If you have difficulty in submitting comments on draft standards you can use a commenting template and email it to admin.start@bsigroup.com. The commenting template can be found here.
This document specifies cybersecurity requirements and associated assessment requirements for identity management systems that qualify as products within the meaning of Regulation (EU) 2024/2847. Such products are classified as important products (class 1) according to the implementing regulation Commission Implementing Regulation (EU) 2025/2392.
Identity management systems are products that provide mechanisms for authentication or authorisation and that may also provide mechanisms for the lifecycle management of identity credentials of natural persons, legal persons, devices or systems, such as identity registration, provisioning, maintenance, deregistration.
These systems include access management systems that control access of natural persons, legal persons, devices or systems to digital resources or physical locations.
Privileged access management software is an access management system that controls and monitors access rights to IT or OT systems and sensitive information within an organisation, including systems enforcing differentiated access control policies for privileged users.
This category includes but is not limited to authentication and access control readers, biometric readers, single sign-on software, federated identity management software, one-time password software, hardware authentication devices such as transaction authentication number (TAN) generators, authentication software and multi-factor authentication software.
This document covers:
Products within the scope of this document:
The following non-exhaustive categories of products are within the scope of this document where their primary or supporting function relates to identity management, authentication, authorisation, or logical and physical access control to natural persons, legal persons, devices or systems.
Logical and Physical Identity lifecycle management
Products for:
Logical and Physical Authentication
Products for:
Logical and Physical Biometric identity management
Products for:
Logical and Physical Access management
Products for:
Logical and Physical Privileged access management
Product not in the scope of this document:
All other important and critical products that are covered by harmonised standards as per the standardisation request Mandate M/606 2025-02-03 such as:
Required form fields are indicated by an asterisk (*) character.
You are now following this standard. Weekly digest emails will be sent to update you on the following activities:
You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.
You have successfully unsubscribed from weekly updates for this standard.
Comment by: