ETSI has published a draft of EN 304 623 V0.1.3 (2026-06), which specifies cybersecurity requirements and assessment criteria for boot managers. The standard is being developed in the context of the EU Cyber Resilience Act (CRA) and focuses on security requirements for boot managers used in products with digital elements.
The document covers areas such as secure boot, protection of the chain of trust, and security-related functions during the boot process. Version 0.1.3 is still a draft and remains under development within ETSI.
You can find the document here: EN 304 623 V0.1.3 (2026-06)
All feedback and comments are welcome by 14 September 2026.


