General

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin:
Close date: 05 Sep 2026
View moreView less
 

The present document specifies technical characteristic and methods of measurements for Very Small Aperture 
Terminal (VSAT) equipment which has the following characteristics: 
• the VSAT is operating in one or more frequency ranges within the following bands allocated to the Fixed 
Satellite Service (FSS), shared with other services, e.g. the Fixed Service (FS) and the Mobile Service (MS): - - - 
5,850 GHz to 7,075 GHz (Earth-to-space); 
3,400 GHz to 4,200 GHz (space-to-Earth); 
4,500 GHz to 4,800 GHz (space-to-Earth); 
• the VSAT uses linear or circular polarization; 
• the VSAT operates through a geostationary satellite at least 2° away from any other geostationary satellite 
operating in the same frequency band and covering the same area; 
• the VSAT antenna diameter does not exceed 7,3 m, or equivalent effective area; 
• the VSAT is either: - - - 
a transmit-only VSAT: designed for transmission-only of radio-communications signals in the frequency 
band (earth-to-space) specified in the present clause; or 
a transmit-and-receive VSAT: designed for transmission-and-reception of radio-communications signals 
in the frequency bands specified in the present clause; or 
a receive-only VSAT: designed for reception-only of radio-communications signals in the frequency 
band (space-to-Earth) specified in the present clause; 
• the VSAT is designed for unattended operation; 
• the VSAT is operating as part of a satellite network (e.g. star, mesh or point-to-point) used for the distribution 
and/or exchange of information between users; the VSAT is controlled, and monitored for the transmit 
functionality, by a Centralized Control and Monitoring Facility (CCMF). The VSAT has to implement Control 
and Monitoring Functions with either Class A or Class B (structures of the radio states). The specifications 
associated to the CCMF facility are outside the scope of the present document. 
The present document applies to the VSAT with its ancillary equipment and its various terrestrial ports, and when 
operated within the boundary limits of the operational environmental profile defined for the intended use of the VSAT 
including all equipment as brought to the market. 
The present document does not contain any requirement, recommendation or information about the installation of the 
VSAT. 
All parts of the indoor unit related to reception, processing and presentation of the received information except the 
control channel are not within the scope of the present document. The syntax of the control channel messages is outside 
the scope of the present document. The present document is intended to cover the provisions of Directive 2014/53/EU 
(Radio Equipment Directive) [i.5] article 3.2.  
NOTE: The relationship between the present document and essential requirements of article 3.2 of 
Directive 2014/53/EU [i.5] is given in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 05 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for firewalls, intrusion detection systems, and intrusion prevention systems related to cybersecurity. The 
products with digital elements in scope: 
• are specified within the "technical description" of the "category of product" in Class II, point 2 by the 
Commission Implementing Regulation (EU) 2025/2392 [i.2] of 28 November 2025 on the technical 
description of the categories of important and critical products with digital elements pursuant to Regulation 
(EU) 2024/2847 of the European Parliament and of the Council [i.1] as: - - - 
"Firewalls are products with digital elements that protect a connected network or system from 
unauthorised access by monitoring and restricting data communication traffic to and from that network. 
This category includes but is not limited to network firewalls and application firewalls such as web 
application firewalls or filters and anti-spam gateways."; 
"Intrusion detection systems are products with digital elements that monitor traffic once it has entered the 
network environment for suspicious activity and detect or identify that an intrusion has been attempted, 
is occurring, or has occurred on a connected network or system. 
This category includes but is not limited to network-based intrusion detection systems and host-based 
intrusion detection systems."; 
"Intrusion prevention systems are products with digital elements composed of an intrusion detection 
system that actively responds to an intrusion to a connected network or system. 
This category includes but is not limited to network-based intrusion prevention systems and host-based 
intrusion prevention systems."; 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with the essential cybersecurity requirements 
of Regulation (EU) 2024/2847 [i.1], Annex I Part I, under the conditions identified in Annex A. 
Firewalls, intrusion detection systems, and intrusion prevention systems fall within the scope of the present document, 
whether deployed as physical appliances or software. The present document applies when the intended purpose or 
reasonably foreseeable use involves monitoring, analysing, or controlling network traffic for security purposes. 
Products that detect access attempts made without authorisation, identify malicious activity, or enforce traffic controls 
to protect networks and systems from intrusions are within scope. 
Firewalls, intrusion detection systems, and intrusion prevention systems intended for use in the industrial OT 
(Operational Technology) domain are excluded from the scope of the present document, see prEN 50770-1 [i.7]. 
The present document does not specify how products detect threats, classify traffic, or implement inspection algorithms. 
Detection accuracy rates, false positive thresholds, and signature effectiveness metrics are outside scope. Security 
requirements for the robustness of protocol parsing engines, the integrity of inspection processes, and vulnerability 
management remain within scope.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for smart home general purpose virtual assistants related to cybersecurity. The products with digital elements in 
scope, thereafter "smart home general purpose virtual assistants": 
• are specified within the "technical description" of the "category of product" number "16." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Products with digital elements that communicate on the public Internet, whether directly or via other 
equipment, that process demands, tasks or questions based on natural language prompts, such as through audio 
or written input, and that, based on those demands, tasks or questions, provide access to other services or 
control the functions of connected devices in residential settings. 
This category includes but is not limited to smart speakers with an integrated virtual assistant, and standalone 
virtual assistants that meet this description"; and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for smart home products with security functionalities related to cybersecurity. The products with digital 
elements in scope, thereafter "smart home products with security functionalities": 
• are specified within the "technical description" of the "category of product" number "17." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Products with digital elements that protect the physical security of consumers in a residential setting and 
which can be controlled or managed remotely from other systems, as well as hardware and software that 
centrally control such products. 
This category includes but is not limited to smart door locking devices, baby monitoring systems, alarm 
systems and home security cameras"; and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in clause A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for internet connected toys related to cybersecurity. The products with digital elements in scope, thereafter 
"internet connected toys": 
• are specified within the "technical description" of the "category of product" number "18." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Internet connected toys that have social interactive features are products with digital elements that are 
covered by Directive 2009/48/EC, that communicate on the public Internet, whether directly or via any other 
equipment, and that have embedded technologies that enable inbound and outbound communication, such as 
keyboard, microphone, speaker or camera." or "Internet connected toys that have location tracking features are 
products with digital elements that are covered by Directive 2009/48/EC, that communicate on the public 
Internet, whether directly or via any other equipment, and that have technologies that enable tracking or 
inferring of the geographical location of the toy or its user. Where the toy merely detects the proximity of the 
user or of other toys by using sensing technologies, the toy is not to be considered to have location tracking 
features." and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] under the conditions identified in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for software products 
with digital elements that detect or search for malicious software or code on a device, or remove or quarantine such 
software or code to prevent or mitigate system infection related to cybersecurity. The products with digital elements in 
scope, thereafter "the product": 
• are specified within the "technical description" of the "category of product" number "4" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: - 
"Software products with digital elements, typically referred to as antivirus or antimalware, that detect or 
search for malicious software or code on devices, or remove or quarantine such software or code, in 
order to maintain the integrity, confidentiality, or availability of such devices. 
In the context of this category of products, malicious software means software containing malicious 
features or capabilities that can cause harm directly or indirectly to the user and/or the computer system, 
such as viruses, worms, ransomware, spyware and trojans. 
This category includes but is not limited to software that detects or searches for malicious software in 
real-time or manually, rootkit detection and rescue disks with the core functionality of searching, 
removing or quarantining malicious software." 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I, Part I under the conditions identified in Annex A. 
The present document specifies technical characteristics and methods of assessment for Antivirus/Antimalware 
products. 

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 14 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for personal wearable 
products that have a health monitoring purpose or that are intended for the use by and for children, related to 
cybersecurity. The products with digital elements in scope, thereafter "personal wearable": 
• are specified within the "technical description" of the "category of product" number "19" by the Commission 
Implementing Regulation (EU) 2025/2392 of 28 November 2025 [i.2] as: 
"Personal wearable products to be worn or placed on a human body that have a health monitoring (such as 
tracking) purpose and to which Regulation (EU) 2017/745(2)or (EU) 2017/746 of the European Parliament 
and of the Council do not apply, or personal wearable products that are intended for the use by and for 
children". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.