WG 02 - CLC/TC 47X/WG 02
The group activities will focus on defining harmonized standards enabling third-party assessment of Cyber Resilience Act (CRA) compliance for MCUs and MPUs with tamper resistance for which scope has been defined as from hardware to generic software (e.g. OS, libraries) with a resistance to a JIL basic/enhanced basic potential of attack. Those activities will be built on existing standards such as SESIP (Security Evaluation for IoT Products). As a first step, this group will identify all relevant protection profiles for such MCUs and MPUs with tamper-resistance in the context of the CRA. A critical part of the work will be to identify and address gaps in the CRA Cybersecurity Essential Requirements (CRA, Annex I of the Draft CRA proposal Text). Manufacturers' reporting obligations in the event of security incidents (CRA, Article 11 of the draft CRA proposal) should also be covered as part of the work.
CLC/TC 47X/WG 02
The group activities will focus on defining harmonized standards enabling third-party assessment of Cyber Resilience Act (CRA) compliance for MCUs and MPUs with tamper resistance for which scope has been defined as from hardware to generic software (e.g. OS, libraries) with a resistance to a JIL basic/enhanced basic potential of attack. Those activities will be built on existing standards such as SESIP (Security Evaluation for IoT Products). As a first step, this group will identify all relevant protection profiles for such MCUs and MPUs with tamper-resistance in the context of the CRA. A critical part of the work will be to identify and address gaps in the CRA Cybersecurity Essential Requirements (CRA, Annex I of the Draft CRA proposal Text). Manufacturers' reporting obligations in the event of security incidents (CRA, Article 11 of the draft CRA proposal) should also be covered as part of the work.
General Information
Frequently Asked Questions
WG 02 is a Technical Committee within CLC. It is named "CLC/TC 47X/WG 02" and is responsible for: The group activities will focus on defining harmonized standards enabling third-party assessment of Cyber Resilience Act (CRA) compliance for MCUs and MPUs with tamper resistance for which scope has been defined as from hardware to generic software (e.g. OS, libraries) with a resistance to a JIL basic/enhanced basic potential of attack. Those activities will be built on existing standards such as SESIP (Security Evaluation for IoT Products). As a first step, this group will identify all relevant protection profiles for such MCUs and MPUs with tamper-resistance in the context of the CRA. A critical part of the work will be to identify and address gaps in the CRA Cybersecurity Essential Requirements (CRA, Annex I of the Draft CRA proposal Text). Manufacturers' reporting obligations in the event of security incidents (CRA, Article 11 of the draft CRA proposal) should also be covered as part of the work. This committee has published 1 standards.
WG 02 develops CLC standards in the area of Information technology. The scope of work includes: The group activities will focus on defining harmonized standards enabling third-party assessment of Cyber Resilience Act (CRA) compliance for MCUs and MPUs with tamper resistance for which scope has been defined as from hardware to generic software (e.g. OS, libraries) with a resistance to a JIL basic/enhanced basic potential of attack. Those activities will be built on existing standards such as SESIP (Security Evaluation for IoT Products). As a first step, this group will identify all relevant protection profiles for such MCUs and MPUs with tamper-resistance in the context of the CRA. A critical part of the work will be to identify and address gaps in the CRA Cybersecurity Essential Requirements (CRA, Annex I of the Draft CRA proposal Text). Manufacturers' reporting obligations in the event of security incidents (CRA, Article 11 of the draft CRA proposal) should also be covered as part of the work. Currently, there are 1 published standards from this technical committee.
CLC is a standardization organization that develops and publishes standards to support industry, commerce, and regulatory requirements.
A Technical Committee (TC) in CLC is a group of experts responsible for developing international standards in a specific technical area. TCs are composed of national member body delegates and work through consensus to create standards that meet global industry needs. Each TC may have subcommittees (SCs) and working groups (WGs) for specialized topics.
This document specifies the technical requirements for general-purposes tamper-resistant microprocessors and microcontrollers intended for integration into products that rely on them as a foundational security component. The microprocessors and microcontrollers in scope are designed for deployment in environments where the security features of the product integrating the platform are of importance, and where the threat landscape includes attackers with low but non-negligeable attack potential, corresponding to AVA_VAN.2 to AVA_VAN.3 as defined in [13].
- Draft102 pagesEnglish languagee-Library read for1 day