The new ETSI EN 304 636 V1.0.0 standard focuses on cybersecurity requirements for firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS). The standard covers vulnerability handling activities, technical security requirements and corresponding assessment criteria.
The standard applies to products with digital elements designed to protect networks and systems against unauthorised access and other cyber threats. The requirements support the implementation of the EU Cyber Resilience Act (CRA) and aim to provide a common framework for cybersecurity throughout the product lifecycle.
You can find the document here: ETSI EN 304 636 V1.0.0
All feedback and comments are welcome by 4 October 2026.


