Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtualisation Execution Stack (VES) and Container Execution Stack (CES), including hypervisors and container runtime systems

DEN/CYBER-EUS-0016

General Information

Status
Not Published
Current Stage
6 - First complete draft
Due Date
23-Jun-2026
Completion Date
23-Jun-2026

Buy Documents

Standard

ETSI EN 304 635 V1.0.1 (2026-06) - Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtualisation Execution Stack (VES) and Container Execution Stack (CES), including hypervisors and container runtime systems

English language (386 pages)
sale 15% off
Preview
sale 15% off
Preview

Buy Documents

Standard

ETSI EN 304 635 V1.0.1 (2026-06) - Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtualisation Execution Stack (VES) and Container Execution Stack (CES), including hypervisors and container runtime systems

English language (386 pages)
sale 15% off
Preview
sale 15% off
Preview

Frequently Asked Questions

ETSI EN 304 635 V1.0.1 (2026-06) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Cyber Security (CYBER); CRA; Cybersecurity requirements for Virtualisation Execution Stack (VES) and Container Execution Stack (CES), including hypervisors and container runtime systems". This standard covers: DEN/CYBER-EUS-0016

DEN/CYBER-EUS-0016

ETSI EN 304 635 V1.0.1 (2026-06) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Draft ETSI EN 304 635 V1.0.1 (2026-06)

HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements
for Virtualisation Execution Stack (VES)
and Container Execution Stack (CES),
including hypervisors and container runtime systems

2 Draft ETSI EN 304 635 V1.0.1 (2026-06)

Reference
DEN/CYBER-EUS-0016
Keywords
container, CRA, cybersecurity, virtualisation

ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.

© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 635 V1.0.1 (2026-06)
Contents
Intellectual Property Rights . 13
Foreword . 13
Modal verbs terminology . 14
Introduction . 14
1 Scope . 15
2 References . 15
2.1 Normative references . 15
2.2 Informative references . 16
3 Definition of terms, symbols and abbreviations . 17
3.1 Terms . 17
3.2 Symbols . 19
3.3 Abbreviations . 19
4 Product Context . 21
4.1 Product Functions . 21
4.1.1 General . 21
4.1.2 VES . 21
4.1.2.1 Intended purpose and reasonably foreseeable use of the VES . 21
4.1.2.2 Intended purpose and reasonably foreseeable use of the Hypervisor . 21
4.1.2.3 Intended purpose and reasonably foreseeable use of the M&O system . 22
4.1.3 CES . 22
4.1.3.1 Intended purpose and reasonably foreseeable use of the CES . 22
4.1.3.2 Intended purpose and reasonably foreseeable use of the CRS . 22
4.1.3.3 Intended purpose and reasonably foreseeable use of the CE . 23
4.1.3.4 Intended purpose and reasonably foreseeable use of the CO . 23
4.2 Product architecture . 23
4.2.1 General distinction of components . 23
4.2.2 VES . 23
4.2.2.1 Architectural types and virtualisation techniques of VES . 23
4.2.2.2 In-scope components of the VES . 24
4.2.2.2.1 Hypervisor . 24
4.2.2.2.2 Management and Orchestration System . 25
4.2.2.3 Security-relevant environmental dependencies (out of scope) . 26
4.2.3 CES . 27
4.2.3.1 In-scope components . 27
4.2.3.2 Security-relevant environmental dependencies (out of scope) . 28
4.2.4 Deployment of M&O, CE, and CO outside the local execution environment . 28
4.2.5 Product variants and conforming products . 29
4.2.5.1 Definition of conforming products . 29
4.2.5.2 Product variants . 29
4.3 Operational environment . 30
4.3.1 General Principles . 30
4.3.2 Security Objectives for the Operational Environment . 30
4.3.3 Reference to Relevant CRA Harmonised Standards . 32
4.4 Distribution of Security Functions . 32
4.5 Users . 32
4.6 Use cases . 33
4.6.1 Purpose . 33
4.6.2 Use Cases for VES . 33
4.6.3 Use Cases for CES . 35
4.6.4 Use Case to Risk Mapping . 37
5 Technical Requirements for products . 37
5.1 Risk-Based requirement classes/categorization and application . 37
5.1.1 Requirement Classes, Categorization and Security Profiles . 37
ETSI
4 Draft ETSI EN 304 635 V1.0.1 (2026-06)
5.1.1.1 Definition of Requirement Classes: Basic, Elevated, Advanced . 37
5.1.1.2 Security Profile Definitions . 38
5.1.1.3 Requirement Categorization . 38
5.1.1.4 Guidance for Manufacturers. 39
5.1.2 Requirement Application . 40
5.1.2.1 Approaches for determining security requirements . 40
5.1.2.2 SP-Based Requirement Application . 40
5.1.3 Applicability of requirements . 41
5.2 VES Security Requirements . 42
5.2.1 Hypervisor Requirements . 42
5.2.1.1 Isolation . 42
5.2.1.1.1 General . 42
5.2.1.1.2 VM Isolation . 42
5.2.1.1.3 Control Plane Isolation . 43
5.2.1.1.4 Network Plane Separation . 44
5.2.1.2 Integrity Protection. 45
5.2.1.2.1 Boot integrity verification . 45
5.2.1.2.2 Guest VM image integrity verification . 46
5.2.1.2.3 Runtime integrity protection . 47
5.2.1.2.4 Remote attestation . 47
5.2.1.3 Authentication . 48
5.2.1.3.1 General . 48
5.2.1.3.2 Administrative Authentication . 49
5.2.1.3.3 Service Authentication . 49
5.2.1.4 Authorization . 50
5.2.1.4.1 General . 50
5.2.1.4.2 Administrative Authorization . 50
5.2.1.4.3 Service Authorization . 51
5.2.1.5 Confidentiality Protection . 51
5.2.1.6 Availability and Resilience . 52
5.2.1.7 Logging . 53
5.2.1.8 Secure Update . 54
5.2.1.9 Secure Configuration and Default . 55
5.2.1.10 Data Minimisation . 56
5.2.1.11 Decommissioning . 56
5.2.2 Management and Orchestration System Requirements . 57
5.2.2.1 General applicability . 57
5.2.2.2 Authentication . 57
5.2.2.3 Authorization . 57
5.2.2.4 Secure Configuration . 58
5.2.2.5 Communication Security . 58
5.2.2.6 Integrity Protection. 59
5.2.2.7 Logging . 59
5.2.2.8 Secure Update . 60
5.2.2.9 Decommissioning and Secure Transfer . 61
5.3 CES Security Requirements . 61
5.3.1 CRS Requirements . 61
5.3.1.1 Isolation . 61
5.3.1.1.1 Container Isolation . 61
5.3.1.1.2 Control Plane Isolation . 62
5.3.1.1.3 Network Plane Isolation . 62
5.3.1.2 Integrity Protection. 63
5.3.1.2.1 Boot integrity verification . 63
5.3.1.2.2 Container image integrity verification . 64
5.3.1.2.3 Runtime integrity protection . 65
5.3.1.2.4 Remote attestation . 65
5.3.1.3 Authentication . 66
5.3.1.3.1 General . 66
5.3.1.3.2 Administrative Authentication . 67
5.3.1.3.3 Service Authentication . 67
5.3.1.4 Authorization . 68
5.3.1.4.1 General . 68
ETSI
5 Draft ETSI EN 304 635 V1.0.1 (2026-06)
5.3.1.4.2 Administrative Authorization . 68
5.3.1.4.3 Service Authorization . 69
5.3.1.5 Confidentiality Protection . 69
5.3.1.6 Availability and Resilience . 70
5.3.1.7 Logging . 71
5.3.1.8 Secure Update . 72
5.3.1.9 Secure Configuration and Default . 73
5.3.1.10 Data Minimisation . 73
5.3.1.11 Decommissioning . 74
5.3.2 CE Requirements . 74
5.3.2.1 Isolation . 74
5.3.2.2 Integrity Protection. 74
5.3.2.3 Authentication . 75
5.3.2.4 Authorization . 75
5.3.2.5 Confidentiality . 76
5.3.2.6 Secure Update . 76
5.3.2.7 Decommissioning and secure data deletion . 77
5.3.3 CO Requirements . 78
5.3.3.1 Isolation . 78
5.3.3.2 Integrity Protection. 78
5.3.3.3 Authentication . 78
5.3.3.4 Authorization . 79
5.3.3.5 Confidentiality . 79
5.3.3.6 Secure Update . 80
5.3.3.7 Decommissioning and secure data deletion . 81
5.4 Assurance Security Requirements . 81
5.4.1 Vulnerability Management . 81
5.4.2 Software Bill of Materials (SBOM) . 82
6 Assessment criteria for compliance with technical requirements . 83
6.1 Assessment Methodology . 83
6.1.1 General Assessment Procedure . 83
6.1.2 Technology-neutral Assessment . 84
6.1.2.1 General . 84
6.1.2.2 Equivalence of Hardware-based and Software-based Approaches . 85
6.1.2.3 Technology-neutral Assessment Principles . 86
6.1.3 Assessment of RDPS requirements . 87
6.2 Assessment Report Requirements . 87
6.2.1 Mandatory Report Contents . 87
6.2.2 Traceability Requirements . 89
6.2.3 Evidence Package . 89
6.3 VES . 90
6.3.1 Hypervisor . 90
6.3.1.1 Assessment for VM Isolation . 90
6.3.1.1.1 Assessment Case AC-H-VM-ISO-001 . 90
6.3.1.1.2 Assessment Case AC-H-VM-ISO-002 . 91
6.3.1.1.3 Assessment Case AC-H-VM-ISO-003 . 92
6.3.1.1.4 Assessment Case AC-H-VM-ISO-004 . 94
6.3.1.2 Assessment for Control Plane Isolation . 95
6.3.1.2.1 Assessment Case AC-H-CP-ISO-001 . 95
6.3.1.2.2 Assessment Case AC-H-CP-ISO-002 . 96
6.3.1.2.3 Assessment Case AC-H-CP-ISO-003 . 97
6.3.1.3 Assessment for Network Plane Separation . 99
6.3.1.3.1 Assessment Case AC-H-NP-ISO-001 . 99
6.3.1.3.2 Assessment Case AC-H-NP-ISO-002 . 100
6.3.1.3.3 Assessment Case AC-H-NP-ISO-003 . 101
6.3.1.4 Assessment for Boot Integrity Verification . 102
6.3.1.4.1 Assessment Case AC-H-B-INT-002. 102
6.3.1.5 Assessment for Guest VM Image Integrity Verification . 104
6.3.1.5.1 Assessment Case AC-H-IMG-INT-001 . 104
6.3.1.5.2 Assessment Case AC-H-IMG-INT-002 . 105
6.3.1.5.3 Assessment Case AC-H-IMG-INT-003 . 107
ETSI
6 Draft ETSI EN 304 635 V1.0.1 (2026-06)
6.3.1.6 Assessment for Runtime Integrity Protection . 108
6.3.1.6.1 Assessment Case AC-H-RP-INT-002 . 108
6.3.1.7 Assessment for Remote Attestation . 109
6.3.1.7.1 Assessment Case AC-H-RA-INT-003 . 109
6.3.1.7.2 Assessment Case AC-H-RA-INT-004 . 111
6.3.1.8 Assessment for Administrative Authentication . 113
6.3.1.8.1 Assessment Case AC-H-ADMIN-AUTH-001 . 113
6.3.1.8.2 Assessment Case AC-H-ADMIN-AUTH-002 . 114
6.3.1.8.3 Assessment Case AC-H-ADMIN-AUTH-003 . 115
6.3.1.9 Assessment for Service Authenticatio n . 116
6.3.1.9.1 Assessment Case AC-H-SERV-AUTH-001 . 116
6.3.1.9.2 Assessment Case AC-H-SERV-AUTH-002 . 117
6.3.1.9.3 Assessment Case AC-H-SERV-AUTH-003 . 118
6.3.1.10 Assessment for Administrative Authorization . 119
6.3.1.10.1 Assessment Case AC-H-ADMIN-AUTHZ-001 . 119
6.3.1.10.2 Assessment Case AC-H-ADMIN-AUTHZ-002 . 120
6.3.1.10.3 Assessment Case AC-H-ADMIN-AUTHZ-003 . 121
6.3.1.11 Assessment for Service Authorization . 122
6.3.1.11.1 Assessment Case AC-H-SERV-AUTHZ-001 . 122
6.3.1.11.2 Assessment Case AC-H-SERV-AUTHZ-002 . 123
6.3.1.11.3 Assessment Case AC-H-SERV-AUTHZ-003 . 124
6.3.1.12 Assessment for Confidentiality Protection . 125
6.3.1.12.1 Assessment Case AC-H-CONF-001. 125
6.3.1.12.2 Assessment Case AC-H-CONF-002. 126
6.3.1.12.3 Assessment Case AC-H-CONF-003. 128
6.3.1.12.4 Assessment Case AC-H-CONF-004. 129
6.3.1.13 Assessment for Availability and Resilience . 130
6.3.1.13.1 Assessment Case AC-H-AVAIL-001 . 130
6.3.1.13.2 Assessment Case AC-H-AVAIL-002 . 131
6.3.1.13.3 Assessment Case AC-H-AVAIL-003 . 132
6.3.1.14 Assessment for Logging . 134
6.3.1.14.1 Assessment Case AC-H-LOG-001 . 134
6.3.1.14.2 Assessment Case AC-H-LOG-002 . 134
6.3.1.14.3 Assessment Case AC-H-LOG-003 . 135
6.3.1.15 Assessment for Secure Update . 137
6.3.1.15.1 Assessment Case AC-H-UPD-001 . 137
6.3.1.15.2 Assessment Case AC-H-UPD-002 . 139
6.3.1.15.3 Assessment Case AC-H-UPD-003 . 140
6.3.1.16 Assessment for Secure Configuration and Default . 142
6.3.1.16.1 Assessment Case AC-H-CFG-001 . 142
6.3.1.16.2 Assessment Case AC-H-CFG-002 . 143
6.3.1.16.3 Assessment Case AC-H-CFG-003 . 144
6.3.1.17 Assessment for Data Minimisation . 145
6.3.1.17.1 Assessment Case AC-H-DM-001 . 145
6.3.1.17.2 Assessment Case AC-H-DM-002 . 146
6.3.1.18 Assessment for Decommissioning . 147
6.3.1.18.1 Assessment Case AC-H-DECOM-001 . 147
6.3.2 M&O System . 148
6.3.2.1 Assessment for Authentication. 148
6.3.2.1.1 Assessment Case AC-M&O-AUTH-001 . 148
6.3.2.1.2 Assessment Case AC-M&O-AUTH-002 . 149
6.3.2.1.3 Assessment Case AC-M&O-AUTH-003 . 150
6.3.2.2 Assessment for Authorization . 151
6.3.2.2.1 Assessment Case AC-M&O-AUTHZ-001 . 151
6.3.2.2.2 Assessment Case AC-M&O-AUTHZ-002 . 152
6.3.2.2.3 Assessment Case AC-M&O-AUTHZ-003 . 153
6.3.2.3 Assessment for Secure Configuration . 154
6.3.2.3.1 Assessment Case AC-M&O-CFG-001 . 154
6.3.2.3.2 Assessment Case AC-M&O-CFG-002 . 155
6.3.2.3.3 Assessment Case AC-M&O-CFG-003 . 155
6.3.2.4 Assessment for Communication Security . 156
6.3.2.4.1 Assessment Case AC-M&O-COM-001 . 156
ETSI
7 Draft ETSI EN 304 635 V1.0.1 (2026-06)
6.3.2.4.2 Assessment Case AC-M&O-COM-002 . 157
6.3.2.4.3 Assessment Case AC-M&O-COM-003 . 158
6.3.2.5 Assessment for Integrity Protection . 159
6.3.2.5.1 Assessment Case AC-M&O-INT-001 . 159
6.3.2.5.2 Assessment Case AC-M&O-INT-002 . 160
6.3.2.5.3 Assessment Case AC-M&O-INT-003 . 161
6.3.2.6 Assessment for Logging . 162
6.3.2.6.1 Assessment Case AC-M&O-LOG-001 . 162
6.3.2.6.2 Assessment Case AC-M&O-LOG-002 . 162
6.3.2.6.3 Assessment Case AC-M&O-LOG-003 . 163
6.3.2.7 Assessment for Secure Update . 164
6.3.2.7.1 Assessment Case AC-M&O-UPD-001 . 164
6.3.2.7.2 Assessment Case AC-M&O-UPD-002 . 166
6.3.2.7.3 Assessment Case AC-M&O-UPD-003 . 168
6.3.2.8 Assessment for Decommissioning and Secure Transfer . 169
6.3.2.8.1 Assessment Case AC-M&O-DECOM-001 . 169
6.3.2.8.2 Assessment Case AC-M&O-DECOM-002 . 170
6.4 CES . 171
6.4.1 CRS . 171
6.4.1.1 Assessment for Container Isolation . 171
6.4.1.1.1 Assessment Case AC-CRS-CN-ISO-001 . 171
6.4.1.1.2 Assessment Case AC-CRS-CN-ISO-002 . 172
6.4.1.1.3 Assessment Case AC-CRS-CN-ISO-003 . 174
6.4.1.2 Assessment for Control Plane Isolation . 175
6.4.1.2.1 Assessment Case AC-CRS-CP-ISO-001 . 175
6.4.1.2.2 Assessment Case AC-CRS-CP-ISO-002 . 176
6.4.1.2.3 Assessment Case AC-CRS-CP-ISO-003 . 177
6.4.1.3 Assessment for Network Plane Isolation . 179
6.4.1.3.1 Assessment Case AC-CRS-NP-ISO-001 . 179
6.4.1.3.2 Assessment Case AC-CRS-NP-ISO-002 . 180
6.4.1.3.3 Assessment Case AC-CRS-NP-ISO-003 . 181
6.4.1.4 Assessment for Boot Integrity Verification . 183
6.4.1.4.1 Assessment Case AC-CRS-B-INT-002 . 183
6.4.1.5 Assessment for Container Image Integrity Verification . 185
6.4.1.5.1 Assessment Case AC-CRS-IMG-INT-001 . 185
6.4.1.5.2
...