
Its purpose is to support compliance with the requirements of the European Cyber Resilience Act (CRA).
The standard focuses on risks associated with the use of virtualisation technologies and containers, such as Docker and Kubernetes, with the aim of improving the cybersecurity of digital products and their operating environments.
Key aspects of EN 304 635:
- Objective: To define security requirements for systems that run virtual machines and containers.
- CRA compliance: The standard directly supports compliance with obligations arising from the Cyber Resilience Act.
- Scope: Virtualisation technologies, hypervisors, container runtime environments and orchestration environments.
- Status: A draft standard currently being developed within ETSI, the European Telecommunications Standards Institute.
If you work with hypervisors, container platforms, orchestration, cloud infrastructure or cybersecurity resilience assessments, your expert comments can make an important contribution to the clear preparation and future implementation of this standard.
The NBÚ is not responsible for this activity. Comments and proposals should be sent directly to ETSI or cybersupport@etsi.org. See also the standards preparation page at https://docbox.etsi.org/CYBER/EUSR/Open.
Draft standard: EN 304 635 v1.0 mature draft (PDF, 2 MB)