CEN/CENELEC

Available (98)

Showing 1 - 12 per page



CEN/CLC/JTC 13/WG 9 - Horizontal cybersecurity for products with digital elements

CEN/CLC/JTC 13/WG 9  -  Horizontal cybersecurity for products with digital elements: WG9 is responsible for the development of the horizontal standards in response to the European Cyber Resilience Act Standardisation Request M/606, items 1 - 15.WG 9 supports coordination and coherence between the vertical deliverables of the CRA and the horizontal deliverables of WG9

Llogari Casas Cambra

Country
Spain
Fellow's country
Open Call
Organisation type
Organization
Kaleidoscop Reality SL
Portrait Picture
Llogari
Proposal Title (2nd Open Call)
Standardisation Contribution for Accessible Mixed Reality Navigation Interfaces in Europe
Standards Development Organisation
Topic
Virtual Worlds, Metaverse
StandICT.eu Year
2029
Year

Alehandro Blumentals

Country
Latvia
Fellow's country
Open Call Topics
Open Call
Organisation type
Organization
Idea Jet Lab SIA
Portrait Picture
Photo
Proposal Title (2nd Open Call)
AI Competence Measurement Standard for EU AI Act Article 4 Compliance — cont. to CEN-CENELEC JTC 21
Standards Development Organisation
Topic
Artificial Intelligence
StandICT.eu Year
2029
Year
Topic (2nd Open Call)

Sarah Oury

Country
France
Fellow's country
Open Call Topics
Open Call
Organisation type
Organization
Sopra Steria
Portrait Picture
Sarah
Proposal Title (2nd Open Call)
From Drafting to Strategy: Leading a European Sustainable AI Standard
Standards Development Organisation
Topic
Artificial Intelligence
StandICT.eu Year
2029
Year
Topic (2nd Open Call)

prEN 18287 AI Requirements and guidance for the environmental impact evaluation of artificial intelligence systems and services

This document describes the principles and framework for environmental impact measurement of artificial intelligence systems and services and provides guidelines for impact reduction throughout its lifecycle. It includes: - A framework for defining the environmental impact of artificial intelligence - A harmonized calculation method for assessing the environmental impact of artificial intelligence systems and services - Reporting guidelines - Best practices for reducing the environmental impact of AI systems and services throughout their lifecycle. This document is aimed at organizations developing AI systems and services and organizations using AI systems and services, but also at all actors in the value chain who are required to use AI systems and services.

prEN 18281 Artificial Intelligence - Evaluation methods for accurate computer vision systems

This document specifies the evaluation of computer vision systems, in the sense of measuring the quality of a system’s results to assess its functional suitability. It provides a definition of evaluation methods for those systems, together with guidance on how to select, implement and interpret those evaluation methods. This document covers quantitative metrics as well as other evaluation methods. It includes requirements on the implementation of the described metrics, and further requirements on the technical resources involved in the evaluation process.

CRA SR M/606 PT3 Cybersecurity requirements for products with digital elements Part 1-3: Vulnerability handling

prEN 40000-1-3: Cybersecurity requirements for products with digital elements - Part 1-3: Vulnerability handling


These standards shall provide specifications applicable to vulnerability handling processes, covering all relevant product categories, to be put in place by manufacturers of the products with digital elements. Those processes shall at least allow to: (a) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machinereadable format covering at the very least the top-level dependencies of the product; (b) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; (c) apply effective and regular tests and reviews of the security of the product with digital elements; (d) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch; (e) put in place and enforce a policy on coordinated vulnerability disclosure; (f) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a standardised contact address for the reporting of the vulnerabilities discovered in the product with digital elements; (g) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner, and, where applicable for security updates, in an automatic manner; (h) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.

CRA SR M/606 PT2 Cybersecurity requirements for products with digital elements - Generic security requirements

This document provides generic technical cybersecurity requirements for products with digital elements including their remote data processing solutions to fulfil the Essential Requirements of Annex I, Part I, (2)(a) through (2)(m) of the CRA. Where appropriate, multiple alternative requirements are provided that can be chosen from on a risk basis. The standard will include generic assessment criteria to support compliance of products with digital elements with the essential requirements of the CRA as listed above. Guidance will be provided to support the user of the standard in selecting the appropriate requirements to address the identified risks demonstrating the relation between cybersecurity threats and requirements. The EN 18031 series will be used as an input.

Matthieu Grall

Country
France
Fellow's country
Open Call
Organisation type
Organization
Independent expert
Portrait Picture
Matthieu
Proposal Title
EU Aligned Contributions to SC27 and SC42 on Security, Privacy and Trustworthy AI
Standards Development Organisation
Topic
Artificial Intelligence
StandICT.eu Year
2029
Year

Artificial intelligence - Quality management system for EU AI Act regulatory purposes (EN 18286:2026)

This document specifies the requirements and provides guidance for the definition, implementation and maintenance of a quality management system for organizations that provide AI systems. This document is intended to support the organization in meeting applicable regulatory requirements. It is primarily intended for organizations placing on the market or putting into service high-risk AI systems and is not specific to any particular sector.

AI Conformity assessment framework (prEN 18285)

Artificial Intelligence conformity assessment serves the purpose of providing notice and assurance to stakeholders about conformity against stated requirements. It maps the conformity assessment activities to the different phases of the AI system life cycle. This document provides procedures and processes for conformity assessment activities related to AI systems. The intended audience for this document is primarily conformity assessment scheme developers, owners and operators that evaluate, test, assess and certify AI systems. It is also useful for organizations and people that are not scheme owners or operators, such as AI system stakeholders including AI system developers, providers, customers, partners and regulatory authorities.