EN 17640:2022+A1:2026

Fixed-time cybersecurity evaluation methodology for ICT products EN 17640:2022+A1:2026

General information

60.60   Standard published   Jul 1, 2026

CEN/CENELEC

CEN/CLC/JTC 13 Cybersecurity and Data Protection

European Norm

35.030   IT Security

Scope

This document describes a cybersecurity evaluation methodology that can be implemented using pre-defined time and workload resources, for ICT products. It is intended to be applicable for all three assurance levels defined in the CSA (i.e. basic, substantial and high).
The methodology comprises different evaluation blocks including assessment activities that comply with the evaluation requirements of the CSA for the mentioned three assurance levels. Where appropriate, it can be applied both to third-party evaluation and self-assessment.

Life cycle

NOW

PUBLISHED
EN 17640:2022+A1:2026
60.60 Standard published
Jul 1, 2026




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.