General

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 12 Sep 2026
View moreView less
 

The present document specifies vulnerability handling activities, technical requirements and corresponding assessment 
criteria for internet connected toys related to cybersecurity. The products with digital elements in scope, thereafter 
"internet connected toys": 
• are specified within the "technical description" of the "category of product" number "18." by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as: 
"Internet connected toys that have social interactive features are products with digital elements that are 
covered by Directive 2009/48/EC, that communicate on the public Internet, whether directly or via any other 
equipment, and that have embedded technologies that enable inbound and outbound communication, such as 
keyboard, microphone, speaker or camera." or "Internet connected toys that have location tracking features are 
products with digital elements that are covered by Directive 2009/48/EC, that communicate on the public 
Internet, whether directly or via any other equipment, and that have technologies that enable tracking or 
inferring of the geographical location of the toy or its user. Where the toy merely detects the proximity of the 
user or of other toys by using sensing technologies, the toy is not to be considered to have location tracking 
features." and 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] under the conditions identified in annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 14 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for personal wearable 
products that have a health monitoring purpose or that are intended for the use by and for children, related to 
cybersecurity. The products with digital elements in scope, thereafter "personal wearable": 
• are specified within the "technical description" of the "category of product" number "19" by the Commission 
Implementing Regulation (EU) 2025/2392 of 28 November 2025 [i.2] as: 
"Personal wearable products to be worn or placed on a human body that have a health monitoring (such as 
tracking) purpose and to which Regulation (EU) 2017/745(2)or (EU) 2017/746 of the European Parliament 
and of the Council do not apply, or personal wearable products that are intended for the use by and for 
children". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 29 Sep 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for public key
infrastructure and digital certificate issuance software related to cybersecurity. The products with digital elements in
scope, thereafter "the Products":
• are specified within the "technical description" of the "category of product" number "9" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Products with digital elements used as part of a public key infrastructure (PKI) that manage the validation,
creation, issuance, distribution, status publication, renewal or revocation of digital certificates, or the
generation, storage, escrow, exchange, destruction or rotation of cryptographic keys associated with such
digital certificates. This category includes but is not limited to key management systems, digital certificate
management systems, online certificate status protocol responders and all-in-one PKI solutions".
• are only covered within the product context described in clause 4.
The present document covers those Products to demonstrate compliance with essential cybersecurity requirements in
the Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
Different use cases representing different product architecture are presented in clause 4.6. Requirements applicability in
clause 5 then defines which requirements apply to which use case to ensure compliance with the CRA's essential
cybersecurity requirements.

Categories: General
Committee: NSAI/TC 2 (ICT )
Origin: NSAI
Close date: 02 Oct 2026
View moreView less
 

The present document specifies technical requirements and corresponding assessment criteria for physical and virtual 
network interfaces related to cybersecurity. The products with digital elements in scope, thereafter "network interfaces": 
• are specified within the "technical description" of the "category of product" number "10" by the Commission 
Implementing Regulation (EU) 2025/2392 [i.2] as:  
"Physical network interfaces are products with digital elements that directly connect a device to a network via 
an Application Programming Interface (API) provided by the interface drivers, typically operating at the data 
link layer, and that feature hardware adapters to transmission media with corresponding firmware, typically 
operating at the physical and data link layer. 
Virtual network interfaces are products with digital elements that directly or indirectly connect a device to a 
network via an API that emulates that of drivers of physical network interfaces, typically operating at the data 
link layer. 
This category includes but is not limited to wired and wireless network interface cards, controllers and 
adapters, such as for Wi-Fi®, Ethernet, IrDA, USB, Bluetooth, NearLink, Zigbee®, or Fieldbus, as well as 
purely virtual standalone products, such as virtual network interface cards, container network interfaces and 
VPN interfaces". 
• are only covered within the product context described in clause 4. 
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the 
Regulation (EU) 2024/2847 [i.1], Annex I Part I under the conditions identified in Annex A. 
Network interfaces intended for use in the industrial Operational Technology (OT) domain are excluded from the scope 
of the present document, see prEN 50770 series [i.5]. 
Network interfaces whose intended purpose includes management or configuration of the product over the attached 
network are excluded from the present document. 
Network interfaces whose intended purpose includes routing, switching; or transfer of information from one attached 
network to a different attached network are excluded from the present document.