The ETSI EN 304 series: one CRA standard per product category
While CEN and CENELEC draft the horizontal EN 40000 series, ETSI is drafting 18 vertical standards, one for each Annex III product category. This is the full mapping from your classification to the standard being written for it.
Draft standards, no presumption of conformity yet
No standard in the ETSI EN 304 6xx series is cited in the Official Journal of the European Union. Every deliverable below is a draft or a work item, so applying one does not confer presumption of conformity and does not change the conformity assessment route for your product.
Horizontal and vertical standards
Standardisation request M/606 asked CEN, CENELEC and ETSI for 41 standards. They split into two kinds. The horizontal standards apply to every product with digital elements and cover the essential requirements in general terms. That is the EN 40000 series from CEN-CENELEC JTC 13. The vertical standards each cover one Annex III product category, and most of those went to ETSI TC CYBER as the EN 304 6xx series.
The numbering is not arbitrary. A deliverable number is 304 600 plus its M/606 line item, so line item 17 for browsers is EN 304 617 and line item 36 for firewalls is EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead, which is why there is no EN 304 628 through 630.
A manufacturer of an important product will likely end up needing both families. The horizontal series carries the general essential requirements and the vulnerability handling process, and the vertical standard adds what that specific product type has to do.
The 18 ETSI vertical standards
| ETSI standard | Annex III / IV point | Status | Other ESO track |
|---|---|---|---|
Browsers | Annex III, Class I, point 2 Standalone and embedded browsers | Mature draft V0.1.1, 2026-04-04 | |
Password managers | Annex III, Class I, point 3 Password managers | Enquiry draft V0.2.2, 2026-06-22 | |
Anti-malware software | Annex III, Class I, point 4 Software that searches for, removes, or quarantines malicious software | Enquiry draft V1.0.0, 2026-07-15 | |
VPN products | Annex III, Class I, point 5 Products with digital elements with the function of virtual private network (VPN) | Mature draft V0.1.9, 2026-04-27 | prEN 50770-4 CENELEC CLC/TC 65X WG 3 |
Network management systems | Annex III, Class I, point 6 Network management systems | Mature draft V0.1.3, 2026-04-20 | prEN 50770-2 CENELEC CLC/TC 65X WG 3 |
EN 304 622 SIEM systems | Annex III, Class I, point 7 Security information and event management (SIEM) systems | Work item, no public draft | prEN 50770-6 CENELEC CLC/TC 65X WG 3 |
Boot managers | Annex III, Class I, point 8 Boot managers | Enquiry draft V0.1.3, 2026-06-17 | |
EN 304 624 PKI and certificate issuance | Annex III, Class I, point 9 Public key infrastructure and digital certificate issuance software | Work item, no public draft | |
Network interfaces | Annex III, Class I, point 10 Physical and virtual network interfaces | Mature draft V0.0.14, 2026-04-17 | prEN 50770-3 CENELEC CLC/TC 65X WG 3 |
EN 304 626 Operating systems | Annex III, Class I, point 11 Operating systems | Work item, no public draft | |
Routers, modems and switches | Annex III, Class I, point 12 Routers, modems intended for the connection to the internet, and switches | Enquiry draft V1.0.1, 2026-07-06 | prEN 50770-5 CENELEC CLC/TC 65X WG 3 |
EN 304 631 Smart home virtual assistants | Annex III, Class I, point 16 Smart home general purpose virtual assistants | Work item, no public draft | |
EN 304 632 Smart home security products | Annex III, Class I, point 17 Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems | Work item, no public draft | |
Internet-connected toys | Annex III, Class I, point 18 Internet connected toys covered by Directive 2009/48/EC that have social interactive features (e.g. speaking or filming) or that have location tracking features | Final draft V0.4.3, 2026-07-10 | |
Personal wearables | Annex III, Class I, point 19 Personal wearable products worn or placed on a human body with a health monitoring purpose (outside Regulation (EU) 2017/745 or 2017/746), or personal wearable products intended for use by and for children | Final draft V0.4.2, 2026-07-10 | |
Hypervisors and container runtimes | Annex III, Class II, point 1 Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments | Enquiry draft V1.0.1, 2026-06-24 | |
Firewalls and IDS/IPS | Annex III, Class II, point 2 Firewalls, intrusion detection and prevention systems | Enquiry draft V1.0.0, 2026-07-09 | prEN 50770-1 CENELEC CLC/TC 65X WG 3 |
EN 304 642 Telecom network functions | No Annex III or Annex IV point. A separate M/606 line item. | Work item, no public draft |
Versions and stages verified 2026-07-29 against the ETSI CYBER-EUSR open consultation area. Only publicly downloadable drafts are listed, so a deliverable shown as a work item may be further along inside ETSI than this table can show. Numbering and stages follow the ETSI work programme and can change.
What ETSI is not covering
Nine Annex III and Annex IV points sit outside the EN 304 series. If your product is one of these, watching the ETSI work programme will tell you nothing. These are the committees to follow instead.
| Annex point | Category | Drafted instead by |
|---|---|---|
| Annex III, Class I, point 1 | Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers | Number not yet allocated CEN/TC 224 WG 17 |
| Annex III, Class I, point 13 | Microprocessors with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class I, point 14 | Microcontrollers with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class I, point 15 | Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class II, point 3 | Tamper-resistant microprocessors | prEN 50766 CENELEC CLC/TC 47X |
| Annex III, Class II, point 4 | Tamper-resistant microcontrollers | prEN 50766 CENELEC CLC/TC 47X |
| Annex IV, point 1 | Hardware Devices with Security Boxes | Number not yet allocated CEN/TC 224 WG 17 |
| Annex IV, point 2 | Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing | Number not yet allocated CEN-CLC/JTC 13 WG 6 |
| Annex IV, point 3 | Smartcards or similar devices, including secure elements | prEN 50764 CENELEC CLC/TC 47X prEN 18330 CEN/TC 224 WG 17 |
The operational-technology series
Six product types are being standardised twice. CENELEC CLC/TC 65X WG 3 is drafting the prEN 50770 series on IEC 62443 foundations, covering the same product types as their ETSI counterparts but aimed at operational technology. The M/606 wording for the firewall item reaches industrial use explicitly, which is where the overlap comes from.
- prEN 50770-1An IEC 62443-based equivalent for firewalls and intrusion detection or prevention systems intended for industrial use.
- prEN 50770-2An IEC 62443-based equivalent for network management systems in operational technology.
- prEN 50770-3An IEC 62443-based equivalent for physical and virtual network interfaces in operational technology.
- prEN 50770-4An IEC 62443-based equivalent for VPN products deployed in operational technology.
- prEN 50770-5An IEC 62443-based equivalent for routers, modems and switches in operational technology.
- prEN 50770-6An IEC 62443-based equivalent for SIEM systems in operational technology.
If you sell the same product into both IT and OT markets, you may eventually have a choice of standard to apply. Neither track is cited in the Official Journal, so this is a decision to revisit once citations appear rather than one to make now.
EN 304 questions
Is there a CRA harmonised standard for my product category yet?
There is a draft or a work item for every Annex III category, but none is cited in the Official Journal of the European Union. Until a citation appears, no standard confers presumption of conformity, and an Annex III Class I product without an applied harmonised standard goes to third-party conformity assessment under Article 32(2).
What is the difference between EN 40000 and EN 304 6xx?
EN 40000 is horizontal: CEN and CENELEC are drafting it to apply across every product with digital elements. EN 304 6xx is vertical: ETSI is drafting one standard per Annex III product category. A manufacturer of an important product will likely need both, the horizontal series for the general essential requirements and the vertical standard for its product type.
How do the ETSI numbers map to the standardisation request?
The deliverable number is 304 600 plus the M/606 line item. Line item 17, standalone and embedded browsers, becomes EN 304 617. Line item 36, firewalls and intrusion detection or prevention systems, becomes EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead of ETSI.
Which Annex III categories is ETSI not writing a standard for?
Identity management and privileged access management, the semiconductor categories (microprocessors, microcontrollers, ASICs and FPGAs, and their tamper-resistant variants), and all three Annex IV critical categories. Those sit with CEN/TC 224, CENELEC CLC/TC 47X and CEN-CLC/JTC 13 WG 6 instead.
Do I need the ETSI standard or the operational-technology one?
Six product types have both an ETSI deliverable and a CENELEC prEN 50770 equivalent built on IEC 62443, covering firewalls, network management systems, network interfaces, VPNs, routers and SIEM. The mandate wording for the firewall item reaches industrial use explicitly. Neither track is cited yet, so this is a question to revisit when citations appear.
Public drafts are published in the ETSI CYBER-EUSR open consultation area at docbox.etsi.org. Paths there change as drafts progress.
Find out which standard applies to you
Classify your product against Annex III in under a minute and see the vertical standard being drafted for its category, along with the conformity assessment route the CRA sends it down.