The new ETSI EN 304 627 V1.0.1 standard focuses on cybersecurity requirements for routers, modems intended for internet connection, and switches. The standard covers both vulnerability handling activities and technical security requirements, along with corresponding assessment criteria.
The requirements include secure authentication and access control, protection of data and system integrity, vulnerability handling, monitoring and logging, as well as measures to reduce a product’s attack surface and improve its availability and resilience.
The standard has been developed as a candidate for harmonisation in support of the EU Cyber Resilience Act (CRA) and aims to provide manufacturers with a common framework for meeting cybersecurity requirements for this type of network equipment.
You can find the document here: ETSI EN 304 627 V1.0.1
All feedback and comments on the document are welcome by 29 September 2026.


