General Information

Abstract

DEN/CYBER-EUS-0012

Status
Not Published
Current Stage
7 - Dispatch to NSOs / TC
Due Date
31-Oct-2026

Buy Documents

Standard

ETSI EN 304 626 V1.0.1 (2026-08) - Cyber Security (CYBER); CRA; Cybersecurity requirements for operating systems

English language (121 pages)
sale 15% off
Preview
sale 15% off
Preview

Buy Documents

Standard

ETSI EN 304 626 V1.0.1 (2026-08) - Cyber Security (CYBER); CRA; Cybersecurity requirements for operating systems

English language (121 pages)
sale 15% off
Preview
sale 15% off
Preview

Frequently Asked Questions

ETSI EN 304 626 V1.0.1 (2026-08) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Cyber Security (CYBER); CRA; Cybersecurity requirements for operating systems". This standard covers: DEN/CYBER-EUS-0012

DEN/CYBER-EUS-0012

ETSI EN 304 626 V1.0.1 (2026-08) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Draft ETSI EN 304 626 V1.0.1 (2026-08)

HARMONISED EUROPEAN STANDARD
Cyber Security (CYBER);
CRA;
Cybersecurity requirements for operating systems

2 Draft ETSI EN 304 626 V1.0.1 (2026-08)

Reference
DEN/CYBER-EUS-0012
Keywords
CRA, cybersecurity, operating system
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.

© ETSI 2026.
All rights reserved.
ETSI
3 Draft ETSI EN 304 626 V1.0.1 (2026-08)
Contents
Intellectual Property Rights . 9
Foreword. 9
Modal verbs terminology . 10
Introduction . 10
1 Scope . 11
1.1 General . 11
1.2 Products in scope . 11
1.2.1 General . 11
1.2.2 Components of operating systems that are in scope . 12
1.3 Products covered by other CRA harmonised standards . 12
2 References . 13
2.1 Normative references . 13
2.2 Informative references . 14
3 Definition of terms, symbols and abbreviations . 15
3.1 Terms . 15
3.2 Symbols . 17
3.3 Abbreviations . 17
4 Product context . 18
4.1 Intended purpose and reasonably foreseeable use . 18
4.2 Product functions . 18
4.3 Product architecture . 19
4.3.1 Overview . 19
4.3.2 Operating system security functions . 19
4.3.3 Privileges . 19
4.3.4 Access control mechanisms . 19
4.3.5 Resource management. 20
4.3.6 Scheduling . 20
4.4 Operational Environment . 20
4.5 Distribution of security functions . 21
4.5.1 General . 21
4.5.2 Security functions provided by some other part of its context . 21
4.5.3 Security functions provided to other components . 21
4.6 Users . 21
4.7 Use cases . 21
4.7.1 General . 21
4.7.2 Basic use cases . 22
4.7.2.1 UC-REST: Restricted operating system . 22
4.7.2.2 UC-GEN: General-purpose operating system . 22
4.7.3 Conditions . 22
4.7.4 Characterising a product . 23
4.7.5 Risk-factor levels of the basic use cases. 23
4.8 Remote data-processing dependencies. 24
4.8.1 General . 24
4.8.2 Remote data-processing solutions . 24
4.8.3 RDPS interfaces . 24
4.8.4 RDPS-dependent product functions . 25
5 Technical requirements for products . 25
5.1 Notes on the structure of the Requirements . 25
5.1.0 General . 25
5.1.1 Necessity of Requirements . 25
5.1.2 Types of Technical Requirements . 25
5.1.3 Assumptions Regarding Requirements . 26
ETSI
4 Draft ETSI EN 304 626 V1.0.1 (2026-08)
5.1.3.1 Testability . 26
5.1.3.2 Mitigations . 26
5.1.3.3 Residual risk . 26
5.2 Technical security requirements specifications . 26
5.2.1 General . 26
5.2.2 TR-NKEV: No known exploitable vulnerabilities . 26
5.2.2.1 MI-KEVM: Documentation of mitigation of known exploitable vulnerabilities . 26
5.2.2.2 MI-KEVT: Testing for known exploitable vulnerabilities . 27
5.2.3 TR-MINI: Minimise impact on other devices and services. 27
5.2.3.1 MI-RRIS: Document residual risk to other devices and services . 27
5.2.3.2 MI-MNET: Minimise negative impact of network transmission . 27
5.2.4 TR-SDEF: Secure by default configuration . 27
5.2.4.1 MI-ADEF: Authorisation required by default to access security-relevant assets . 27
5.2.4.2 MI-PDDI-1: Document how to control access to debug and management interfaces . 28
5.2.4.3 MI-PDDI-2: Control local software access to debug and management interfaces . 28
5.2.4.4 MI-PDDI-3: Control network access to debug or management interfaces . 28
5.2.5 TR-SCUD: Secure updates . 28
5.2.5.1 MI-KEVD: Documentation for secure update before or during first use . 28
5.2.5.2 MI-KEVA: Secure update before or during first use . 28
5.2.5.3 MI-SCUE: Security updates provided by the operational environment . 29
5.2.5.4 MI-SUVI: Update authenticity and integrity verification . 29
5.2.5.5 MI-SUDP: Anti-rollback protection . 29
5.2.5.6 MI-SUAR: Authorised rollback . 29
5.2.6 TR-AUTH: Authentication and access control . 30
5.2.6.1 MI-RAUT: Authenticate the remote data processing solution and validate its interactions at the
RDPS boundary . 30
5.2.6.2 MI-AUTH-1: Require user authentication on interfaces providing access to the operating system . 30
5.2.6.3 MI-AUTH-2: Require privilege or authorisation on interfaces providing access to the operating
system . 30
5.2.6.4 MI-LCKT: Authentication failure protection . 30
5.2.6.5 MI-CRED: Protect stored critical security parameters and enforce credential strength . 30
5.2.6.6 MI-ACCS: Access control enforcement on operating system resources and functions . 31
5.2.6.7 MI-PRIV: Privilege separation and restriction . 31
5.2.6.8 MI-SESS: Interactive session lifecycle controls . 31
5.2.6.9 MI-ACSD: Access control for stored data . 31
5.2.7 TR-CDST: Confidentiality of data stored on the product . 31
5.2.7.1 MI-ENST: Cryptographic encryption of stored data . 31
5.2.8 TR-CDTX: Confidentiality of data transmitted by the product . 31
5.2.8.1 MI-CDTX: Protect confidentiality of user data transmitted by the product . 31
5.2.8.2 MI-RRDC: Document residual risk to confidentiality of data transmitted . 32
5.2.8.3 MI-ENTX: Cryptographic encryption of transmitted data . 32
5.2.9 TR-CRYP: Encryption . 32
5.2.9.1 MI-CRYP: Conformance to Annex K . 32
5.2.10 TR-IDST: Integrity of data stored on the product . 32
5.2.10.1 MI-DCST: Detect corruption of stored data . 32
5.2.10.2 MI-INTS: Cryptographic integrity protection of stored data . 32
5.2.11 TR-IDTX: Integrity of data transmitted by the product . 33
5.2.11.1 MI-INTT: Cryptographic integrity protection of transmitted data . 33
5.2.12 TR-DMIN: Data Minimisation . 33
5.2.12.1 MI-DJST: Document and justify processed data . 33
5.2.13 TR-AVAI: Availability . 33
5.2.13.1 MI-AVNT: Availability of network functions . 33
5.2.13.2 MI-CSFR: Detection and recovery from critical service failures . 33
5.2.13.3 MI-RLIM: Resource usage limits and exhaustion fallback . 34
5.2.13.4 MI-PRIO: Workload prioritisation . 34
5.2.13.5 MI-RRDS: Document residual risk of denial of service . 34
5.2.13.6 MI-RTDL: Real-time deadline preservation . 34
5.2.13.7 MI-RTRY: Retry and degraded behaviour on unavailability of the remote data processing
solution . 34
5.2.14 TR-ISOL: Isolation . 35
5.2.14.1 MI-ISO-1: Access control across security boundaries . 35
5.2.14.2 MI-ISO-2: Process isolation . 35
ETSI
5 Draft ETSI EN 304 626 V1.0.1 (2026-08)
5.2.14.3 MI-ISO-3: Isolation between the processes of different users . 35
5.2.14.4 MI-ISO-4: Isolation between the data of different users . 35
5.2.14.5 MI-ISO-5: Privilege model . 35
5.2.14.6 MI-ISO-6: Side-channel isolation . 36
5.2.14.7 MI-ISO-7: Binary hardening . 36
5.2.15 TR-LOGG: Logging and monitoring . 36
5.2.15.1 MI-LOGG: Logging . 36
5.2.16 TR-SCDL: Secure deletion . 37
5.2.16.1 MI-SDEL: Secure deletion . 37
5.2.16.2 MI-RRSD: Document residual risk to secure deletion . 37
5.2.17 TR-SDTR: Secure data read and transfer . 37
5.2.17.1 MI-SDRF: Secure data read from product . 37
5.2.17.2 MI-SDTR: Document secure data transfer to another product or system . 37
5.3 Security profiles . 37
5.3.1 General . 37
5.3.2 SP-REST baseline mitigations . 38
5.3.3 SP-GEN baseline mitigations . 38
5.3.4 Conditioned mitigations . 39
5.3.4.0 General . 39
5.3.4.1 C-NET: Public network access . 39
5.3.4.2 C-NETR: Restricted network access . 40
5.3.4.3 C-MOD: User-modifiable software, firmware, or hardware . 40
5.3.4.4 C-APPS: Third-party application installation . 40
5.3.4.5 C-LOSS: Loss or theft of a portable device . 40
5.3.4.6 C-MULTI: Multiple user accounts . 40
5.3.4.7 C-UNTR: Untrusted concurrent users . 41
5.3.4.8 C-DATA: Sensitive or personal data . 41
5.3.4.9 C-FUNC: Sensitive functions . 41
5.3.4.10 C-RDPS: Remote data-processing dependency . 42
5.3.4.11 C-PHYS: Physical exposure to untrusted persons . 42
5.3.4.12 C-SELFADM: Self-administration . 42
6 Assessment criteria for compliance with technical requirements . 42
6.1 Introduction to the assessment and compliance criteria . 42
6.2 TR-NKEV: No known exploitable vulnerabilities . 44
6.2.1 [AC-KEVM] Assessment criteria: Documentation of mitigation of known exploitable vulnerabilities . 44
6.2.2 [AC-KEVT] Assessment criteria: Testing for known exploitable vulnerabilities . 45
6.3 TR-MINI: Minimise impact on other devices and services . 45
6.3.1 [AC-RRIS] Assessment criteria: Document residual risk to other devices and services . 45
6.3.2 [AC-MNET] Assessment criteria: Minimise negative impact of network transmission . 46
6.4 TR-SDEF: Secure by default configuration . 47
6.4.1 [AC-ADEF] Assessment criteria: Authorisation required by default to access security-relevant assets. 47
6.4.2 [AC-PDDI-1] Assessment criteria: Document how to control access to debug and management
interfaces . 48
6.4.3 [AC-PDDI-2] Assessment criteria: Control local software access to debug and management
interfaces . 48
6.4.4 [AC-PDDI-3] Assessment criteria: Control network access to debug or management interfaces. 49
6.5 TR-SCUD: Secure updates . 50
6.5.1 [AC-KEVD] Assessment criteria: Documentation for secure update before or during first use . 50
6.5.2 [AC-KEVA] Assessment criteria: Secure update before or during first use . 50
6.5.3 [AC-SCUE] Assessment criteria: Security updates provided by the operational environment . 51
6.5.4 [AC-SUVI] Assessment criteria: Update authenticity and integrity verification . 52
6.5.5 [AC-SUDP] Assessment criteria: Anti-rollback protection . 53
6.5.6 [AC-SUAR] Assessment criteria: Authorised rollback . 53
6.6 TR-AUTH: Authentication and access control . 54
6.6.1 [AC-RAUT] Assessment criteria: Authenticate the remote data processing solution and validate its
interactions at the RDPS boundary . 54
6.6.2 [AC-AUTH-1] Assessment criteria: Require user authentication on interfaces providing access to
the operating system . 55
6.6.3 [AC-AUTH-2] Assessment criteria: Require privilege or authorisation on interfaces providing
access to the operating system. 56
6.6.4 [AC-LCKT] Assessment criteria: Authentication failure protection . 57
ETSI
6 Draft ETSI EN 304 626 V1.0.1 (2026-08)
6.6.5 [AC-CRED] Assessment criteria: Protect stored critical security parameters and enforce credential
strength . 57
6.6.6 [AC-ACCS] Assessment criteria: Access control enforcement on operating system resources and
functions . 58
6.6.7 [AC-PRIV] Assessment criteria: Privilege separation and restriction . 59
6.6.8 [AC-SESS] Assessment criteria: Interactive session lifecycle controls . 60
6.6.9 [AC-ACSD] Assessment criteria: Access control for stored data . 61
6.7 TR-CDST: Confidentiality of data stored on the product . 62
6.7.1 [AC-ENST] Assessment criteria: Cryptographic encryption of stored data . 62
6.8 TR-CDTX: Confidentiality of data transmitted by the product . 63
6.8.1 [AC-CDTX] Assessment criteria: Protect confidentiality of user data transmitted by the product . 63
6.8.2 [AC-RRDC] Assessment criteria: Document residual risk to confidentiality of data transmitted . 64
6.8.3 [AC-ENTX] Assessment criteria: Cryptographic encryption of transmitted data . 64
6.9 TR-CRYP: Encryption . 65
6.9.1 [AC-CRYP] Assessment criteria: Conformance to Annex K . 65
6.10 TR-IDST: Integrity of data stored on the product . 66
6.10.1 [AC-DCST] Assessment criteria: Detect corruption of stored data . 66
6.10.2 [AC-INTS] Assessment criteria: Cryptographic integrity protection of stored data . 66
6.11 TR-IDTX: Integrity of data transmitted by the product . 67
6.11.1 [AC-INTT] Assessment criteria: Cryptographic integrity protection of transmitted data . 67
6.12 TR-DMIN: Data Minimisation . 68
6.12.1 [AC-DJST] Assessment criteria: Document and justify processed data . 68
6.13 TR-AVAI: Availability . 69
6.13.1 [AC-AVNT] Assessment criteria: Availability of network functions . 69
6.13.2 [AC-CSFR] Assessment criteria: Detection and recovery from critical service failures . 70
6.13.3 [AC-RLIM] Assessment criteria: Resource usage limits and exhaustion fallback . 70
6.13.4 [AC-PRIO] Assessment criteria: Workload prioritisation . 71
6.13.5 [AC-RRDS] Assessment criteria: Document residual risk of denial of service . 72
6.13.6 [AC-RTDL] Assessment criteria: Real-time deadline preservation . 73
6.13.7 [AC-RTRY] Assessment criteria: Retry and degraded behaviour on unavailability of the remote data
processing solution . 73
6.14 TR-ISOL: Isolation . 74
6.14.1 [AC-ISO-1] Assessment criteria: Access control across security boundaries . 74
6.14.2 [AC-ISO-2] Assessment criteria: Process isolation. 75
6.14.3 [AC-ISO-3] Assessment criteria: Isolation between the processes of different users . 76
6.14.4 [AC-ISO-4] Assessment criteria: Isolation between the data of different users . 77
6.14.5 [AC-ISO-5] Assessment criteria: Privilege model . 77
6.14.6 [AC-ISO-6] Assessment criteria: Side-channel isolation . 78
6.14.7 [AC-ISO-7] Assessment criteria: Binary hardening . 80
6.15 TR-LOGG: Logging and monitoring . 81
6.15.1 [AC-LOGG] Assessment criteria: Logging . 81
6.16 TR-SCDL: Secure deletion . 82
6.16.1 [AC-SDEL] Assessment criteria: Secure deletion . 82
6.16.2 [AC-RRSD] Assessment criteria: Document residual risk to secure deletion . 83
6.17 TR-SDTR: Secure data read and transfer . 83
6.17.1 [AC-SDRF] Assessment criteria: Secure data read from product . 83
6.17.2 [AC-SDTR] Assessment criteria: Document secure data transfer to another product or system . 84
Annex A (informative): Relationship between the present document and the essential
cybersecurity requirements of Regulation (EU) 2024/2847 . 86
Annex B (informative): Security analysis. 88
B.0 General . 88
B.1 Assets . 88
B.1.1 Data assets . 88
B.1.2 Software assets . 88
B.1.3 Hardware-interfacing assets . 88
B.1.4 Network assets . 89
B.1.5 Identity and access assets . 89
B.1.6 Product functions . 89
B.1.7 Impact of asset compromise. 89
ETSI
7 Draft ETSI EN 304 626 V1.0.1 (2026-08)
B.2 Risk factors . 90
B.2.1 General comments regarding risk factors . 90
B.2.2 RF-NUSR: Number of User Accounts . 90
B.2.3 RF-CUSR: User Account Concurrency . 90
B.2.4 RF-PPII: Potential for Collection of Personally Identifiable Information . 91
B.2.5 RF-SNDS: Sensitivity of Data Stored . 91
B.2.6 RF-SNDT: Sensitivity of Data Transmitted . 91
B.2.7 RF-SENF: Sensitivity of Functions . 91
B.2.8 RF-PHYS: Physical Access by Threat Actors to the Device . 91
B.2.9 RF-UEIN: Processing of Untrusted External Inputs . 91
B.2.10 RF-LOSS: Probability of Loss of the Device . 92
B.2.11 RF-HWMD: Hardware Modifiability by End Users . 92
B.2.12 RF-SWMD: Software Modifiability by End Users . 92
B.2.13 RF-DVCS: Untrusted Peripheral Devices . 92
B.2.14 RF-TNET: Access to a Public Network . 92
B.2.15 RF-FNET: Accessed From Untrusted Networks Including a Public Network . 93
B.2.16 RF-CONF: Configurability . 93
B.2.17 RF-ADMN: Administration . 93
B.2.18 RF-SUPP: Support and Foreseeable Updates . 93
B.2.19 RF-RDPS: Remote data processing dependency . 93
B.3 Assumptions . 94
B.3.0 General . 94
B.3.1 AS-PA: Proper administrator . 94
B.4 Security analysis . 94
B.4.1 Methodology . 94
B.4.2 TH-UEVU: Unknown exploitable vulnerabilities . 94
B.4.3 TH-KEVU: Known exploitable vulnerabilities . 95
B.4.4 TH-SUPC: Compromise of the secure update mechanism . 95
B.4.5 TH-UAPP: Unauthorised access to product assets via unprotected physical interfaces in default
configuration . 96
B.4.6 TH-UAPS: Unauthorised access to product assets via unprotected local software access in default
configuration . 97
B.4.7 TH-UAPN: Unauthorised access to product assets via unprotected network interfaces in default
configuration . 97
B.4.8 TH-UADT: Unauthorised access to confidential data transmitted . 98
B.4.9 TH-UADX: Unauthorised access to data during transfer to another product . 98
B.4.10 TH-PDOS: Denial of service attack on product functions via user or network access . 99
B.4.11 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities or unauthorised
use of product functions . 100
B.4.12 TH-MQSE: Masquerading authorised server . 100
B.4.13 TH-XUSR: Unauthorised access, resource exhaustion, or privilege escalation between concurrent users . 101
B.4.14 TH-LEAK: Data leak through side channels . 101
B.4.15 TH-RDPS: Compromise of the remote data processing solution boundary. 102
B.4.16 TH-SUPP: Supply chain compromise. 102
B.4.17 TH-HARD: Compromise via hardware-level or platform trust components . 103
B.5 Mapping of use cases to risk factors . 103
B.5.1 General . 103
B.5.2 Baseline risk-factor levels of the basic use cases . 103
B.5.3 Condition increments .
...