The ETSI EN 304 series: one CRA standard per product category
While CEN and CENELEC draft the horizontal EN 40000 series, ETSI is drafting 18 vertical standards, one for each Annex III product category. This is the full mapping from your classification to the standard being written for it.
In approval, not yet cited, so no presumption of conformity
17 of the 18 ETSI EN 304 6xx deliverables have a publicly downloadable draft, and 10 of those record an open ETSI approval procedure. No deliverable in the series is cited in the Official Journal of the European Union, so applying one does not confer presumption of conformity and does not change the conformity assessment route for your product.
A Harmonised Standard flag reading Yes is not a citation
Each of these ETSI work items carries a field labelled Harmonised Standard, and on every one it reads Yes. That field marks the deliverable as a candidate for harmonisation under standardisation request M/606. A separate field on the same page records the Official Journal reference, and on 2026-09-01 it was empty for all 18 deliverables. Article 27 turns on that second field.
ETSI announced on 13 August 2026 that 17 final drafts had entered Public Enquiry, and the procedure closes between mid-September and mid-November 2026. The per-deliverable status in the table below is finer than that announcement, because 10 work items record an open approval procedure and the rest record an earlier assessment step. Both readings come from ETSI. Check the announcement and the work item for your own category rather than either summary.
Horizontal and vertical standards
Standardisation request M/606 asked CEN, CENELEC and ETSI for 41 standards. They split into two kinds. The horizontal standards apply to every product with digital elements and cover the essential requirements in general terms. That is the EN 40000 series from CEN-CENELEC JTC 13. The vertical standards each cover one Annex III product category, and most of those went to ETSI TC CYBER as the EN 304 6xx series.
The numbering is not arbitrary. A deliverable number is 304 600 plus its M/606 line item, so line item 17 for browsers is EN 304 617 and line item 36 for firewalls is EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead, which is why there is no EN 304 628 through 630.
A manufacturer of an important product will likely end up needing both families. The horizontal series carries the general essential requirements and the vulnerability handling process, and the vertical standard adds what that specific product type has to do.
The 18 ETSI vertical standards
| ETSI standard | Annex III / IV point | Status | Read it yourself | Other ESO track |
|---|---|---|---|---|
Browsers | Annex III, Class I, point 2 Standalone and embedded browsers | Approval procedure initiated V1.0.0, 2026-08-13 Opened 2026-08-13 |
| |
Password managers | Annex III, Class I, point 3 Password managers | Enquiry draft V0.2.2, 2026-06-22 |
| |
Anti-malware software | Annex III, Class I, point 4 Software that searches for, removes, or quarantines malicious software | Approval procedure initiated V1.0.0, 2026-07-20 Opened 2026-07-20 |
| |
VPN products | Annex III, Class I, point 5 Products with digital elements with the function of virtual private network (VPN) | Approval procedure initiated V1.0.0, 2026-08-13 Opened 2026-08-13 |
| prEN 50770-4 CENELEC CLC/TC 65X WG 3 |
Network management systems | Annex III, Class I, point 6 Network management systems | Approval procedure initiated V1.0.5, 2026-08-13 Opened 2026-08-13 |
| prEN 50770-2 CENELEC CLC/TC 65X WG 3 |
SIEM systems | Annex III, Class I, point 7 Security information and event management (SIEM) systems | Approval procedure initiated V1.0.0, 2026-08-13 Opened 2026-08-13 |
| prEN 50770-6 CENELEC CLC/TC 65X WG 3 |
Boot managers | Annex III, Class I, point 8 Boot managers | Enquiry draft V0.1.3, 2026-06-17 |
| |
PKI and certificate issuance | Annex III, Class I, point 9 Public key infrastructure and digital certificate issuance software | Final draft V1.0.0, 2026-08-06 |
| |
Network interfaces | Annex III, Class I, point 10 Physical and virtual network interfaces | Approval procedure initiated V1.0.0, 2026-08-10 Opened 2026-08-10 |
| prEN 50770-3 CENELEC CLC/TC 65X WG 3 |
Operating systems | Annex III, Class I, point 11 Operating systems | Approval procedure initiated V1.0.1, 2026-08-13 Opened 2026-08-13 |
| |
Routers, modems and switches | Annex III, Class I, point 12 Routers, modems intended for the connection to the internet, and switches | Final draft V1.0.1, 2026-07-09 |
| prEN 50770-5 CENELEC CLC/TC 65X WG 3 |
Smart home virtual assistants | Annex III, Class I, point 16 Smart home general purpose virtual assistants | Approval procedure initiated V1.0.0, 2026-07-20 Opened 2026-07-20 |
| |
Smart home security products | Annex III, Class I, point 17 Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems | Approval procedure initiated V1.0.0, 2026-07-20 Opened 2026-07-20 |
| |
Internet-connected toys | Annex III, Class I, point 18 Internet connected toys covered by Directive 2009/48/EC that have social interactive features (e.g. speaking or filming) or that have location tracking features | Approval procedure initiated V1.0.0, 2026-07-20 Opened 2026-07-20 |
| |
Personal wearables | Annex III, Class I, point 19 Personal wearable products worn or placed on a human body with a health monitoring purpose (outside Regulation (EU) 2017/745 or 2017/746), or personal wearable products intended for use by and for children | Final draft V1.0.0, 2026-07-23 |
| |
Hypervisors and container runtimes | Annex III, Class II, point 1 Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments | Final draft V1.0.1, 2026-06-25 |
| |
Firewalls and IDS/IPS | Annex III, Class II, point 2 Firewalls, intrusion detection and prevention systems | Final draft V1.0.0, 2026-07-13 |
| prEN 50770-1 CENELEC CLC/TC 65X WG 3 |
EN 304 642 Telecom network functions | No Annex III or Annex IV point. A separate M/606 line item. | Work item, no public draft |
|
Verified 2026-09-01. Version, cover date and status come from each deliverable's own ETSI Work Programme work item report. The published PDF is the permanent version-addressed copy in the ETSI publication directory, and the draft source is the public GitLab repository where the rapporteur edits it. Numbering and stages follow the ETSI work programme and can change.
What ETSI is not covering
Nine Annex III and Annex IV points sit outside the EN 304 series. If your product is one of these, watching the ETSI work programme will tell you nothing. These are the committees to follow instead.
| Annex point | Category | Drafted instead by |
|---|---|---|
| Annex III, Class I, point 1 | Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers | Number not yet allocated CEN/TC 224 WG 17 |
| Annex III, Class I, point 13 | Microprocessors with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class I, point 14 | Microcontrollers with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class I, point 15 | Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities | prEN 50765 CENELEC CLC/TC 47X |
| Annex III, Class II, point 3 | Tamper-resistant microprocessors | prEN 50766 CENELEC CLC/TC 47X |
| Annex III, Class II, point 4 | Tamper-resistant microcontrollers | prEN 50766 CENELEC CLC/TC 47X |
| Annex IV, point 1 | Hardware Devices with Security Boxes | Number not yet allocated CEN/TC 224 WG 17 |
| Annex IV, point 2 | Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing | Number not yet allocated CEN-CLC/JTC 13 WG 6 |
| Annex IV, point 3 | Smartcards or similar devices, including secure elements | prEN 50764 CENELEC CLC/TC 47X prEN 18330 CEN/TC 224 WG 17 |
The operational-technology series
Six product types are being standardised twice. CENELEC CLC/TC 65X WG 3 is drafting the prEN 50770 series on IEC 62443 foundations, covering the same product types as their ETSI counterparts but aimed at operational technology. The M/606 wording for the firewall item reaches industrial use explicitly, which is where the overlap comes from.
- prEN 50770-1An IEC 62443-based equivalent for firewalls and intrusion detection or prevention systems intended for industrial use.
- prEN 50770-2An IEC 62443-based equivalent for network management systems in operational technology.
- prEN 50770-3An IEC 62443-based equivalent for physical and virtual network interfaces in operational technology.
- prEN 50770-4An IEC 62443-based equivalent for VPN products deployed in operational technology.
- prEN 50770-5An IEC 62443-based equivalent for routers, modems and switches in operational technology.
- prEN 50770-6An IEC 62443-based equivalent for SIEM systems in operational technology.
If you sell the same product into both IT and OT markets, you may eventually have a choice of standard to apply. Neither track is cited in the Official Journal, so this is a decision to revisit once citations appear rather than one to make now.
EN 304 questions
Is there a CRA harmonised standard for my product category yet?
There is a draft or a work item for every Annex III category, but none is cited in the Official Journal of the European Union. Until a citation appears, no standard confers presumption of conformity, and an Annex III Class I product without an applied harmonised standard goes to third-party conformity assessment under Article 32(2).
What is the difference between EN 40000 and EN 304 6xx?
EN 40000 is horizontal: CEN and CENELEC are drafting it to apply across every product with digital elements. EN 304 6xx is vertical: ETSI is drafting one standard per Annex III product category. A manufacturer of an important product will likely need both, the horizontal series for the general essential requirements and the vertical standard for its product type.
How do the ETSI numbers map to the standardisation request?
The deliverable number is 304 600 plus the M/606 line item. Line item 17, standalone and embedded browsers, becomes EN 304 617. Line item 36, firewalls and intrusion detection or prevention systems, becomes EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead of ETSI.
Which Annex III categories is ETSI not writing a standard for?
Identity management and privileged access management, the semiconductor categories (microprocessors, microcontrollers, ASICs and FPGAs, and their tamper-resistant variants), and all three Annex IV critical categories. Those sit with CEN/TC 224, CENELEC CLC/TC 47X and CEN-CLC/JTC 13 WG 6 instead.
Do I need the ETSI standard or the operational-technology one?
Six product types have both an ETSI deliverable and a CENELEC prEN 50770 equivalent built on IEC 62443, covering firewalls, network management systems, network interfaces, VPNs, routers and SIEM. The mandate wording for the firewall item reaches industrial use explicitly. Neither track is cited yet, so this is a question to revisit when citations appear.
Public drafts are published in the ETSI CYBER-EUSR open consultation area at docbox.etsi.org. Paths there change as drafts progress.
Find out which standard applies to you
Classify your product against Annex III in under a minute and see the vertical standard being drafted for its category, along with the conformity assessment route the CRA sends it down.