Skip to main content

Infoteenus

35 INFOTEHNOLOOGIA
Uued standardid
EVS-EN ISO/IEC 29151:2026
Information security, cybersecurity and privacy protection - Controls, requirements, and guidance for personally identifiable information protection (ISO/IEC 29151:2026)
Käsitlusala: This document specifies controls, purpose, and guidance for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this document specifies requirements and guidance based on ISO/IEC 27002, taking into consideration the controls for processing PII that can be applicable within the context of an organization's information security risk environment(s).
This document is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII, in particular, organizations that do not establish or operate a privacy information management system.
Alusdokumendid: ISO/IEC 29151:2026; EN ISO/IEC 29151:2026
EVS-EN ISO/IEC 27017:2026
Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)
Käsitlusala: This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
- additional guidance for relevant controls specified in ISO/IEC 27002:2022;
- additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Alusdokumendid: ISO/IEC 27017:2026; EN ISO/IEC 27017:2026
EVS-EN IEC 63474:2026
Electrical and electronic household and office equipment - Measurement of networked standby power of edge equipment
Käsitlusala: This document specifies methods of measurement of electrical power in networked standby mode and the reporting of the results for edge equipment.
The measurement of power and energy use in non-active mode, other than networked standby mode, is covered by IEC 62301, including the input voltage range.
This document applies to edge equipment that are powered by:
– low voltage mains AC power (𝐿𝐿𝐿𝐿 ≤ 1000 𝑉𝑉 𝐴𝐴𝐴𝐴), or
– an external power supply that provides low voltage (𝐿𝐿𝐿𝐿 ≤ 1000 𝑉𝑉) or extra low voltage (𝐸𝐸𝐸𝐸𝐸𝐸 ≤ 50 𝑉𝑉) AC or DC power, or
– a separate source of extra low voltage DC power (𝐸𝐸𝐸𝐸𝐸𝐸 ≤ 50 𝑉𝑉 𝐷𝐷𝐷𝐷), or
– an internal main battery.
Conditions that are out of scope:
– active mode (primary function),
– other non-active mode (which are either covered by IEC 62301 or by specific product group standards),
– conditions where main batteries are being charged other than maintenance mode,
– disconnected condition of the equipment.
This document applies to the following product groups where a networked standby mode is present:
– edge equipment with a network reactivation function, such as household appliances, information technology equipment, audio, video and multimedia systems and equipment,
– digital radio receivers with an emergency warning function,
– gas burning equipment.
NOTE 1 The measurement of power, energy use and performance of products during their intended use (when performing their primary functions) are generally specified in product standards and are not covered by this document.
NOTE 2 Networked standby mode for lighting equipment and the measurement of power is specified in IEC 63103.
NOTE 3 interconnecting equipment (equipment that provides network infrastructure and function) is out of scope.
Measurement of electrical power in networked standby mode for interconnecting equipment is the subject of ETSI standard EN 303 423 [2].
This document also provides a method to test power management and to test whether it is possible to deactivate wireless network connection(s).
NOTE 4 Edge equipment can also include auxiliary battery.
This document has the status of a horizontal publication in accordance with IEC Guide 108.
Alusdokumendid: IEC 63474:2026; EN IEC 63474:2026
EVS-EN ISO/IEC 27000:2026
Infoturve, küberturve ja privaatsuskaitse. Infoturbe halduse süsteemid. Ülevaade
Käsitlusala: See dokument annab ülevaate infoturbe halduse süsteemidega (ISMS) seotud dokumentides, sh standardis ISO/IEC 27001, kasutatavatest mõistetest ja põhimõtetest.
Dokumenti käsitletakse horisontaalse dokumendina, kuivõrd selle eesmärk on selgitada infoturbe ja ISMS-ide alusmõisteid ja -põhimõtteid.
Alusdokumendid: ISO/IEC 27000:2026; EN ISO/IEC 27000:2026
EVS-EN ISO/IEEE 11073-10101:2020/A1:2026
Health informatics - Device interoperability - Part 10101: Point-of-care medical device communication - Nomenclature - Amendment 1: Additional definitions (ISO/IEEE 11073-10101:2020/Amd 1:2026)
Käsitlusala: Amendment to EN ISO/IEEE 11073-10101:2020
Alusdokumendid: ISO/IEEE 11073-10101:2020/Amd 1:2026; EN ISO/IEEE 11073-10101:2020/A1:2026
EAS 16931-14:2026
Electronic invoicing - Part 14: Examples to support the implementation of EN 16931-1
Käsitlusala: This document contains examples that are relevant for the implementation of EN 16931-1 [2].
Basic scenarios described in the EN 16931-1 [2] are documented but not limited to those scenarios.
Specific more complex scenarios are documented as well.
Examples are documented by means of a full invoice content or a snippet of an invoice, together with a human readable visualization and representation in two syntaxes: UBL (CEN/TS 16931-3-2:2020 [21]) and CII (CEN/TS 16931-3-3:2020 [22]).
Alusdokumendid: EAS 16931-14:2026
EAS 18425:2026
Requirements for implementation tools and artefacts for data governance, data management and data quality supporting trusted data sharing
Käsitlusala: This document aims to provide an overview of requirements for implementation tools and artefacts for data governance, data management, data quality and process quality assessment supporting trusted data sharing, and guidance on the selection of appropriate tools based on the experiences of various use cases.
Alusdokumendid: EAS 18425:2026
CEN/TS 16931-3-2:2026
Electronic invoicing – Part 3-2 Syntax binding of EN 16931-1 to ISO/IEC 19845 (UBL) invoice and credit note
Käsitlusala: This document specifies the mapping between the semantic model of an electronic invoice, included in
EN 16931-1 and the UBL syntax. For each element in the semantic model (including sub-elements or
supplementary components such as Identification scheme identifiers) it is defined which element in the
syntax is to be used to contain its information contents. Any mismatches between semantics, format,
cardinality or structure are indicated.
Alusdokumendid: CEN/TS 16931-3-2:2026
CEN/TS 16931-3-3:2026
Electronic invoicing – Part 3-3: Syntax binding of EN 16931-1 to UN/CEFACT XML Industry Invoice
Käsitlusala: This document specifies the mapping between the semantic model of an electronic invoice, included in EN 16931-1 and the Cross Industry Invoice in the UN/CEFACT XML syntax. For each element in the semantic model (including sub-elements or supplementary components such as Identification scheme identifiers) it is defined which element in the syntax is to be used to contain its information contents.
Any mismatches between semantics, format, cardinality or structure are indicated.
Alusdokumendid: CEN/TS 16931-3-3:2026
CEN/TS 16931-3-4:2026
Electronic invoicing - Part 3-4: Syntax binding for UN/EDIFACT INVOIC D16B
Käsitlusala: This CEN Technical Specification (TS) contains the mapping between the semantic data model of an electronic invoice (EN 16931-1) and the UN/EDIFACT INVOIC syntax. For each element in the semantic model (including sub-elements or supplementary components such as Code List identifiers) it is defined which element in the syntax is to be used to contain its information contents. Any mismatches between semantics, format, cardinality or structure are indicated. Any rules to be followed when using the specific syntax are stated informally in this TS. If later versions of the UN/EDIFACT INVOIC support the semantics more accurately, this is indicated.
Alusdokumendid: CEN/TS 16931-3-4:2026
CEN/TR 18362:2026
Guidelines for building multimodal travel purchase APIs based on Transmodel
Käsitlusala: This document covers:
— Provision of a catalogue of fares
— Request for specific fare offers (including specific search criteria),
— Selection of one or several formal offers by the customer (pre-purchase),
— Initiation of the purchase,
— Commitment to buy,
— Reservation of a place on a specific journey,
— Reception of evidence of the purchase,
— Management after purchase (basic after-sale actions),
— All interactions that can be related to a persistent identity.
These functions can be seen as the minimum required for the data flow of reservation from the travellers’
perspective.
Though some of the studied APIs have functions beyond just reservation and involving other parties, the
following activities are not in scope of this document nor the CoRoM project:
— Creation and distribution of the travel document,
— Travel planning,
— Payment interfaces with banking information systems,
— Validation of purchased access rights during travel,
— Control of purchased access rights during travel
Alusdokumendid: CEN/TR 18362:2026
ISO/IEC 9075-15:2023/Cor 1:2026
Information technology — Database languages SQL — Part 15: Multidimensional arrays (SQL/MDA) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-15:2023
Alusdokumendid:
ISO/IEC 39075:2024/Cor 1:2026
Information technology — Database languages — GQL — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 39075:2024
Alusdokumendid:
ISO/IEC 9075-16:2023/Cor 1:2026
Information technology — Database languages SQL — Part 16: Property Graph Queries (SQL/PGQ) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-16:2023
Alusdokumendid:
ISO/IEC 25986:2026
Software engineering — NESMA functional size measurement method — Easy functional sizing (EFS)
Käsitlusala:
Alusdokumendid:
ISO/IEC 9075-14:2023/Cor 1:2026
Information technology — Database languages SQL — Part 14: XML-Related Specifications (SQL/XML) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-14:2023
Alusdokumendid:
ISO/IEC 9075-13:2023/Cor 1:2026
Information technology — Database languages SQL — Part 13: SQL Routines and types using the Java TM programming language (SQL/JRT) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-13:2023
Alusdokumendid:
ISO/IEC 9075-11:2023/Cor 1:2026
Information technology — Database languages SQL — Part 11: Information and definition schemas (SQL/Schemata) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-11:2023
Alusdokumendid:
ISO/IEC 23000-19:2024/Amd 2:2026
Information technology — Multimedia application format (MPEG-A) — Part 19: Common media application format (CMAF) for segmented media — Amendment 2: Additional structural CMAF brand profile
Käsitlusala: Amendment to ISO/IEC 23000-19:2024
Alusdokumendid:
ISO 13940:2026
Health informatics — System of concepts to support continuity of care
Käsitlusala: This document defines the requirements for a system of concepts for different aspects of the provision of care encompassing social care as well as clinical care. The focus of this document is continuity of care.
This document defines requirements for a system of concept definitions needed to describe health and care businesses. Concept systems conforming to this document can be used to support the development of:

logical reference models within the information viewpoint as a common basis for semantic interoperability on international, national or local levels;
information systems;
information for specified types of care processes.

This document does not specify how to perform specific care processes. This document does not cover research processes in the context of social and clinical care, welfare and educational processes.
Alusdokumendid:
Asendab: ISO 13940:2015
ISO/IEC 9075-10:2023/Cor 1:2026
Information technology — Database languages SQL — Part 10: Object language bindings (SQL/OLB) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-10:2023
Alusdokumendid:
ISO/IEC 9075-9:2023/Cor 1:2026
Information technology — Database languages SQL — Part 9: Management of External Data (SQL/MED) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-9:2023
Alusdokumendid:
ISO/IEC 9075-3:2023/Cor 1:2026
Information technology — Database languages SQL — Part 3: Call-Level Interface (SQL/CLI) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-3:2023
Alusdokumendid:
ISO/IEC/IEEE 26512:2026
Systems and software engineering — Requirements for acquirers and suppliers of information products and services
Käsitlusala: This document provides an overview of the information management processes that are relevant to the acquisition and supply of information for users. It applies the agreement processes (acquisition and supply) to information for users, and addresses the preparation of requirements for this information. These requirements are central to the information for users specification and statement of work discussed in this document. This document also addresses requirements for primary information outputs of the acquisition and supply process: the request for proposal and the proposal for information products and services.
This document is intended for use in acquiring or supplying any type of information for users and is independent of information development or management tools or methodologies.
This document can be helpful for acquiring and supplying the following types of information, although it does not cover all aspects of them:

multimedia systems using animation, video, and sound;
computer-based training (CBT) packages and specialized course materials intended primarily for use in formal training programs;
maintenance information describing the internal operation of systems software;
virtual reality and augmented reality;
collaboratively generated, often known as “wiki”, information, which is curated periodically;
information for users incorporated into the user interface.

This document is applicable to acquirers and suppliers of information for users, including a variety of specialists:

analysts (e.g. business analysts, human factors engineers) who identify the tasks that the intended users perform with the system;
managers of the software or system development process or the information management process;
managers of the acquisition process, and those who authorize and approve acquisitions;
managers and authors involved in proposal preparation.

It can also be consulted by those with other roles and interests in the information development process:

information designers and architects who plan the structure, format, and content requirements of information products;
experienced authors and editors who develop the written content for information for users;
graphic designers with expertise in electronic media;
user interface designers and ergonomics experts working together to design the presentation of the information on the screen;
usability testers, information development reviewers, subject-matter experts;
developers of tools for creating on-screen information.
Alusdokumendid:
ISO/IEC 23167:2026
Information technology — Cloud computing — Common technologies and techniques
Käsitlusala: This document provides a description of a set of common technologies and techniques used in conjunction with cloud computing. These include:

virtual machines (VMs) and hypervisors;
containers and container management systems (CMSs);
serverless computing;
microservices architecture;
automation;
platform as a service systems and architecture;
storage services;
security, scalability and networking as applied to the above cloud computing technologies.
Alusdokumendid:
ISO/IEC 9075-2:2023/Cor 1:2026
Information technology — Database languages SQL — Part 2: Foundation (SQL/Foundation) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-2:2023
Alusdokumendid:
ISO/IEC 9075-1:2023/Cor 1:2026
Information technology — Database languages SQL — Part 1: Framework (SQL/Framework) — Technical Corrigendum 1
Käsitlusala: Corrigendum to ISO/IEC 9075-1:2023
Alusdokumendid:
ISO/IEC 23001-19:2026
Information technology — MPEG systems technologies — Part 19: Carriage of green metadata
Käsitlusala: This document defines a storage and delivery format for metadata for energy-efficient decoding, encoding, presentation, and selection of media (green metadata) as defined in ISO/IEC 23001-11. The green metadata are timed metadata which can be associated with other tracks in the ISO Base Media File Format. Timed metadata such as power consumption information and their metrics are defined in this document for carriage in files based on ISO/IEC 14496-12.
In the context of DASH delivery, the green metadata representations and their association to the media representations are also defined using the signalling mechanisms specified in ISO/IEC 23009-1:2022 and ISO/IEC 23009-3[1].
These metadata can be used for multiple purposes, including optimizing power consumption during playback and supporting dynamic adaptive streaming.
Alusdokumendid:
ISO/TS 24932:2026
Genomics informatics — Procedures for gene expression panel-based similarity calculation for human pluripotent stem cell-derived organoids
Käsitlusala: This document specifies procedures for gene expression-based similarity calculation between human pluripotent stem cell (hPSC)-derived organoids and a pre-defined data set of gene expression profiles in normal tissues. This document covers situations where the gene expression in the organoids have been quantified in a way functionally similar to the samples in the pre-defined dataset, and it is not intended for medical decisions.
Alusdokumendid:
ISO 21763:2026
Guidelines for smart manufacturing in the iron and steel industry
Käsitlusala: This document specifies guidelines for smart manufacturing technologies applicable to smart plants in the iron and steel industry, together with the basic requirements for these technologies as defined in the application guidelines.
This document covers three dimensions related to the steel production process:

smart production process design,
smart equipment, and
smart production.

This document provides an overview of the potential applications of smart manufacturing technology in these scenarios, as well as the specific technical requirements it needs to meet.
This document provides reference guidelines for the iron and steel industry to formulate smart factory upgrading plans to improve productivity and product quality. It is intended for use by iron and steel manufacturing enterprises, smart manufacturing technology vendors, and relevant public sector organizations, and is applicable to steel plants regardless of manufacturing process route, equipment configuration, plant size, geographic location, or product type.
This document is not intended to be used for any form of evaluation or grading of steel plants or companies.
Alusdokumendid:
ISO/TS 25271:2026
Automation systems and integration — Industrial digital twin interface architecture
Käsitlusala: This document specifies the interface architecture of industrial digital twin systems, which is structured around three key elements: the digital twin, the physical twin and the interface that links them. Together, these elements form the essential framework of an industrial digital twin.
The following are within the scope of this document:

Defining the elements of industrial digital twin systems that embody a distinct architecture.
Analysing the interactions among the three core elements of industrial digital twin systems
Identifying the characteristics that distinguish industrial digital twin systems from related concepts or technologies
Examining typical use cases that implement the three-element interface architecture
The following is outside the scope of this document:

Detailed applications of industrial digital twin systems
Alusdokumendid:
ISO 20038:2026
Banking and related financial services — Key wrap using advanced encryption standard (AES)
Käsitlusala: This document defines a method for packaging cryptographic keys for transport. This method can also be used for the storage of keys under an advanced encryption standard (AES) key. The method uses the block cipher AES as the wrapping cipher algorithm.
Other methods for wrapping keys are outside the scope of this document but can use the authenticated encryption algorithms specified in ISO/IEC 19772.
Alusdokumendid:
Asendab: ISO 20038:2017
ISO 25186:2026
Financial services — Methods for the generation and verification of card security codes
Käsitlusala: This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC).
Key management mechanisms associated with these processes are beyond the scope of this document.
Alusdokumendid:
ISO/TS 5087-3:2026
Information technology — City data model — Part 3: Service level concepts for transport
Käsitlusala: This document defines an ontology for service level concepts defined for the transport domain using terms specified in ISO/IEC 5087-1 and ISO/IEC 5087-2. The values for service-level concepts defined in this document are intended to be managed by the transport domain but accessible by multiple city services and stakeholders.
Alusdokumendid:
ISO/IEC 29151:2026
Information security, cybersecurity and privacy protection — Controls, requirements, and guidance for personally identifiable information protection
Käsitlusala: This document specifies controls, purpose, and guidance for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this document specifies requirements and guidance based on ISO/IEC 27002, taking into consideration the controls for processing PII that can be applicable within the context of an organization's information security risk environment(s).
This document is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII, in particular, organizations that do not establish or operate a privacy information management system.
Alusdokumendid:
ISO/IEC 23093-6:2026
Information technology — Internet of media things — Part 6: Media data formats and application programming interface (API) for distributed artificial intelligence (AI) processing
Käsitlusala: This document specifies the syntax and semantics of description schemes to represent data exchanged by media analysers for distributed artificial intelligence (AI) processing. Moreover, it specifies the application programming interfaces (APIs) to exchange these data between media things.
This document does not specify how analysis is carried out, but defines the interfaces between the media things.
Alusdokumendid:
ISO/IEC 23093-3:2026
Information technology — Internet of media things — Part 3: Media data formats and application programming interface (API)
Käsitlusala: This document specifies the syntax and semantics of description schemes for representing data exchanged by media things (e.g. media sensors, media actuators, and media storages). Moreover, it specifies the APIs to exchange these data between media things. The following interfaces are under the scope of this document:

APIs for accessing media sensors, actuators, storage, managers, controllers, and aggregators;
structured data formats (XML) representing media thing’s base data types, including sensors, actuators, storage, managers, aggregators, controllers, and their elements;
structured data formats (XML) representing the media sensor’s output data; and,
structured data formats (XML) representing media actuator’s commands.

This document does not specify how sensing and actuating are carried out but defines the interfaces between the media things.
Alusdokumendid:
ISO/IEC 30188:2026
Digital twin — Reference architecture
Käsitlusala: This document specifies a general reference architecture for a digital twin system in terms of defining system fundamentals through the use of architecture views.
Alusdokumendid:
ISO/IEC 19763-13:2026
Information technology — Metamodel framework for interoperability (MFI) — Part 13: Metamodel for form design registration
Käsitlusala: This document provides a metamodel to describe the structure and semantics of an implemented form devoid of any specific, domain semantics, e.g. in healthcare, social science, e-government and e-business, or representation format so that data can be faithfully exchanged between systems and system components, and associations expressed between sets of form designs whose data can be compared, joined or composed for analysis.
Alusdokumendid:
ISO/IEC 30178:2026
Internet of Things (IoT) — Data format, value and coding for interoperability
Käsitlusala: This document defines common formats, values, and coding for data interoperability and exchange among systems in the Internet of Things (IoT).
Alusdokumendid:
ISO 22532:2026
Health informatics — Identification of medicinal products — Core vocabulary
Käsitlusala: This document defines the terms used in the ISO standards on the identification of medicinal products (IDMP) and their related technical specifications.
Alusdokumendid:
ISO 19127:2026
Geographic information — Geodetic register
Käsitlusala: This document defines the structure, governance and management of the ISO Geodetic Register, in accordance with ISO 19135. This document also identifies the data elements applicable to geodetic referencing by coordinates, in accordance with ISO 19111.
Alusdokumendid:
Asendab: ISO 19127:2019
ISO/IEC 23090-30:2026
Information technology — Coded representation of immersive media — Part 30: Low latency, low complexity light detection and ranging (LiDAR) coding
Käsitlusala: This document specifies low latency, low complexity light detection and ranging (LiDAR) coding.
Alusdokumendid:
ISO 21926:2026
Semantic data model for audit data services
Käsitlusala: This document aims to define a methodology and framework to build a sematic data model for audit data services (ADS), adapt it (by extensions), and convert it to exchange formats.
The methodology describes a standardized semantic structure for audit data, focusing on specifying object classes and their attributes and associations, how to decouple audit data from specific systems (ERP applications) and how to extract and exchange data uniformly for audits, and describes the methods used for this such as graph walk (from relational to hierarchical model), syntax binding (to technical formats), semantic binding (link to other standards).
The semantic data model applies to areas such as general ledger journal entries, accounts receivable, sales, accounts payable, purchasing, inventory (movement and data), and property, plant, and equipment, customs and indirect tax and payroll.
These areas are limited to the functional requirements set forth in ISO 21378, ISO 5401, and ISO 5405 and can be extended with future extensions to ISO 21378.
This document describes the methodology and framework, not the full implementation or concrete technical exchange standards.
Alusdokumendid:
ISO/IEC 27017:2026
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Käsitlusala: This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:

additional guidance for relevant controls specified in ISO/IEC 27002:2022;
additional controls with guidance that specifically relate to cloud services.

This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Alusdokumendid:
Asendatud standardid
ISO/IEC 27017:2015
Information technology -- Security techniques -- Code of practice for information security controls based on ISO/IEC 27002 for cloud services
Käsitlusala: ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
- additional implementation guidance for relevant controls specified in ISO/IEC 27002;
- additional controls with implementation guidance that specifically relate to cloud services.
This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.
Alusdokumendid:
Asendatud: ISO/IEC 27017:2026
ISO 13940:2015
Health informatics -- System of concepts to support continuity of care
Käsitlusala: ISO 13940:2015 defines a system of concepts for different aspects of the provision of healthcare.
The core business in healthcare is the interaction between subjects of care and healthcare professionals. Such interactions occur in healthcare/clinical processes and are the justification for the process approach of ISO 13940:2015. To be able to represent both clinical content and clinical context, ISO 13940:2015 is related to a generic healthcare/clinical process model as well as comprehensive concept definitions and concept models for the clinical, management and resource aspects of healthcare services.
In practice ISO 13940:2015 covers the concept definitions needed whenever structured information in healthcare is specified as a requirement. The definitions are intended to refer to the conceptual level only and not to details of implementation. ISO 13940:2015 will cover all levels of specifications in the development of
logical reference models within the information viewpoint as a common basis for semantic interoperability on international, national or local levels,
information systems, and
information for specified types of clinical processes.
Alusdokumendid:
Asendatud: ISO 13940:2026
ISO/IEC TS 19763-13:2016
Information technology -- Metamodel framework for interoperability (MFI) -- Part 13: Metamodel for form design registration
Käsitlusala: The primary purpose of the ISO/IEC 19763 series is to specify a metamodel framework for interoperability. ISO/IEC TS 19763-13(E) specifies a metamodel for registering form designs.
ISO/IEC TS 19763-13(E) provides a metamodel to describe the structure and semantics of an implemented form devoid of any specific, domain semantics, e.g. in healthcare, social science, e-government and e-business, or representation format so that data may be faithfully exchanged between systems and system components, and associations expressed between sets of form designs whose data may be compared, joined or composed for analysis.
Alusdokumendid:
ISO/IEC 29151:2017
Information technology -- Security techniques -- Code of practice for personally identifiable information protection
Käsitlusala: ISO/IEC 29151:2017 establishes control objectives, controls and guidelines for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this Recommendation | International Standard specifies guidelines based on ISO/IEC 27002, taking into consideration the requirements for processing PII that may be applicable within the context of an organization's information security risk environment(s).
ISO/IEC 29151:2017 is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII.
Alusdokumendid:
Asendatud: ISO/IEC 29151:2026
ISO 20038:2017
Banking and related financial services -- Key wrap using AES
Käsitlusala: ISO 20038:2017 defines a method for packaging cryptographic keys for transport. This method can also be used for the storage of keys under an AES key. The method uses the block cipher AES as the wrapping cipher algorithm.
Other methods for wrapping keys are outside the scope of this document but can use the authenticated encryption algorithms specified in ISO/IEC 19772.
Alusdokumendid:
Asendatud: ISO 20038:2026
ISO/IEC/IEEE 26512:2018
Systems and software engineering -- Requirements for acquirers and suppliers of information for users
Käsitlusala: This document supports the interest of system users in having consistent, complete, accurate, and usable information. It addresses both available approaches to standardization: a) process standards, which specify the way that information products are to be acquired and supplied; and b) information product standards, which specify the characteristics and functional requirements of the information.
As defined in ISO/IEC/IEEE 12207 and ISO/IEC/IEEE 15288:2015, the acquisition and supply activities make up the agreement processes of the software or system life cycle. Acquisition and supply of information for users and related services are specializations of those processes. Such services can be acquired and supplied for any part of the information management process, such as the following:
-       information management;
-       information design and development;
-       information editing and review coordination;
-       information testing, particularly usability testing;
-       information production and packaging;
-       information distribution and delivery;
-       advice on the selection and implementation of information development tools and supporting systems; and
-       information development process improvement.
This document provides an overview of the information management processes that are relevant to the acquisition and supply of information for users. It applies the Agreement processes (acquisition and supply) to information for users, and addresses the preparation of requirements for this information. These requirements are central to the information for users specification and statement of work discussed in this document. This document also addresses requirements for primary document outputs of the acquisition and supply process: the request for proposal and the proposal for documentation products and services.
This document is intended for use in acquiring or supplying any type of information for users and is independent of information development or management tools or methodologies.
This document might be helpful for acquiring and supplying the following types of information, although it does not cover all aspects of them:
-       multimedia systems using animation, video, and sound;
-       computer-based training (CBT) packages and specialized course materials intended primarily for use in formal training programs;
-       maintenance documentation describing the internal operation of systems software;
-       collaboratively generated, often known as "wiki", documentation, which will usually need to be curated periodically; and
-       information for users incorporated into the user interface.
This document is applicable to acquirers and suppliers of information for users, including a variety of specialists:
-       analysts (e.g., business analysts, human factors engineers) who identify the tasks that the intended users will perform with the system;
-       managers of the software or system development process or the information management process;
-        managers of the acquisition process, and those who authorize and approve acquisitions; and
-       managers and authors involved in proposal preparation.
It can also be consulted by those with other roles and interests in the information development process:
-       information designers and architects who plan the structure, format, and content requirements of information products;
-       experienced authors and editors who develop the written content for information for users;
-       graphic designers with expertise in electronic media;
-       user interface designers and ergonomics experts working together to design the presentation of the information on the screen;
-       usability testers, information development reviewers, technical contacts;
-       developers of tools for creating on-screen information for users.
Alusdokumendid:
ISO 19127:2019
Geographic information -- Geodetic register
Käsitlusala: This document defines the management and operations of the ISO geodetic register and identifies the data elements, in accordance with ISO 19111:2007 and the core schema within ISO 19135-1:2015, required within the geodetic register.
Alusdokumendid:
Asendatud: ISO 19127:2026
ISO/IEC TS 23167:2020
Information technology -- Cloud computing -- Common technologies and techniques
Käsitlusala: This document provides a description of a set of common technologies and techniques used in conjunction with cloud computing. These include:
- virtual machines (VMs) and hypervisors;
- containers and container management systems (CMSs);
- serverless computing;
- microservices architecture;
- automation;
- platform as a service systems and architecture;
- storage services;
- security, scalability and networking as applied to the above cloud computing technologies.
Alusdokumendid:
Asendatud: ISO/IEC 23167:2026
EVS-EN ISO/IEC 27000:2020
Infotehnoloogia. Turbemeetodid. Infoturbe halduse süsteemid. Ülevaade ja sõnavara
Käsitlusala: See dokument annab ülevaate infoturbe halduse süsteemidest (ISMS). Ta esitab ka ISMS-i standardiperes kasutatavad ühised terminid ja määratlused. See dokument on rakendatav igat liiki ja iga suurusega organisatsioonides (nt äriettevõtetes, riigiasutustes, mittetulunduslikes organisatsioonides).
Selles dokumendis toodud terminid ja määratlused
—  hõlmavad ISMS-i standardipere üldkasutatavaid termineid ja määratlusi,
—  ei hõlma kõiki ISMS-i standardiperes kasutatavaid termineid ja määratlusi ning
—  ei piira ISMS-i standardiperet uute terminite määratlemisel.
Alusdokumendid: ISO/IEC 27000:2018; EN ISO/IEC 27000:2020
CEN/TS 16931-3-4:2020
Electronic invoicing - Part 3-4: Syntax binding for UN/EDIFACT INVOIC D16B
Käsitlusala: This documents specifies the mapping between the semantic model of an electronic invoice, included in EN 16931-1 and the ISO 9735 (UN/EDIFACT) syntax. For each element in the semantic model (including sub-elements or supplementary components such as Identification scheme identifiers) it is defined which element in the syntax is to be used to contain its information contents. Any mismatches between semantics, format, cardinality or structure are indicated.
Alusdokumendid: CEN/TS 16931-3-4:2020
CEN/TS 16931-3-2:2020
Electronic invoicing - Part 3-2: Syntax binding for ISO/IEC 19845 (UBL 2.1) invoice and credit note
Käsitlusala: This document specifies the mapping between the semantic model of an electronic invoice, included in EN 16931-1 and the UBL 2.1 syntax (ISO/IEC 19845). For each element in the semantic model (including sub-elements or supplementary components such as Identification scheme identifiers) it is defined which element in the syntax is to be used to contain its information contents. Any mismatches between semantics, format, cardinality or structure are indicated.
Alusdokumendid: CEN/TS 16931-3-2:2020
CEN/TS 16931-3-3:2020
Electronic invoicing - Part 3-3: Syntax binding for UN/CEFACT XML Industry Invoice D16B
Käsitlusala: This document specifies the mapping between the semantic model of an electronic invoice, included in EN 16931 1 and the Cross Industry Invoice in the UN/CEFACT XML syntax. For each element in the semantic model (including sub-elements or supplementary components such as Identification scheme identifiers) it is defined which element in the syntax is to be used to contain its information contents. Any mismatches between semantics, format, cardinality or structure are indicated.
Alusdokumendid: CEN/TS 16931-3-3:2020
EVS-EN ISO/IEC 27017:2021
Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2015)
Käsitlusala: ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
- additional implementation guidance for relevant controls specified in ISO/IEC 27002;
- additional controls with implementation guidance that specifically relate to cloud services.
This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.
Alusdokumendid: ISO/IEC 27017:2015; EN ISO/IEC 27017:2021
EVS-EN ISO/IEC 29151:2022
Information technology - Security techniques - Code of practice for personally identifiable information protection (ISO/IEC 29151:2017)
Käsitlusala: ISO/IEC 29151:2017 establishes control objectives, controls and guidelines for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this Recommendation | International Standard specifies guidelines based on ISO/IEC 27002, taking into consideration the requirements for processing PII that may be applicable within the context of an organization's information security risk environment(s).
ISO/IEC 29151:2017 is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII.
Alusdokumendid: ISO/IEC 29151:2017; EN ISO/IEC 29151:2022
ISO/IEC 23093-3:2022
Information technology — Internet of media things — Part 3: Media data formats and APIs
Käsitlusala: This document specifies the syntax and semantics of description schemes to represent data exchanged by media things (e.g., media sensors, media actuators, media analysers, media storages). Moreover, it specifies the APIs to exchange these data between media things.
This document does not specify how sensing and analysing is carried out but defines the interfaces between the media things.
Alusdokumendid:
EVS-EN IEC 63474:2023
Electrical and electronic household and office equipment - Measurement of networked standby power consumption of edge equipment
Käsitlusala: IEC 63474:2023 specifies methods of measurement of electrical power consumption in networked standby and the reporting of the results for edge equipment.

Power consumption in standby (other than networked standby) is covered by EN 50564, including the input voltage range.

This document also provides a method to test power management and to test whether it is possible to deactivate wireless network connection(s).

This document does not apply to the measurement of electrical power consumption in networked standby for interconnecting equipment.
Alusdokumendid: IEC 63474:2023; EN IEC 63474:2023
Kavandid
prEN 304 624 V1.0.0
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded avaliku võtme taristule ja digitaalsertifikaatide väljastamise tarkvarale
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for public key infrastructure and digital certificate issuance software related to cybersecurity. The products with digital elements in scope, thereafter "the Products":
• are specified within the "technical description" of the "category of product" number "9" by the Commission Implementing Regulation (EU) 2025/2392 as:
"Products with digital elements used as part of a public key infrastructure (PKI) that manage the validation, creation, issuance, distribution, status publication, renewal or revocation of digital certificates, or the generation, storage, escrow, exchange, destruction or rotation of cryptographic keys associated with such digital certificates. This category includes but is not limited to key management systems, digital certificate management systems, online certificate status protocol responders and all-in-one PKI solutions".
• are only covered within the product context described in clause 4.
The present document covers those Products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in annex A.
Different use cases representing different product architecture are presented in clause 4.6. Requirements applicability in clause 5 then defines which requirements apply to which use case to ensure compliance with the CRA's essential cybersecurity requirements.
Alusdokumendid: Draft ETSI EN 304 624 V1.0.0
prEN ISO/IEC 42006
Information technology - Artificial intelligence - Requirements for bodies providing audit and certification of artificial intelligence management systems (ISO/IEC 42006:2025)
Käsitlusala: This document specifies additional requirements to ISO/IEC 17021-1. The requirements contained in this document, when implemented, support the demonstration of competence, consistency and reliability by the bodies performing auditing and certification of an artificial intelligence management system (AIMS) according to ISO/IEC 42001 for organizations that provide, develop or use AI systems.
Certification of AIMS is a third-party conformity assessment activity (as described in ISO/IEC 17000:2020, 4.5), and bodies performing this activity are third-party conformity assessment bodies.
This document also provides the necessary information and confidence to customers about the way certification has been granted.
NOTE This document can be used as a criteria document for accreditation or peer assessment.
Alusdokumendid: ISO/IEC 42006:2025; prEN ISO/IEC 42006
prEN ISO 23143-2
Information exchange between BIM and GIS - Part 2: Facilitating data exchange through metadata (ISO/DIS 23143-2:2026)
Käsitlusala: This document provides guidelines for the data exchange between BIM and GIS through metadata. This document explains the role that metadata plays in facilitating data exchange within the framework of the standards referenced in ISO/DIS 23143-1, Clause 6.3 (Metadata resources).
This document offers a perspective on leveraging metadata to ensure interoperability between BIM and GIS. It builds on the core principles established in ISO/DIS 23143-1 by presenting how metadata supports communication between the two domains, thereby facilitating seamless data exchange This document defines a framework for facilitating data exchange between Building Information Modelling (BIM) and Geographic Information Systems (GIS) through metadata-driven interoperability.
It specifies methods for identifying and cross-mapping metadata elements in the GIS Metadata Schema (ISO 19115-1:2014 [2]), and for deriving BIM-side metadata from IDM Data Schema (ISO 29481-3:2022 [1]) to support semantic alignment and structured transformation between the two domains. ISO 29481-3:2022 [1] is used as a source to derive BIM-side metadata candidates for cross-mapping and is not treated as a metadata schema.
The scope of this part includes:
1) Establishing metadata-based cross-mapping rules to support the semantic translation of information between BIM and GIS, including the use of BIM-side metadata candidates (derived from ISO 29481-3:2022 [1]) and GIS metadata elements (ISO 19115-1:2014 [2]);
2) Supporting bidirectional information requests and responses, where each domain (BIM or GIS) can serve as either information provider or consumer.
Alusdokumendid: ISO/DIS 23143-2; prEN ISO 23143-2
prEN ISO 23143-1
Information exchange between BIM and GIS - Part 1: Core principles and specifications (ISO/DIS 23143-1:2026)
Käsitlusala: This document establishes the core principles and specifications for enabling structured and semantically consistent information exchange between BIM and GIS. It provides a comprehensive framework for understanding, planning, and implementing information exchanges that span both the BIM domain and the GIS domain.
This document provides a conceptual framework, built around eight perspectives on BIM-GIS information exchange: life cycle, process, product, data, exchange, actor, geospatial, and standards perspectives, how they shape, dictate, or constrain the structuring and execution of information exchanges, and the relationships between them and their application to specific use cases.
It also addresses the following key elements:
— Requirements definition and hierarchy for BIM-GIS information exchanges
— Services enabling exchange and integration, transformation, query and analysis, and visualization and communication
— Functions supporting spatial registration and georeferencing, data harmonization, linking, analytical operations, and workflow management
— Resources including data and information types, formats, and their characteristics
— Repositories for centralized data management, translation and integration, and specialized storage
It provides guidance on:
— Use case definition, services, and functions specification
— Application schema considerations addressing fundamental differences between BIM and GIS data structures
— Data resources management including objects, entities, and features
— Position and location management including georeferencing levels, metadata requirements, and implementation tasks
— Coordinate reference system selection and transformation parameters
— Georeferencing, including levels of georeferencing, metadata requirements and georeferencing tasks
Alusdokumendid: ISO/DIS 23143-1; prEN ISO 23143-1
EN 50173-6:2018/prA1:2026
Information technology - Generic cabling systems - Part 6: Distributed building services
Käsitlusala: This standard specifies generic cabling for distributed building services and can be used in conjunction with all the space-specific standards of the EN 50173 series.
It covers balanced cabling and optical fibre cabling.
This standard specifies directly or via reference to EN 50173 1 the:
—  structure and minimum configuration for generic cabling for distributed building services;
—  interfaces at the service outlet (SO);
—  performance requirements for cabling links and channels;
—  implementation requirements and options;
—  performance requirements for cabling components;
—  conformance requirements and verification procedures.
Alusdokumendid: EN 50173-6:2018/prA1:2026
EN 50173-3:2018/prA1:2026
Information technology - Generic cabling systems - Part 3: Industrial spaces
Käsitlusala: This standard specifies generic cabling to serve the automation islands in industrial premises, or industrial spaces within other types of building.
It covers balanced cabling and optical fibre cabling.
This standard specifies directly or via reference to EN 50173 1 the:
—  structure and minimum configuration for generic cabling within industrial spaces;
—  interfaces at the telecommunications outlet (TO);
—  performance requirements for cabling links and channels;
—  implementation requirements and options;
—  performance requirements for cabling components;
—  conformance requirements and verification procedures.
Alusdokumendid: EN 50173-3:2018/prA1:2026
prEN 9300-230
Aerospace series - LOTAR - LOng Term Archiving and Retrieval of digital technical product documentation such as 3D, CAD and PDM data - Part 230: As-built/As-delivered/As-maintained
Käsitlusala: This document specifies the “as-built” data used for demonstrating completion of the build process and conformity of the product to type design. This document defines the minimum set of information to be archived to serve as a complete representation of an organization’s as-built data.
Alusdokumendid: prEN 9300-230
prEN 304 625 V1.0.0
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded füüsilistele ja virtuaalsetele võrguliidestele
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for physical and virtual network interfaces related to cybersecurity. The products with digital elements in scope, thereafter "network interfaces":
• are specified within the "technical description" of the "category of product" number "10" by the Commission Implementing Regulation (EU) 2025/2392 as:
"Physical network interfaces are products with digital elements that directly connect a device to a network via an Application Programming Interface (API) provided by the interface drivers, typically operating at the data link layer, and that feature hardware adapters to transmission media with corresponding firmware, typically operating at the physical and data link layer.
Virtual network interfaces are products with digital elements that directly or indirectly connect a device to a network via an API that emulates that of drivers of physical network interfaces, typically operating at the data link layer.
This category includes but is not limited to wired and wireless network interface cards, controllers and adapters, such as for Wi-Fi®, Ethernet, IrDA, USB, Bluetooth, NearLink, Zigbee®, or Fieldbus, as well as purely virtual standalone products, such as virtual network interface cards, container network interfaces and VPN interfaces".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847, Annex I Part I under the conditions identified in Annex A.
Network interfaces intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the present document, see prEN 50770 series.
Network interfaces whose intended purpose includes management or configuration of the product over the attached network are excluded from the present document.
Network interfaces whose intended purpose includes routing, switching; or transfer of information from one attached network to a different attached network are excluded from the present document.
Alusdokumendid: Draft ETSI EN 304 625 V1.0.0
EN ISO 12855:2025/prA1
Electronic fee collection - Information exchange between service provision and toll charging - Amendment 1 (ISO 12855:2025/DAM 1:2026)
Käsitlusala: Amendment to EN ISO 12855:2025
Alusdokumendid: ISO 12855:2025/DAmd 1; EN ISO 12855:2025/prA1
prEN 304 622 V1.0.0
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded turvateabe ja -sündmuste haldamise (SIEM) süsteemidele
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for Security Information and Event Management related to cybersecurity.
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems":
• are specified within the "technical description" of the "category of product" number 7 by the Commission Implementing Regulation (EU) 2025/2392 as: Products with digital elements that collect data from multiple sources, analyse and correlate that data and present it as actionable information for security-related purposes, such as threat and incident detection, forensic analysis or compliance purposes.
• are covered only within the product context described in clause 4.
The present document covers those products for the purpose of demonstrating compliance with the essential cybersecurity requirements of Regulation (EU) 2024/2847 Annex I, Part I under the conditions identified in Annex A.
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the present document, see prEN 50770 series.
Alusdokumendid: Draft ETSI EN 304 622 V1.0.0
prEN 304 617 V1.0.0
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded brauseritele
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for web browsers related to cybersecurity. The products with digital elements in scope, thereafter "the products" are specified within the "technical description" of the "category of product" number "2" by the Commission Implementing Regulation (EU) 2025/2392 as:
• "Software products with digital elements that enable end users to access, render, and interact with web content and services hosted on servers that are connected to networks such as the Internet. They typically include a browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of temporary or persistent data from websites (cookies).
This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded browsers intended for integration into another system or application as well as browsers with AI agent integration."
The products are only covered within the product context described in clause 4. The present document specifies technical characteristics and methods of assessment for:
• Standalone web browsers: standalone applications that fulfil the functions of web browsers
• Embedded web browsers: embedded browsers intended for integration into another system or application
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in Annex A.
Browsers with AI agent integration are out of the scope of the present document as well.
Alusdokumendid: Draft ETSI EN 304 617 V1.0.0
prEN 304 626 V1.0.1
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded operatsioonisüsteemidele
Käsitlusala: 1.1 General
The present document specifies technical requirements and corresponding assessment criteria for operating systems related to cybersecurity. The products with digital elements in scope, thereafter "the operating system":
• are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by the Commission Implementing Regulation (EU) 2025/2392 as: "software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real time operating systems, general-purpose and special-purpose operating systems".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in Annex A.
The use of harmonised standards is voluntary.
1.2 Products in scope
1.2.1 General
Products in scope are products whose core function and intended or reasonably foreseeable use or misuse is as an operating system. Operating systems are defined in point 11 of Annex III, Class I of Regulation (EU) 2024/2847 and described in Commission Implementing Regulation (EU) 2025/2392 as "software products with digital elements that provide an abstract interface of the underlying hardware and control the execution of software, and that may provide services such as computing resource management and configuration, scheduling, input-output control, managing data, and providing an interface through which applications interact with system resources and peripherals. This category includes but is not limited to real-time operating systems, general-purpose and special-purpose operating systems".
The present document applies equally to real-time, general-purpose, and special-purpose operating systems. Where a specific requirement depends on hardware or software features that not all operating system architectures provide, the applicability of that requirement is stated in the applicability field of the corresponding mitigation in clause 5.
The underlying hardware may be virtualised to some degree, as when an operating system is running on a hypervisor.
This category includes but is not limited to:
• General purpose operating systems
- Personal computing operating systems
- Mobile operating systems
- Server operating systems
• Special purpose operating systems
- Real-time operating systems
- Embedded operating systems
- Single-purpose operating systems
Many products contain multiple operating systems which can affect the security functions of other operating system(s) in the product. For example, a Baseboard Management Controller (BMC) contains an operating system that can manage most or all of the hardware managed by the main system operating system. Radiofrequency transmission devices often have an embedded real-time operating system and the ability to read or write to system memory or trigger interrupts.
Where a product contains multiple operating systems, the present document applies to each operating system in scope separately. From the perspective of the operating system under assessment, any other operating system in the product is part of its operational environment.
Some of the operating systems may not always be readily available as separate products and are included as components of another product. Where there may be other specifications that target that product category, it may be more relevant to review the operating system as part of that larger system rather than independently via the present document.
1.2.2 Components of operating systems that are in scope
The present document applies to the operating system as a whole. The following non-exhaustive list identifies common component types where the cybersecurity requirements of the present document most often have effect. The list is informative; all components of the operating system are covered by the requirements.
The following non-exhaustive list of types of components are common to many operating systems and, when present, are considered security-relevant:
• Kernel: The central component responsible for managing hardware resources and enforcing access controls.
• Device Drivers: Software components supplied with the operating system that interact directly with hardware devices.
• Cybersecurity Libraries: Libraries used to provide cybersecurity services, such as encryption, authentication, and authorisation.
• Authentication Services: Authentication mechanisms required for operating system functionality.
• Privileged Processes: Operating system processes running with elevated privileges or access to sensitive resources.
• Software Update Mechanisms: Systems responsible for installing and updating software components supplied with the operating system.
• Logging and Monitoring: Functions performed by the operating system that record cybersecurity-relevant events or monitor system behaviour.
• Configuration Management: Management of the configuration of cybersecurity-relevant operating system settings, including provisioning of a secure-by-default configuration.
A given component may fall under more than one category. The categories are illustrative and not mutually exclusive.
1.3 Products covered by other CRA harmonised standards
Some product categories that provide functionality overlapping with an operating system are covered by their own CRA harmonised standard. Where such a standard exists for a product category, that standard applies to it. These categories include:
• Hypervisors and container runtime systems that support virtualised execution of operating systems (Annex III, Class II, point 1 of Regulation (EU) 2024/2847).
• Boot managers (Annex III, Class I, point 8 of Regulation (EU) 2024/2847).
For products that embed or interact with an operating system while having a different core functionality, manufacturers may refer to the present document as one part of demonstrating compliance for the operating system component.
Alusdokumendid: Draft ETSI EN 304 626 V1.0.1
prEN 304 621 V1.0.5
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded võrguhaldussüsteemidele
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for Network Management Systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":
• are specified within the "technical description" of the "category of product" number "6" by the Commission Implementing Regulation (EU) 2025/2392 as: "Products with digital elements that manage connected network elements, such as servers, routers, switches, workstations, printers or mobile devices, by monitoring them and controlling their network operations and configuration".
This category includes but is not limited to end-to-end management systems and dedicated configuration management systems, such as controllers for software-defined networking.
• The products with digital elements in scope are only covered within the product context described in clause 4 of the present document.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in annex A.
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking, e.g when an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI).
NMS intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the present document.
An NMS is a product controlling at least partially connected devices with network access. Despite its central positioning, an NMS can be an aggregate of several components, including but not limited to: end-to-end management systems, dedicated configuration management systems, or controllers for software-defined networking.
NMS can be composed of several components or can implement additional functions that are outside the scope of the present document.
EXAMPLE: Aggregate product design would be an implementation where the operating system acts as an abstraction layer for the system(s) that host the NMS, or the networking interfaces.
Alusdokumendid: Draft ETSI EN 304 621 V1.0.5
prEN 304 620 V1.0.0
Küberturvalisus (CYBER); CRA; Küberturvalisuse nõuded virtuaalsetele privaatvõrkudele (VPN)
Käsitlusala: The present document specifies technical requirements and corresponding assessment criteria for Virtual Private Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs":
• are specified within the "technical description" of the "category of product" number "5" by the Commission Implementing Regulation (EU) 2025/2392 as: "Products with digital elements that establish an encrypted logical tunnel that is constructed from the system resources of a physical or virtual network".
• are only covered within the product context described in clause 4 and the text of this clause.
In particular, the present document specifies technical characteristics and methods of assessment for:
1) Software that operates as a VPN client or endpoint
2) Software that operates as a node within a mesh VPN network
3) Software that operates as a VPN server
4) Remote data processing, specifically VPN server software performing the logical server role, and associated software used for such VPN products
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the Regulation (EU) 2024/2847 Annex I Part I under the conditions identified in Annex A.
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document. VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the present document, see prEN 50770 series.
Alusdokumendid: Draft ETSI EN 304 620 V1.0.0