ETSI has published EN 304 618 V0.2.2 which specifies cybersecurity requirements and assessment criteria for password managers.
The standard has been developed in the context of the EU Cyber Resilience Act (CRA) and focuses on security requirements for products that store and manage authentication credentials.
You can find the document here: EN 304 618 V0.2.2
All feedback and comments are welcome by 20 September 2026.


