Product Standards by Category
This tracker keeps every Annex III and Annex IV product category visible. It links a public ETSI CYBER EUSR draft when one is listed in the Open folder checked on 23 June 2026. Missing public draft links are shown instead of hidden.
Public source
The page uses Annex III and Annex IV as the category list, Regulation 2025/2392 for the technical meaning of the category names, M/606 for the requested product-specific standards, and the ETSI CYBER EUSR Open folder for public draft files.
Complete list
Categories stay visible even when no public draft is listed.
Public drafts
Links point to public files in the ETSI Open folder.
Legal effect
Presumption of conformity still needs an Official Journal reference.
Annex III Class I
Class I contains the longer Annex III list. Public draft links are included only where the Open folder lists a matching file.
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readersNo public draft listed.
- Standalone and embedded browsersEN 304 617 public draft
- Password managersEN 304 618 public draft
- Software that searches for, removes, or quarantines malicious softwareEN 304 619 public draft
- Products with digital elements with the function of virtual private network (VPN)EN 304 620 public draft
- Network management systemsEN 304 621 public draft
- Security information and event management (SIEM) systemsNo public draft listed.
- Boot managersEN 304 623 public draft
- Public key infrastructure and digital certificate issuance softwareNo public draft listed.
- Physical and virtual network interfacesEN 304 625 public draft
- Operating systemsEN 304 626 public draft
- Routers, modems intended for the connection to the internet, and switchesEN 304 627 public draft
- Microprocessors with security-related functionalitiesNo public draft listed.
- Microcontrollers with security-related functionalitiesNo public draft listed.
- Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalitiesNo public draft listed.
- Smart home general purpose virtual assistantsEN 304 631 public draft
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systemsEN 304 632 public draft
- Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking featuresEN 304 633 public draft
- Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 of the European Parliament and of the Council do not apply, or personal wearable products that are intended for the use by and for childrenEN 304 634 public draft
Annex III Class II
Class II contains four Annex III categories. Two currently have public ETSI Open draft links in this tracker.
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environmentsEN 304 635 public draft
- Firewalls, intrusion detection and prevention systemsEN 304 636 public draft
- Tamper-resistant microprocessorsNo public draft listed.
- Tamper-resistant microcontrollersNo public draft listed.
Annex IV critical products
Annex IV critical products are also part of M/606's product-specific standardisation request. No ETSI Open draft link is listed here for these categories.
- Hardware Devices with Security BoxesNo public draft listed.
- Smart meter gateways within smart metering systems as defined in Article 2(23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessingNo public draft listed.
- Smartcards or similar devices, including secure elementsNo public draft listed.
Using public drafts
Public drafts can help early gap analysis, design discussion, and product planning. They should not be described as cited harmonised standards unless their references are published in the Official Journal.
For the legal effect of harmonised standards, use Harmonised Standards and Presumption of Conformity. For the technical meaning of product categories, use Regulation 2025/2392 Technical Descriptions.