If you sell routers, modems, switches or network management systems into the EU, you have probably noticed something that looks like a mistake. There are two draft harmonised standards covering what appears to be the same box. ETSI is drafting one. CEN-CENELEC is drafting another. A reasonable person reads that and assumes duplication, a turf war, or a numbering error.
The real explanation is simpler. The two standards exist on purpose, and the line between them follows the deployment context of the product rather than the product itself.
This came up directly in a recent CRA standardisation Q&A. Attendees asked why network management systems have one document from CEN-CENELEC and another from ETSI, and why routers, modems and switches sit under both EN 304 627 and prEN 50770-5. The answer from the panel was short. The scopes correspond to different product contexts. The ETSI standard covers the IT context. The CENELEC standard covers the OT, or operational technology, context. You apply one or the other, chosen to match where your product is meant to operate, and you never combine them.
That answer is correct, and it is worth unpacking because the consequences for a manufacturer are real.
What the split actually is
The CRA classifies routers, modems intended for connection to the internet, and switches as Important Class I products under Annex III, point 12. That classification triggers the need to demonstrate conformity against the Annex I essential requirements, and the cleanest way to do that is by applying a harmonised standard once it is cited in the Official Journal.
Two European Standards Organisations are building the technical specifications for that product family.
ETSI Technical Committee CYBER is drafting EN 304 627. It defines cybersecurity requirements for routers, modems and switches in consumer, enterprise and service provider settings, covering both physical and virtual devices. Crucially, the final draft is explicit that products used in the operational technology domain are excluded from its scope, and it points the reader to prEN 50770-5 for those.
CENELEC, through CLC/TC 65X WG 3, is drafting the EN 50770 series under the title Security for Operational Technologies. This series is built on the IEC 62443 industrial security standard. prEN 50770-5 is Part 5, the security profile for routers, modems intended for connection to the internet, and switches in the OT context. There are sibling parts for firewalls and intrusion detection (Part 1), network management systems (Part 2), network interfaces (Part 3), VPNs (Part 4), and SIEM systems (Part 6).
So the network management system question and the router question have the same answer. ETSI EN 304 627 and CENELEC EN 50770-2 cover network management systems. ETSI EN 304 627 and CENELEC prEN 50770-5 cover routers, modems and switches. In each pair, one document is for IT and one is for OT.
One correction worth flagging. The standard is prEN 50770-5, not 50777-5. The
number that circulated in the Q&A chat was a typo. If you go looking for 50777-5 you will not find
it.
Why the EU built it this way
A router on an office network and a router inside a factory automation cell are physically similar and functionally different in the ways that matter for security. The IT box optimises around confidentiality and frequent patching. The OT box sits in an environment where availability and safety dominate, where downtime can stop a production line, and where you often cannot simply push an update mid-shift. The threat model, the acceptable mitigations, and the test criteria diverge.
Forcing both contexts through a single standard would mean either watering down the IT requirements to fit OT constraints or imposing IT assumptions on OT environments where they do not hold. The CRA chose to split by context and let each ESO write to the realities of its domain. ETSI owns telecommunications and IT. CENELEC owns the electrotechnical and industrial side, which is why the OT profiles are built on IEC 62443, the established industrial control system security framework.
This is also why the panel was firm that the two standards shall not be used together. They are mutually exclusive routes selected by context, each one a complete answer on its own. Applying both to a single product would be incoherent, because each presumes a different operating environment and a different set of proportionate controls.
What a manufacturer should actually do
The practical question is which context your product is placed on the market for, not which standard reads better on paper.
Start by deciding, honestly, where the product is intended to operate. The intended purpose you declare drives the choice. A consumer or enterprise switch goes down the ETSI EN 304 627 route. An industrial switch sold into automation environments goes down the CENELEC EN 50770-5 route. If you genuinely sell variants into both worlds, you have two products for compliance purposes even if the hardware is shared, and each variant follows its matching standard.
The harder cases are the products that straddle. A ruggedised switch marketed at both factory floors and ordinary IT closets forces a real decision rather than a default. Resolve it on intended purpose and the dominant deployment context, document the reasoning, and be ready to defend it. Covering both standards makes you look worse, not safer, because it signals you have not pinned down your own product context.
Watch the status, because neither route is finished. EN 304 627 reached final draft in 2026 and is the furthest along of the pair. The EN 50770 OT profiles are earlier in the process and were still pre-enquiry as of mid 2026. A draft is useful for anticipating requirements, but the legal presumption of conformity arrives only once the Commission cites the reference in the Official Journal. Until then the draft is a guide for building your Annex I evidence, and it carries no legal weight on its own yet.
There is one more thing the draft text makes concrete. EN 304 627 requires a machine-readable Software Bill of Materials for each release and a check for known exploitable vulnerabilities before launch. That obligation does not wait for the standard to be cited. The Annex I requirements behind it apply regardless of which harmonised standard you eventually use, so the SBOM and vulnerability handling work is worth starting now whichever context your product falls into.
The short version
Two standards for one router is a deliberate split by deployment context. ETSI EN 304 627 is the IT route. CENELEC prEN 50770-5 is the OT route. The same logic governs network management systems through EN 304 627 and EN 50770-2. Choose the one that matches where your product is meant to live, apply it on its own, and build your Annex I evidence now rather than waiting for the Official Journal citation that turns either draft into a presumption of conformity.