ETSI EN 304 619 V1.0.0 specifies cybersecurity requirements for software that detects or searches for malicious software or code. It also covers software that removes or quarantines such code. The standard covers products such as antivirus and antimalware software designed to protect devices against cybersecurity threats.
The requirements address areas including secure-by-default configuration, security updates, and authentication and access control. They also cover confidentiality and integrity protection, monitoring, attack surface minimisation and exploit mitigation. Assessment criteria are also included to verify compliance with the technical requirements.
The standard has been developed under the framework of the EU Cyber Resilience Act (CRA). It aims to provide a common technical cybersecurity framework for this category of products.
You can find the document here: ETSI EN 304 619 V1.0.0
All feedback and comments are welcome by 11 October 2026.


