Skip to main content

Information service

35 Information technology
New standards
EVS-EN 50159:2026
Railway Applications - Communication, signalling and processing systems - Safety-related communication in transmission systems
Scope: This document is applicable to safety-related electronic systems using for digital communication purposes a transmission system which was not necessarily designed for safety-related applications. For transmission systems where the risk of unauthorized access is not negligible, the document defines the interface to the applicable cybersecurity standards.
Both safety-related equipment and non-safety-related equipment can be connected to the transmission system.
This document gives the specific requirements needed to achieve safety-related communication between safety-related equipment connected to the transmission system, while the general system requirements including allocation of safety requirements and content of the safety case are defined in EN 50129.
This document is not applicable to existing systems which had already been accepted prior to the release of this document. However, so far as reasonably practicable, it is applicable to modifications and extensions to existing systems, subsystems and equipment.
This document does not specify:
-  the transmission system;
-  equipment connected to the transmission system;
-  solutions (e.g. for interoperability);
-  which kind of data are safety-related and which are not.
A safety-related equipment connected through an open transmission system can be subjected to many different cybersecurity threats, against which an overall program is defined encompassing management, technical and operational aspects.
Base documents: EN 50159:2026
EVS-EN ISO 22532:2026
Health informatics - Identification of medicinal products - Core vocabulary (ISO 22532:2026)
Scope: This document defines the terms used in the ISO standards on the identification of medicinal products (IDMP) and their related technical specifications.
Base documents: ISO 22532:2026; EN ISO 22532:2026
EVS-EN ISO 19127:2026
Geographic information - Geodetic register (ISO 19127:2026)
Scope: This document defines the structure, governance and management of the ISO Geodetic Register, in accordance with ISO 19135. This document also identifies the data elements applicable to geodetic referencing by coordinates, in accordance with ISO 19111.
Base documents: ISO 19127:2026; EN ISO 19127:2026
EVS-EN ISO 13940:2026
Health informatics - System of concepts to support continuity of care (ISO 13940:2026)
Scope: This document defines the requirements for a system of concepts for different aspects of the provision of care encompassing social care as well as clinical care. The focus of this document is continuity of care.
This document defines requirements for a system of concept definitions needed to describe health and care businesses. Concept systems conforming to this document can be used to support the development of:
- logical reference models within the information viewpoint as a common basis for semantic interoperability on international, national or local levels;
- information systems;
- information for specified types of care processes.
This document does not specify how to perform specific care processes. This document does not cover research processes in the context of social and clinical care, welfare and educational processes.
Base documents: ISO 13940:2026; EN ISO 13940:2026
EVS-EN 50600-1:2026
Information technology - Data centre facilities and infrastructures - Part 1: General concepts
Scope: This document:
a)  describes the general principles for data centres upon which the requirements of the EN 50600 series are based;
b)  defines the common aspects of data centres including terminology, parameters and reference models (functional elements and their accommodation) addressing both the size and complexity of their intended purpose;
c)  describes general aspects of the facilities and infrastructures required to support data centres;
d)  specifies a classification system, based upon the key criteria of "availability", "security" and "resource and energy efficiency enablement" over the planned lifetime of the data centre, for the provision of effective facilities and infrastructure;
e)  details the issues to be addressed in a business risk and operating cost analysis enabling application of the classification of the data centre;
f)  provides reference to documentation, operation and management of data centres;
g)  introduces the concepts of Key Performance Indicators (KPIs) for resource management and resilience of data centre facilities and infrastructures;
h)  defines the use of an environmental sustainability strategy.
The following topics are outside of the scope of this series of documents:
1)  the selection of information technology and network telecommunications equipment, software and associated configuration issues are outside the scope of this document;
2)  quantitative analysis of overall service availability resulting from multi-site data centres;
3)  safety and electromagnetic compatibility (EMC) requirements (covered by other standards and regulations. However, information given in this document can be of assistance in meeting these standards and regulations).
Base documents: EN 50600-1:2026
ISO 16484-5:2026
Building automation and control systems (BACS) — Part 5: Data communication protocol
Scope: The purpose of this document is to define data communication services and protocols for computer equipment used for monitoring and control of HVAC&R and other building systems and to define, in addition, an abstract, object-oriented representation of information communicated between such equipment, thereby facilitating the application and use of digital control technology in buildings.
Base documents:
Replaces: ISO 16484-5:2022
ISO 16785:2026
Electronic fee collection — Application interface definition between dedicated short-range communication on-board equipment (DSRC-OBE) and external in-vehicle devices
Scope: This document specifies requirements for an application interface between dedicated short-range communication on-board equipment (DSRC-OBE) and external in-vehicle devices to make DSRC-OBE applicable for diversified electronic fee collection (EFC) systems.
This document applies to:
—     definitions of the application interface between DSRC-OBE and external in-vehicle devices;
— definitions of data groups and data elements.
Base documents:
EAS 18433:2026
Quantum Computing - High-Level Programming Language
Scope: This document specifies a meta-model for a High-Level Programming Language for quantum computers (HPLQC) which is applicable to digital gate-based quantum computers.
NOTE     This scope can be extended to other types of quantum computers in future revisions.
This meta-model is intended to simplify quantum programming and make it accessible to a wider range of developers and end users. It abstracts complex quantum operations into user-friendly constructs to improve the readability of the code. It is realized in an existing programming language/platform (e.g. Python), in the form of an embedded Domain Specific Language (eDSL) that allows hybrid quantum algorithms to be developed while leveraging the potential of the entire ecosystem (e.g. Python) in terms of libraries and available developer resources.
To achieve a higher level of scalability and market penetration, the eDSL is available for different platforms and programming languages, e.g. Python, C/C++, Java or Rust. In order to provide the means for implementing a high-level quantum programming eDSL in various programming languages, the current project aims to specify a meta-model that outlines the targeted design philosophy, architecture, and key features, including compatibility with existing frameworks. In addition, the meta-model can be used to formally extend other programming languages and platforms by the identified capabilities and concepts.
Base documents: EAS 18433:2026
ISO/IEC 38505-1:2026
Information technology — Governance of data — Part 1: Application of ISO/IEC 38500 to the governance of data
Scope: This document provides principles for governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient and acceptable use of data within their organizations by:

applying the governance principles and model of ISO/IEC 38500 to the governance of data;
assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization’s governance of data;
informing and guiding governing bodies in the use and protection of data in their organizations.
This document can also provide guidance to a wider community, including:
executive managers;
external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies;
internal and external service providers (including consultants);
auditors.

This document applies to the governance of the current and future use of data that is created, collected, stored, secured, protected, or controlled by IT systems, and impacts the management processes and decisions relating to data.
This document defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance.
This document is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes, regardless of the extent of their dependence on data.
Base documents:
ISO/IEC 20071-31:2026
Information technology — User interface component accessibility — Part 31: Accessibility of kiosks
Scope: This document provides requirements and guidance for kiosk manufacturers, service providers and purchasers to ensure that kiosks can be used by a diverse range of users.
This document specifies requirements and recommendations for designing, manufacturing, installing, and operating kiosks to ensure accessibility across diverse users and varying physical and environmental conditions. The requirements and recommendations pertain to the presentation of information, operation and interaction with users on kiosks. They are applied to hardware, software and content of the kiosks, as well as their installation environment.
Base documents:
CEN/TR 18358:2026
Electronic fee collection - Interferences on CEN DSRC devices from radio local area network devices operating in the 5 GHz frequency range - Results of a test campaign
Scope: This document contains test results on RLAN interference to CEN DSRC devices, including the setup and execution of the tests, along with the main findings
Base documents: CEN/TR 18358:2026
EAS 18435-1:2026
Quantum Computing - Hardware Abstraction Layer - Part 1: Descriptions and functional requirements
Scope: This document describes the functionalities of the hardware abstraction layer (HAL) for use in the software stack of quantum computers, as described in CEN/CLC/TR 18202:2025 on "Layer Models for Quantum Computing" [13]. The present document is focused on a high-level functional description of the HAL while additional details on implementation and interfacing are reserved for other future documents.
The word "functional" means within this context that a precise definition of implementation, interfaces, information flows (via instructions, commands, signals, etc.) and values is out of scope. This document concentrates therefore on general descriptions of what the HAL supports and which properties or quantities need to be considered for future specification. It offers mainly an enumeration of characteristics that are considered as relevant as well as a motivation why they are relevant.
The Hardware Abstraction Layer aims to inform higher layers with capabilities and limitations supported by the underlying hardware. It hides many implementation-specific details, and provides a more unified interface to higher layers.  This includes instruction translation, resource management, fault tolerant quantum computing, mapping and routing, virtualisation for multi-user environments, and reporting of hardware capabilities.
Not all quantum computers make use of the same paradigm. Annealing quantum computers behave differently from gate-based quantum computers, and therefore their HALs might behave differently as well. The HAL can therefore provide information about the underlying architecture, such as for instance being "gate-based", "annealing" or "simulation". When applicable, the HAL can also select between multiple quantum architectures and even partition a single task into multiple queues to perform calculations in parallel on multiple architectures.
To speed-up progress, the first version of this document puts a focus on gate-based quantum computers, but that does not exclude functional requirements for other architectures. Details of other architectures are left for future revisions of this document.
Base documents: EAS 18435-1:2026
EAS 18434:2026
Quantum Computing - Roadmap for Post-Processing Software in Space
Scope: This document provides insights into post-processing software (PPSW) in space with the aim of coordinating standardization efforts.
For this purpose, the state of the art in PPSW development for space-based QKD systems, along with past experiences and best practices, is analyzed, and the general architecture of the PPSW is described for both space and ground segments.
Furthermore, the functional blocks for the PPSW, the information flow, and the corresponding interfaces for standardization and their hardware components are identified. A mapping of hardware to software components for standardization needs is provided. The distillation of secure keys and the creation of entanglement are addressed, though the latter is treated as more prospective due to current technological limitations.
Finally, a critical review of the components and interfaces is carried out to propose a standardization plan and priorities for PPSW in space-based QKD systems.
Base documents: EAS 18434:2026
Replaced standards
ISO 11783-8:2006
Tractors and machinery for agriculture and forestry -- Serial control and communications data network -- Part 8: Power train messages
Scope: ISO 11783-8:2006 specifies a serial data network for control and communications on forestry or agricultural tractors, mounted, semi-mounted, towed or self-propelled implements. Its purpose is to standardize the method and format of transfer of data between sensor, actuators, control elements, information storage and display units whether mounted or part of the tractor, or any implements. ISO 11783-8:2005 describes the messages required by tractors and self-propelled implements.
Base documents:
EVS-EN ISO 13940:2016
Health informatics - System of concepts to support continuity of care (ISO 13940:2015)
Scope: This International standard defines a system of concepts for different aspects of the provision of
healthcare.
The core business in healthcare is the interaction between subjects of care and healthcare professionals.
Such interactions occur in healthcare/clinical processes and are the justification for the process
approach of this International Standard. To be able to represent both clinical content and clinical
context, this International Standard is related to a generic healthcare/clinical process model as well
as comprehensive concept definitions and concept models for the clinical, management and resource
aspects of healthcare services.
In practice this International Standard covers the concept definitions needed whenever structured
information in healthcare is specified as a requirement. The definitions are intended to refer to the
conceptual level only and not to details of implementation. This International Standard will cover all
levels of specifications in the development of
• logical reference models within the information viewpoint as a common basis for semantic
interoperability on international, national or local levels,
• information systems, and
• information for specified types of clinical processes.
How to perform specific healthcare/clinical/informatics processes is not covered by this
International Standard.
Healthcare research processes and healthcare educational processes are not covered in this International Standard.
Base documents: ISO 13940:2015; EN ISO 13940:2016
ISO/IEC 38505-1:2017
Information technology -- Governance of IT -- Governance of data -- Part 1: Application of ISO/IEC 38500 to the governance of data
Scope: ISO/IEC 38505-1:2017 provides guiding principles for members of governing bodies of organizations (which can comprise owners, directors, partners, executive managers, or similar) on the effective, efficient, and acceptable use of data within their organizations by
-      applying the governance principles and model of ISO/IEC 38500 to the governance of data,
-      assuring stakeholders that, if the principles and practices proposed by this document are followed, they can have confidence in the organization's governance of data,
-      informing and guiding governing bodies in the use and protection of data in their organization, and
-      establishing a vocabulary for the governance of data.
ISO/IEC 38505-1:2017 can also provide guidance to a wider community, including:
-      executive managers,
-      external businesses or technical specialists, such as legal or accounting specialists, retail or industrial associations, or professional bodies,
-      internal and external service providers (including consultants), and
-      auditors.
While this document looks at the governance of data and its use within an organization, guidance on the implementation arrangement for the effective governance of IT in general is found in ISO/IEC/TS 38501. The constructs in ISO/IEC/TS 38501 can help to identify internal and external factors relating to the governance of IT and help to define beneficial outcomes and identify evidence of success.
ISO/IEC 38505-1:2017 applies to the governance of the current and future use of data that is created, collected, stored or controlled by IT systems, and impacts the management processes and decisions relating to data.
ISO/IEC 38505-1:2017 defines the governance of data as a subset or domain of the governance of IT, which itself is a subset or domain of organizational, or in the case of a corporation, corporate governance.
ISO/IEC 38505-1:2017 is applicable to all organizations, including public and private companies, government entities, and not-for-profit organizations. This document is applicable to organizations of all sizes from the smallest to the largest, regardless of the extent of their dependence on data.
Base documents:
EVS-EN 50600-1:2019
Information technology - Data centre facilities and infrastructures - Part 1: General concepts
Scope: This European Standard:
a) details the issues to be addressed in a business risk and operating cost analysis enabling application of an appropriate classification of the data centre;
b) defines the common aspects of data centres including terminology, parameters and reference models (functional elements and their accommodation) addressing both the size and complexity of their intended purpose;
c) describes general aspects of the facilities and infrastructures required to support effective operation of telecommunications within data centres;
d) specifies a classification system, based upon the key criteria of “availability”, “security” and “energy-efficiency” over the planned lifetime of the data centre, for the provision of effective facilities and infrastructure;
e) describes the general design principles for data centres upon which the requirements of the EN 50600 series are based including symbols, labels, coding in drawings, quality assurance and education.
Base documents: EN 50600-1:2019
CEN/TS 17262:2018
Personal identification - Robustness against biometric presentation attacks - Application to European Automated Border Control
Scope: This document is an application profile for the International Standard ISO/IEC 30107. It provides requirements and recommendations for the implementation of Automated Border Control (ABC) systems in Europe with Presentation Attack Detection (PAD) capability.
This document covers the evaluation of countermeasures from the Biometrics perspective as well as privacy, data protection and usability aspects. Technical descriptions of countermeasures are out of scope. Enrolment, issuance and verification applications of electronic Machine Readable Travel Documents (eMRTD) other than border control are not in scope. In particular, presentation attacks at enrolment are out of scope.
The biometric reference data can be stored in an eMRTD and/or in a database of registered travellers.
This document covers:
- biometric impostor attacks and
- biometric concealer attacks in a watchlist scenario.
This document addresses PAD for facial and fingerprint biometrics only.
Base documents: CEN/TS 17262:2018
CEN/TS 17261:2018
Biometric authentication for critical infrastructure access control - Requirements and Evaluation
Scope: This document addresses biometric recognition systems that are used as part of an automated access control system to provide a second and independent authentication factor of the individual using the AACS to access secured areas of critical infrastructure.
This document:
-  specifies requirements for biometric recognition systems to be used as part of an AACS for critical infrastructure,
-  describes a methodology for the evaluation of biometric authentication for AACSs against the specified requirements.
The requirements and test methods address biometric authentication for AACS that: (i) operate in an internal environment constituting part of a larger site, access to which is restricted and controlled by a separate access control system; and (ii) use biometrics as a second authentication factor to a token or proximity card.
This document does not consider access by the general public, e.g. passengers in an airport, or visitors to a hospital.
Products that meet the requirements of this document will comprise (i) a biometric sensor(s) external to the secured area, which reads the biometric characteristics of the user at the point of access; and (ii) a biometric server system performing biometric enrolment, signal processing, storage of biometric references and biometric comparison within a secured area.
This document does not address AACS or AACS portals (turnstiles) but is only concerned with the biometric components which integrate with the AACS. Other standards address requirements and testing of the non-biometric parts of the AACS.
Base documents: CEN/TS 17261:2018
CEN/TR 12896-9:2019
Public transport - Reference data model - Part 9: Informative documentation
Scope: A Technical Report with informative and didactical material to users.
Base documents: CEN/TR 12896-9:2019
EVS-EN 50159:2010+A1:2020
Railway applications - Communication, signalling and processing systems - Safety-related communication in transmission systems
Scope: This European Standard is applicable to safety-related electronic systems using for digital communication
purposes a transmission system which was not necessarily designed for safety-related applications and
which is
– under the control of the designer and fixed during the lifetime, or
– partly unknown or not fixed, however unauthorised access can be excluded, or
– not under the control of the designer, and also unauthorised access has to be considered.
Both safety-related equipment and non safety-related equipment can be connected to the transmission
system.
This standard gives the basic requirements needed to achieve safety-related communication between
safety-related equipment connected to the transmission system.
This European Standard is applicable to the safety requirement specification of the safety-related
equipment connected to the transmission system, in order to obtain the allocated safety integrity
requirements.
Safety requirements are generally implemented in the safety-related equipment, designed according to
EN 50129. In certain cases these requirements may be implemented in other equipment of the
transmission system, as long as there is control by safety measures to meet the allocated safety integrity
requirements.
The safety requirement specification is a precondition of the safety case of a safety-related electronic
system for which the required evidence is defined in EN 50129. Evidence of safety management and
quality management has to be taken from EN 50129. The communication-related requirements for
evidence of functional and technical safety are the subject of this standard.
This European Standard is not applicable to existing systems, which had already been accepted prior to
the release of this standard.
This European Standard does not specify
– the transmission system,
– equipment connected to the transmission system,
– solutions (e.g. for interoperability),
– which kind of data are safety-related and which are not.
A safety-related equipment connected through an open transmission system can be subjected to many
different IT security threats, against which an overall program has to be defined, encompassing
management, technical and operational aspects.
In this European Standard however, as far as IT security is concerned, only intentional attacks by means
of messages to safety-related applications are considered.
This European Standard does not cover general IT security issues and in particular it does not cover IT
security issues concerning
– ensuring confidentiality of safety-related information,
– preventing overloading of the transmission system.
Base documents: EN 50159:2010; EN 50159:2010/A1:2020
ISO/TS 16785:2020
Electronic Fee Collection (EFC) -- Application interface definition between DSRC-OBE and external in-vehicle devices
Scope: This document defines an application interface between DSRC-based OBE (hereinafter referred to as "DSRC-OBE") and an external in-vehicle device (hereinafter referred to as "the external device") to make DSRC-OBE applicable for diversified external devices.
NOTE    For use in autonomous tolling and DSRC-based (CEN, UNI, ARIB, TTA and GB/T) electronic fee collection (EFC) systems. For use in urban and inter-urban toll schemes.
The scope of this document covers the following items (as shown in Figure 4):
-  definitions of the application interface between DSRC-OBE and external devices, including global navigation satellite system (GNSS), cellular network (CN) and controller area network (CAN) device;
-  definitions of data groups and data elements.
The following items are out of the scope of this document:
-  definitions of hardware components in the external device such as GNSS module, CN module and mobile devices;
-  definitions of the physical interface between DSRC-OBE and the external device such as USB and Bluetooth;
-   definition of ITS services other than EFC;
-   definition of algorithms for authentication, encryption and key management.
Base documents:
Replaced: ISO 16785:2026
ISO 16484-5:2022
Building automation and control systems (BACS) — Part 5: Data communication protocol
Scope: The purpose of this document is to define data communication services and protocols for computer equipment used for monitoring and control of HVAC&R and other building systems and to define, in addition, an abstract, object-oriented representation of information communicated between such equipment, thereby facilitating the application and use of digital control technology in buildings.
Base documents:
Replaced: ISO 16484-5:2026
Drafts
prEN ISO 23143-3
Information exchange between BIM and GIS - Part 3: Linking abstract concepts in BIM and GIS standards (ISO/DIS 23143-3:2026)
Scope: This document outlines the conceptual framework and methodology for linking abstract concepts between BIM and GIS standards to facilitate BIM/GIS interoperability.
This document provides the mechanisms to establish links between abstract concepts in both domains in terms of metamodels, abstract conceptual schemas and application schemas.
Base documents: ISO/DIS 23143-3; prEN ISO 23143-3