Standards and guidance

ETSI EN 304 223: AI Cybersecurity Evidence

ETSI EN 304 223 sets baseline cybersecurity requirements for AI systems and models across their lifecycle.

How to use this reference

Select the applicable edition and requirements for the system being reviewed. Evidence preparation is not an ETSI endorsement or an assertion of conformity.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

ETSI explanation of EN 304 223

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Lifecycle evidence discussion

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Which system and model lifecycle stages are included in the review?
  • How are security changes, dependencies and test evidence linked to the system version?
  • Who accepts unresolved weaknesses before the next deployment stage?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.