← All standards
ETSICRA vertical standards

The ETSI EN 304 series: one CRA standard per product category

While CEN and CENELEC draft the horizontal EN 40000 series, ETSI is drafting 18 vertical standards, one for each Annex III product category. This is the full mapping from your classification to the standard being written for it.

Draft standards, no presumption of conformity yet

No standard in the ETSI EN 304 6xx series is cited in the Official Journal of the European Union. Every deliverable below is a draft or a work item, so applying one does not confer presumption of conformity and does not change the conformity assessment route for your product.

Horizontal and vertical standards

Standardisation request M/606 asked CEN, CENELEC and ETSI for 41 standards. They split into two kinds. The horizontal standards apply to every product with digital elements and cover the essential requirements in general terms. That is the EN 40000 series from CEN-CENELEC JTC 13. The vertical standards each cover one Annex III product category, and most of those went to ETSI TC CYBER as the EN 304 6xx series.

The numbering is not arbitrary. A deliverable number is 304 600 plus its M/606 line item, so line item 17 for browsers is EN 304 617 and line item 36 for firewalls is EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead, which is why there is no EN 304 628 through 630.

A manufacturer of an important product will likely end up needing both families. The horizontal series carries the general essential requirements and the vulnerability handling process, and the vertical standard adds what that specific product type has to do.

The 18 ETSI vertical standards

ETSI standardAnnex III / IV pointStatusOther ESO track
Browsers
Annex III, Class I, point 2
Standalone and embedded browsers
Mature draft
V0.1.1, 2026-04-04
Password managers
Annex III, Class I, point 3
Password managers
Enquiry draft
V0.2.2, 2026-06-22
Anti-malware software
Annex III, Class I, point 4
Software that searches for, removes, or quarantines malicious software
Enquiry draft
V1.0.0, 2026-07-15
VPN products
Annex III, Class I, point 5
Products with digital elements with the function of virtual private network (VPN)
Mature draft
V0.1.9, 2026-04-27
prEN 50770-4
CENELEC CLC/TC 65X WG 3
Network management systems
Annex III, Class I, point 6
Network management systems
Mature draft
V0.1.3, 2026-04-20
prEN 50770-2
CENELEC CLC/TC 65X WG 3
EN 304 622
SIEM systems
Annex III, Class I, point 7
Security information and event management (SIEM) systems
Work item, no public draft
prEN 50770-6
CENELEC CLC/TC 65X WG 3
Boot managers
Annex III, Class I, point 8
Boot managers
Enquiry draft
V0.1.3, 2026-06-17
EN 304 624
PKI and certificate issuance
Annex III, Class I, point 9
Public key infrastructure and digital certificate issuance software
Work item, no public draft
Network interfaces
Annex III, Class I, point 10
Physical and virtual network interfaces
Mature draft
V0.0.14, 2026-04-17
prEN 50770-3
CENELEC CLC/TC 65X WG 3
EN 304 626
Operating systems
Annex III, Class I, point 11
Operating systems
Work item, no public draft
Routers, modems and switches
Annex III, Class I, point 12
Routers, modems intended for the connection to the internet, and switches
Enquiry draft
V1.0.1, 2026-07-06
prEN 50770-5
CENELEC CLC/TC 65X WG 3
EN 304 631
Smart home virtual assistants
Annex III, Class I, point 16
Smart home general purpose virtual assistants
Work item, no public draft
EN 304 632
Smart home security products
Annex III, Class I, point 17
Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
Work item, no public draft
Internet-connected toys
Annex III, Class I, point 18
Internet connected toys covered by Directive 2009/48/EC that have social interactive features (e.g. speaking or filming) or that have location tracking features
Final draft
V0.4.3, 2026-07-10
Personal wearables
Annex III, Class I, point 19
Personal wearable products worn or placed on a human body with a health monitoring purpose (outside Regulation (EU) 2017/745 or 2017/746), or personal wearable products intended for use by and for children
Final draft
V0.4.2, 2026-07-10
Hypervisors and container runtimes
Annex III, Class II, point 1
Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
Enquiry draft
V1.0.1, 2026-06-24
Firewalls and IDS/IPS
Annex III, Class II, point 2
Firewalls, intrusion detection and prevention systems
Enquiry draft
V1.0.0, 2026-07-09
prEN 50770-1
CENELEC CLC/TC 65X WG 3
EN 304 642
Telecom network functions
No Annex III or Annex IV point. A separate M/606 line item.
Work item, no public draft

Versions and stages verified 2026-07-29 against the ETSI CYBER-EUSR open consultation area. Only publicly downloadable drafts are listed, so a deliverable shown as a work item may be further along inside ETSI than this table can show. Numbering and stages follow the ETSI work programme and can change.

What ETSI is not covering

Nine Annex III and Annex IV points sit outside the EN 304 series. If your product is one of these, watching the ETSI work programme will tell you nothing. These are the committees to follow instead.

Annex pointCategoryDrafted instead by
Annex III, Class I, point 1Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
Number not yet allocated
CEN/TC 224 WG 17
Annex III, Class I, point 13Microprocessors with security-related functionalities
prEN 50765
CENELEC CLC/TC 47X
Annex III, Class I, point 14Microcontrollers with security-related functionalities
prEN 50765
CENELEC CLC/TC 47X
Annex III, Class I, point 15Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
prEN 50765
CENELEC CLC/TC 47X
Annex III, Class II, point 3Tamper-resistant microprocessors
prEN 50766
CENELEC CLC/TC 47X
Annex III, Class II, point 4Tamper-resistant microcontrollers
prEN 50766
CENELEC CLC/TC 47X
Annex IV, point 1Hardware Devices with Security Boxes
Number not yet allocated
CEN/TC 224 WG 17
Annex IV, point 2Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing
Number not yet allocated
CEN-CLC/JTC 13 WG 6
Annex IV, point 3Smartcards or similar devices, including secure elements
prEN 50764
CENELEC CLC/TC 47X
prEN 18330
CEN/TC 224 WG 17

The operational-technology series

Six product types are being standardised twice. CENELEC CLC/TC 65X WG 3 is drafting the prEN 50770 series on IEC 62443 foundations, covering the same product types as their ETSI counterparts but aimed at operational technology. The M/606 wording for the firewall item reaches industrial use explicitly, which is where the overlap comes from.

  • prEN 50770-1An IEC 62443-based equivalent for firewalls and intrusion detection or prevention systems intended for industrial use.
  • prEN 50770-2An IEC 62443-based equivalent for network management systems in operational technology.
  • prEN 50770-3An IEC 62443-based equivalent for physical and virtual network interfaces in operational technology.
  • prEN 50770-4An IEC 62443-based equivalent for VPN products deployed in operational technology.
  • prEN 50770-5An IEC 62443-based equivalent for routers, modems and switches in operational technology.
  • prEN 50770-6An IEC 62443-based equivalent for SIEM systems in operational technology.

If you sell the same product into both IT and OT markets, you may eventually have a choice of standard to apply. Neither track is cited in the Official Journal, so this is a decision to revisit once citations appear rather than one to make now.

EN 304 questions

Is there a CRA harmonised standard for my product category yet?

There is a draft or a work item for every Annex III category, but none is cited in the Official Journal of the European Union. Until a citation appears, no standard confers presumption of conformity, and an Annex III Class I product without an applied harmonised standard goes to third-party conformity assessment under Article 32(2).

What is the difference between EN 40000 and EN 304 6xx?

EN 40000 is horizontal: CEN and CENELEC are drafting it to apply across every product with digital elements. EN 304 6xx is vertical: ETSI is drafting one standard per Annex III product category. A manufacturer of an important product will likely need both, the horizontal series for the general essential requirements and the vertical standard for its product type.

How do the ETSI numbers map to the standardisation request?

The deliverable number is 304 600 plus the M/606 line item. Line item 17, standalone and embedded browsers, becomes EN 304 617. Line item 36, firewalls and intrusion detection or prevention systems, becomes EN 304 636. The gaps in the sequence are the line items that went to CEN and CENELEC instead of ETSI.

Which Annex III categories is ETSI not writing a standard for?

Identity management and privileged access management, the semiconductor categories (microprocessors, microcontrollers, ASICs and FPGAs, and their tamper-resistant variants), and all three Annex IV critical categories. Those sit with CEN/TC 224, CENELEC CLC/TC 47X and CEN-CLC/JTC 13 WG 6 instead.

Do I need the ETSI standard or the operational-technology one?

Six product types have both an ETSI deliverable and a CENELEC prEN 50770 equivalent built on IEC 62443, covering firewalls, network management systems, network interfaces, VPNs, routers and SIEM. The mandate wording for the firewall item reaches industrial use explicitly. Neither track is cited yet, so this is a question to revisit when citations appear.

Public drafts are published in the ETSI CYBER-EUSR open consultation area at docbox.etsi.org. Paths there change as drafts progress.

Find out which standard applies to you

Classify your product against Annex III in under a minute and see the vertical standard being drafted for its category, along with the conformity assessment route the CRA sends it down.