. This category includes but is not limited to key management systems, digital certificate
management systems, online certificate status protocol responders and all-in-one PKI solutions".
• are only covered within the product context described in clause 4.
The present document covers those Products to demonstrate compliance with essential cybersecurity requirements in
the Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
Different use cases representing different product architecture are presented in clause 4.6. Requirements applicability in
clause 5 then defines which requirements apply to which use case to ensure compliance with the CRA's essential
cybersecurity requirements.
The present document specifies technical requirements and corresponding assessment criteria for physical and virtual
network interfaces related to cybersecurity. The products with digital elements in scope, thereafter "network interfaces":
• are specified within the "technical description" of the "category of product" number "10" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Physical network interfaces are products with digital elements that directly connect a device to a network via
an Application Programming Interface (API) provided by the interface drivers, typically operating at the data
link layer, and that feature hardware adapters to transmission media with corresponding firmware, typically
operating at the physical and data link layer.
Virtual network interfaces are products with digital elements that directly or indirectly connect a device to a
network via an API that emulates that of drivers of physical network interfaces, typically operating at the data
link layer.
This category includes but is not limited to wired and wireless network interface cards, controllers and
adapters, such as for Wi-Fi®, Ethernet, IrDA, USB, Bluetooth, NearLink, Zigbee®, or Fieldbus, as well as
purely virtual standalone products, such as virtual network interface cards, container network interfaces and
VPN interfaces".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I Part I under the conditions identified in Annex A.
Network interfaces intended for use in the industrial Operational Technology (OT) domain are excluded from the scope
of the present document, see prEN 50770 series [i.5].
Network interfaces whose intended purpose includes management or configuration of the product over the attached
network are excluded from the present document.
Network interfaces whose intended purpose includes routing, switching; or transfer of information from one attached
network to a different attached network are excluded from the present document.
The present document specifies technical requirements and corresponding assessment criteria for web browsers related
to cybersecurity. The products with digital elements in scope, thereafter "the products" are specified within the
"technical description" of the "category of product" number "2" by the Commission Implementing Regulation (EU)
2025/2392 [i.2] as:
• "Software products with digital elements that enable end users to access, render, and interact with web content
and services hosted on servers that are connected to networks such as the Internet. They typically include a
browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for
web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of
temporary or persistent data from websites (cookies).
This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded
browsers intended for integration into another system or application as well as browsers with AI agent integration."
The products are only covered within the product context described in clause 4. The present document specifies
technical characteristics and methods of assessment for:
• Standalone web browsers: standalone applications that fulfil the functions of web browsers
• Embedded web browsers: embedded browsers intended for integration into another system or application
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
Browsers with AI agent integration are out of the scope of the present document as well.
The present document specifies technical requirements and corresponding assessment criteria for Virtual Private
Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs":
• are specified within the "technical description" of the "category of product" number "5" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that establish an encrypted
logical tunnel that is constructed from the system resources of a physical or virtual network".
• are only covered within the product context described in clause 4 and the text of this clause.
In particular, the present document specifies technical characteristics and methods of assessment for:
1)
2)
3)
4)
Software that operates as a VPN client or endpoint
Software that operates as a node within a mesh VPN network
Software that operates as a VPN server
Remote data processing, specifically VPN server software performing the logical server role, and associated
software used for such VPN products
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document.
VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
The present document specifies technical requirements and corresponding assessment criteria for Network Management
Systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":
• are specified within the "technical description" of the "category of product" number "6" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that manage connected
network elements, such as servers, routers, switches, workstations, printers or mobile devices, by monitoring
them and controlling their network operations and configuration".
This category includes but is not limited to end-to-end management systems and dedicated configuration
management systems, such as controllers for software-defined networking.
• The products with digital elements in scope are only covered within the product context described in clause 4
of the present document.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking, e.g when
an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI).
NMS intended for use in the industrial Operational Technology (OT) [i.18] domain are excluded from the scope of the
present document.
An NMS is a product controlling at least partially connected devices with network access. Despite its central
positioning, an NMS can be an aggregate of several components, including but not limited to: end-to-end management
systems, dedicated configuration management systems, or controllers for software-defined networking.
NMS can be composed of several components or can implement additional functions that are outside the scope of the
present document.
EXAMPLE:
Aggregate product design would be an implementation where the operating system acts as an
abstraction layer for the system(s) that host the NMS, or the networking interfaces.
The present document specifies technical requirements and corresponding assessment criteria for Security Information
and Event Management related to cybersecurity.
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems":
• are specified within the "technical description" of the "category of product" number 7 by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: Products with digital elements that collect data from
multiple sources, analyse and correlate that data and present it as actionable information for security-related
purposes, such as threat and incident detection, forensic analysis or compliance purposes.
• are covered only within the product context described in clause 4.
The present document covers those products for the purpose of demonstrating compliance with the essential
cybersecurity requirements of Regulation (EU) 2024/2847 [i.1] Annex I, Part I under the conditions identified in
Annex A.
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
1.1
General
The present document specifies technical requirements and corresponding assessment criteria for operating systems
related to cybersecurity. The products with digital elements in scope, thereafter "the operating system":
• are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by
the Commission Implementing Regulation (EU) 2025/2392 [i.2] as:
"software products with digital elements that provide an abstract interface of the underlying hardware and
control the execution of software, and that may provide services such as computing resource management and
configuration, scheduling, input-output control, managing data, and providing an interface through which
applications interact with system resources and peripherals. This category includes but is not limited to real
time operating systems, general-purpose and special-purpose operating systems".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
The use of harmonised standards is voluntary.
The present document specifies PAdES digital signatures. PAdES signatures build on PDF signature mechanisms
defined in the ISO 32000 series. For documents conforming to ISO 32000-1 [1] PAdES utilizes an extended, alternative
signature encoding. For documents conforming to ISO 32000-2 [9], these signature structures are incorporated natively
by default within the core standard. Both approaches support digital signature formats equivalent to the signature format
CAdES as specified in ETSI EN 319 122-1 [2], by incorporation of signed and unsigned attributes, which fulfil certain
common requirements (such as the long term validity of digital signatures) in a number of use cases.
The present document specifies formats for PAdES baseline signatures, which provide the basic features necessary for a
wide range of business and governmental use cases for electronic procedures and communications to be applicable to a
wide range of communities when there is a clear need for interoperability of digital signatures used in electronic
documents.
The present document defines four levels of PAdES baseline signatures addressing incremental requirements to
maintain the validity of the signatures over the long term, in a way that a certain level always addresses all the
requirements addressed at levels that are below it. Each level requires the presence of certain PAdES attributes, suitably
profiled for reducing the optionality as much as possible.
Procedures for creation, augmentation, and validation of PAdES digital signatures are out of scope and specified in
ETSI EN 319 102-1 [10]. Guidance on creation, augmentation and validation of PAdES digital signatures including the
usage of the different attributes defined in the present document is provided in ETSI TR 119 100 [i.4]. The present
document aims at supporting electronic signatures in different regulatory frameworks.
NOTE: Specifically but not exclusively, PAdES digital signatures specified in the present document aim at
supporting electronic signatures, advanced electronic signatures, qualified electronic signatures,
electronic seals, advanced electronic seals, and qualified electronic seals as per Regulation (EU)
No 910/2014 [i.2].
The present document specifies technical characteristics and methods of measurements for Vehicle-Mounted Earth
Stations (VMES). The VMES system overview is presented below.
External mounted
equipment (EME)
Enclosure / Radome
LNA
Antenna
Externally or internally
mounted equipment
BDC
HPA
Stabilization
& Tracking
mechanism
Internally mounted
equipment (IME)
BUC
Antenna
Controller
Radio
Modem
Control and
Monitoring
Function
Figure 1: VMES System Overview
In-vehicle
Services
Interface
Antenna
Control
Facility
Interface
• The VMES may transmit and receive data when the vehicle is in motion and also when the vehicle is
stationary.
• The VMES operates on wheeled or tracked vehicles and, therefore, may be subject to occasional disturbances
and interruptions in the satellite link.
• The VMES is operating as part of a satellite network (e.g. star, mesh or point-to-point) used for the distribution
and/or exchange of information.
• The VMES is comprised of all the equipment, electrical and mechanical, from the antenna itself to the
interface with other communications equipment on a vehicle (usually referred to as the terrestrial interface).
• The VMES transmits on single carrier in the frequency range 14,00 GHz to 14,50 GHz.
NOTE 1: For the purposes of the present specification, OFDM modulation is considered as a single carrier.
• The VMES receives in one or more frequencies within the range from 10,70 GHz to 12,75 GHz.
• The VMES uses linear or circular polarization.
• The VMES is designed to operate through a geostationary satellite (or a cluster of co-located geostationary
satellites) that is at least 3° away from any other geostationary satellite operating in the same frequencies and
over the same coverage area.
NOTE 2: Satellites may be spaced closer than 3°. In such cases, the satellite operator will inform the VMES client
of the requirements of the system coordination agreements.
• The VMES transmits at elevations greater than or equal to 7° relative to the local horizon.
• The VMES is designed for unattended operation.
ETSI
9
Draft ETSI EN 302 977 V2.1.13 (2026-08)
• The VMES is designed for both mobile and stationary operation. In the case of stationary operation, the
VMES should not be accessible to the general public and operated safely.
• The VMES is controlled and monitored by an Antenna Control Facility (ACF). This function may be
performed centrally (e.g. for a network of VMESs with a central hub) or it could be performed within the
VMES for autonomous control. The ACF is outside the scope of the present document.
The present document applies to the VMES with its ancillary equipment and its various telecommunication ports, and
when operated within the boundary limits of the operational environmental profile as defined for its intended use and
when installed as required by its intended use or in the user documentation.
NOTE 3: The relationship between the present document and essential requirements of article 3 of
Directive 2014/53/EU 2 [i.6] is given in Annex A.
1.0 General
The present document specifies technical characteristics and methods of measurements for the following equipment:
• Aerial User Equipment (UE) for Evolved Universal Terrestrial Radio Access (E-UTRA) and New Radio (NR).
NOTE: The relationship between the present document and essential requirements of Directive 2014/53/EU is
given in annex A.
1.1 Operating bands
The aerial UE is capable of operating in all, or any part of the E-UTRA and NR frequency bands given in Table 1.1-1.
Table 1.1-1: E-UTRA and NR aerial UE operating bands
Band designation for
operation as:
Uplink (UL) operating band
aerial UE transmit
FUL_low to FUL_high
Downlink (DL) operating band
aerial UE receive
FDL_low to FDL_high
Duplex
Mode
Related EC/ECC
decision
E-UTRA NR
1 n1 1 920 MHz to 1 980 MHz 2 110 MHz to 2 170 MHz FDD [i.15], [i.16] and
[i.18]
3 n3 1 710 MHz to 1 785 MHz 1 805 MHz to 1 880 MHz FDD [i.13], [i.14] and
[i.18]
7
(see note 3)
n7
(see note 3) 2 500 MHz to 2 570 MHz 2 620 MHz to 2 690 MHz FDD [i.17], [i.7] and
[i.18]
8 n8 880 MHz to 915 MHz 925 MHz to 960 MHz FDD [i.13], [i.14] and
[i.18]
20
(see note 3)
n20
(see note 3) 832 MHz to 862 MHz 791 MHz to 821 MHz FDD [i.4], [i.5] and [i.18]
28
(see notes 1
and 3)
n28
(see notes 1
and 3)
703 MHz to 748 MHz 758 MHz to 803 MHz FDD [i.9], [i.10] and
[i.18]
38
(see note 3)
n38
(see note 3) 2 570 MHz to 2 620 MHz 2 570 MHz to 2 620 MHz TDD [i.17], [i.7] and
[i.18]
N/A
n91
(see notes 2
and 3)
832 MHz to 862 MHz 1 427 MHz to 1 432 MHz FDD [i.4], [i.5] and [i.18]
N/A
n92
(see notes 2
and 3)
832 MHz to 862 MHz 1 432 MHz to 1 517 MHz FDD [i.4], [i.5] and [i.18]
N/A n93
(see note 2) 880 MHz to 915 MHz 1 427 MHz to 1 432 MHz FDD [i.13], [i.14] and
[i.18]
N/A n94
(see note 2) 880 MHz to 915 MHz 1 432 MHz to 1 517 MHz FDD [i.13], [i.14] and
[i.18]
N/A
n109
(see notes 2
and 3)
703 MHz to 733 MHz 1 432 MHz to 1 517 MHz FDD [i.11] and [i.18]
NOTE 1: In Europe, according to [i.9] and [i.10], radio equipment in band 28 is only allowed between 703 MHz and
736 MHz (FUL_low = 703 MHz and FUL_high = 736 MHz) for the transmitter and between 758 MHz and 791 MHz
(FDL_low = 758 MHz and FDL_high = 791 MHz) for the receiver.
NOTE 2: Variable duplex operation does not enable dynamic variable duplex configuration by the network, and is used
such that DL and UL frequency ranges are supported independently in any valid frequency range for the
band.
NOTE 3: For those bands, mechanisms to ensure no-transmit zones for the aerial UEs are not considered in the
current version of the present document.
NOTE: The relationship between the present document and essential requirements of article 3.2 of
Directive 2014/53/EU [i.1] is given in annex A.
ETSI
Draft ETSI EN 301 908-26 V1.0.0 (2026-08) 11
The present document covers requirements for E-UTRA and NR aerial UE from 3GPP™ Releases 18 defined in
ETSI TS 136 101 [2] and ETSI TS 138 101-1 [3], respectively. This includes the requirements for E-UTRA and NR
aerial UE operating bands from 3GPP™ Release 18 defined in ETSI TS 136 101 [2] and ETSI TS 138 101-1 [3].
The requirements for NR aerial UE in the present document apply to the combination of channel bandwidths, SCS and
operating bands shown in Table 1.1-2. The channel bandwidths are specified for both the TX and RX path.
Table 1.1-2: Channel Bandwidths for each NR band
NR band / SCS / UE Channel bandwidth
NR
Band
SCS
kHz 5 MHz 10 MHz
(notes 1, 2)
15 MHz
(note 2)
20 MHz
(note 2)
25 MHz
(note 2) 30 MHz 35 MHz 40 MHz 45 MHz 50 MHz
n1
15 Yes Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
Yes
Note 4
30 Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
Yes
Note 4
60 Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
Yes
Note 4
n3
15 Yes Yes Yes Yes Yes Yes Yes
Note 4 Yes Yes
Note 4 Yes
30 Yes Yes Yes Yes Yes Yes
Note 4 Yes Yes
Note 4 Yes
60 Yes Yes Yes Yes Yes Yes
Note 4 Yes Yes
Note 4 Yes
n7
15 Yes Yes Yes Yes Yes Yes Yes Yes
30 Yes Yes Yes Yes Yes Yes Yes
60 Yes Yes Yes Yes Yes Yes Yes
n8
15
Yes
Yes Yes Yes
Yes
Notes 3
and 4
30
Yes
Yes Yes
Yes
Notes 3
and 4
60
n20
15 Yes Yes Yes Yes
30 Yes Yes Yes
60
n28
15 Yes Yes Yes Yes
Note 5 Yes
Note 5
30 Yes Yes Yes
Note 5 Yes
Note 5
60
n38
15 Yes Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
30 Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
60 Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
60 Yes Yes Yes Yes Yes
Note 4
Yes
Note 4
Yes
Note 4
Yes
n91
15 Yes Yes
Note 6
30
60
n92
15 Yes Yes Yes Yes
30
60
n93
15 Yes Yes
Note 6
30
60
n94
15 Yes Yes Yes Yes
30
60
12
Draft ETSI EN 301 908-26 V1.0.0 (2026-08)
NR band / SCS / UE Channel bandwidth
SCS
kHz
5 MHz
10 MHz
(notes 1, 2)
NR
Band
15 MHz
(note 2)
20 MHz
(note 2)
25 MHz
(note 2) 30 MHz 35 MHz 40 MHz 45 MHz 50 MHz
15
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Note 3
n109
30
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Note 3
Yes
Note 3
60
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Note 3
Yes
Note 3
Yes
Note 3
NOTE 1: 90 % spectrum utilization may not be achieved for 30 kHz SCS.
NOTE 2: 90 % spectrum utilization may not be achieved for 60 kHz SCS.
NOTE 3: This aerial UE channel bandwidth applies only to downlink.
NOTE 4: This aerial UE channel bandwidth is optional in this version of the present document.
NOTE 5: For the 20 MHz bandwidth, the minimum requirements are specified for NR UL carrier frequencies confined to
either 713 MHz to 723 MHz or 728 MHz to 738 MHz.
NOTE 6: This aerial UE channel bandwidth is applicable only to uplink.