This is a public working draft that has not been reviewed by the IAB or the IETF
This page contains specific information about the IETF relevant to the European Multi Stakeholder Platform on ICT Standardisation, MSP for short. This page is intended for the stakeholders that seek information specific to the MSP's work and how that work relates to the IETF, it is not intended for IETF participants seeking more information about the MSP.
For more detailed information, or to submit relevant information to the MSP, please contact Mat Ford or Olaf Kolkman who are the IETF representatives in the platform and the editors of this page.
This Rolling Plan for ICT Standardisation identifies EU policy priorities where ICT standardisation and ICT standards should be considered as part of policy making. The Rolling Plan is a strategic document focussing on the support that standards, technical specifications, and standardisation in general can provide in the context of EU policy priorities.
The Rolling Plan looks at the standardisation landscape in relation to the EU policy priorities. It identifies possible areas for action and may go into suggesting a plan or roadmap regarding effective standardisation support.
In chapter 3 of the Rolling Plan various policy areas are identified that need to be supported by ICT standardisation. Below we follow the structure of this Rolling Plan and supply information about the related standardisation and research activities in the IETF and IRTF. The final Rolling Plan itself incorporates the IETF-related sections on this page where appropriate.
Previous versions of the Rolling Plan and the IETF work that fits into it:
The current structure is based on the draft document "Rolling Plan on ICT Standardisation (2027 revision)". The objective of this page is to raise awareness regarding policy areas that need standardisation from a European Union point of view and collect input regarding relevant work at the IETF and IRTF.
Since there may not be sufficient specific policy area expertise for each of the areas mentioned in Chapter 3 of the Rolling Plan the references below are likely to be incomplete. Readers are advised to review the IETF areas for potentially related technology work and contact Mat Ford or Olaf Kolkman or any Area Director with general or specific questions.
RP: The actions proposed focus on fields where ICT standardisation can support horizontal and high-level policy objectives in the area of data economy. Actions that address sector specific needs and objectives are included in the respective chapters addressing the different sectors and technology areas.
Action 1: Stock-taking and collaboration:
Action 1.1: SDOs to identify, map and inform about standards that are available or under development that are of relevance in supporting the scenarios listed in section A2 above. StandICT.eu to contribute to this activity.
Action 1.2: SDOs to collaborate on addressing standardisation needs around all the data lifecycle, from data collection to record keeping, archiving and long term preservation of information and start the respective standardisation activities, taking into account the results of ISA2 program, the privacy by design principles, and other relevant activities (see for example section C.2).
Action 1.3: Following an analysis of standards available or under development (Action 1 above) and of possible standardisation needs (Action 2 above), SDOs to develop, in collaboration when appropriate, specific standards in support of the scenarios outlined in section A.2 above, taking into account EU legislation.
Action 2: In the context of the Multi-Stakeholder Platform for ICT Standardisation (MSP), start an analysis on the role of open source software complementing standardisation in the support of the scenarios listed in section A.2 above, e.g. with APIs, protocols, service delivery and other applications.
Action 3: In collaboration with the Data Spaces Support Centre (DSSC), and considering the policy objectives outlined in the chapter on Data Interoperability as well as the work of the EU High-Level Forum, stakeholders to address the topic of gathering and processing data from different sources across domains and develop proposals for respective standardisation projects.
Action 4: Coordinate and support the standardization of data spaces by identifying cross-sectoral and cross-border projects, use cases, and pilots that implement data spaces extending beyond domain and geographic boundaries. This will help define and test the interoperability standards for data spaces
Action 5: SDOs to establish an exchange with relevant open source developing foundations for identifying open source technologies that are available or under way and that can be of relevance for supporting the upcoming EU Data Act and EU policy objectives around the EU data strategy.
The following IETF Working Groups are active in this area:
The JSON Schema (jsonschema) Working Group will produce a stable, reference specification of JSON Schema as a Proposed Standard. JSON Schema is a JSON language for describing the data structures of other JSON documents. JSON Schema is widely referenced within the IETF and by other organizations such as 3GPP, W3C, HR Open Standards, OpenBanking UK, OpenAPI Initiative, ETSI, C2PA, and more. JSON Schema is widely used in many open source projects and commercial offerings. The working group will liaise with other organizations, including but not limited to, ETSI, 3GPP, and OpenAPI Initiative regarding known uses of JSON Schema mechanisms.
The Building Blocks for HTTP APIs (httpapi) Working Group will standardise HTTP protocol extensions for use when HTTP is used for machine-to-machine communication, facilitated by HTTP APIs. Output can include the following:
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-301-data-economy
RP:
Action 1: Cyber Resilience Act (CRA) Implementation: European Standardisation Organizations (ESOs) to develop standards in line with the Standardisation Request M/606.
The first deliverables relating to the horizontal framework and vulnerability handling are expected for 30 August 2026. Product-specific standards covering the important and critical product categories (CRA Annex III and IV) should be ready by 30 October 2026. The set of standardisation deliverables covering the essential requirements of Annex 1 Part 1 in a product-agnostic way are due one year later on 30 October 2027.
In developing such standards, SDOs should pay particular attention to the needs of SMEs, the open-source community and civil society. Additionally, SDOs should ensure that the process is fully in line with Article 2 of M/606, in particular when it comes to disclosure of interests. All experts should clearly indicate the interests they represent, including when working as consultants.
SDOs should assess which vertical areas would benefit from additional standards not included in M/606 and communicate this to the European Commission as part of the preparation of the second standardisation request in support of the CRA. SDOs may even start developing relevant standards for products with digital elements in coordination with the ongoing standardisation work in reply to M/606. Such standards could be harmonised under the second standardisation request.
Action 2: NIS2 Directive Support: ESOs and SDOs are invited to develop standards to protect critical infrastructure per the NIS2 Directive, including the support to trust services under the NIS2, as well as promoting the implementation of the EN 62443 series to support the implementation of operational technology (OT) security in the context of critical infrastructures, such as in the energy sector.
Action 3: Cybersecurity Act/Cybersecurity Certification Framework facilitation: ESOs and SDOs are invited to evaluate current standards under the European Cybersecurity Certification Framework (including both the present and planned schemes as well as initiatives under the Union Rolling Work Programme for European cybersecurity certification (URWP)) to update or introduce new standards on time to facilitate certification activities, including the preparation of candidate certification schemes by ENISA.
Mapping of upcoming EU cybersecurity certification schemes (EUCS, EU5G, EUMSS, EUDI Wallet) and existing national labels or certification schemes and voluntary assurance mechanisms is recommended, to reduce duplication and facilitate mutual recognition where appropriate. Regarding the EUDI Wallet certification scheme, standardizing the functional scheme component of the certification framework for EUDI Wallets and other actors harmonised by the European Commission would be beneficial.
Action 4: Post-Quantum Cryptography: ESOs, SDOs and Open Source Foundations are welcome to assess post-quantum algorithms, examine advanced cryptographic schemes and adopt standards for secure and interoperable post-quantum communications and authentication, including in hybrid form. These standards should support encryption, authentication and seamless identity management capabilities across variety of networks, in all layers of the cloud-edge/IoT continuum, and in particular for constrained devices, aligning with limitations of available resources.
Action 5: Support to the European Health Data Space regulation: ESOs and SDOs are welcome to evaluate the need and feasibility of sector-specific cybersecurity standards for healthcare (for e.g. electronic health record systems, digital health applications, software as medical device, medical devices software, IoMT) that would complement relevant horizontal cybersecurity standards.
Action 6: Horizontal support to EU policies: ESOs and SDOs are invited to perform gap analysis and explore harmonized methodologies for evaluating cybersecurity risks and controls, integrating these into existing and new standards for trusted products and technologies, both software and hardware, in line with EU policy requirements.
ESOs should collaborate with global SDOs to identify available or ongoing technologies of relevance for supporting EU policies.
The ESOs should work with the open source community on setting up appropriate processes for consultation with the open source community and for collaborating with global SDOs and Open Source Foundations on ways to include available work on Free and Open Source and avoid duplication of efforts. In particular this applies to activities taking place in line with the Cyber resilience Act’s Standardisation Request M/606.
Action 7: Continuous (automated) monitoring of compliance: Standardisation organisations should consider the topic of continuous (automated) monitoring of compliance. Available technologies like OSCAL (Open Security Controls Assessment Language) developed by NIST may be a starting point.
The IETF Security Area is the home for working groups focused on security protocols. They provide one or more of the security services: integrity, authentication, non-repudiation, confidentiality, and access control. Since many of the security mechanisms needed to provide these security services employ cryptography, key management is also vital.
The Security Area intersects with all other IETF Areas, and the participants are frequently involved with activities in the working groups from other areas. This involvement focuses upon practical application of Security Area protocols and technologies to the protocols of other Areas.
With specific reference to Commission Recommendation (EU) C(2024) 2393 of 11 April 2024 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography (PQC), the IETF has established the Post-Quantum Use In Protocols (pquip) Working Group which provides a standing venue to discuss PQC (operational and engineering) transition issues and experiences to date relevant to work in the IETF. The WG will document operational and design guidance which supports PQC transition.
Newly chartered Security Area working groups since the last edition of the Rolling Plan are the PKI, Logs and Tree Signatures (plants) Working Group which is working to reduce the costs of large post-quantum signatures on PKIs with Certificate Transparency, and the Secure Evidence and Attestation Transport (seat) Working Group, which is standardising a protocol that enables peer or mutual attestation for (D)TLS using the extension and/or exporter features of D(TLS). Mutual attestation will be supported with and without client TLS authentication to faciliate anonymous client attestation.
The full list of IETF Working Groups in the Security Area is available here.
Relevant Internet Research Task Force (IRTF) efforts include the Crypto Forum Research Group (CFRG) that develops and reviews cryptographic techniques for use in Internet protocols, providing research input that has informed IETF security protocols. The Privacy Enhancements and Assessments Research Group (PEARG) studies privacy-enhancing technologies and privacy considerations for Internet protocols and systems. The Usable Formal Methods Research Group (UFMRG) works to make formal methods and verification techniques more accessible and applicable to Internet protocol design and implementation.
RP:
Action 1: Global industry standards. Foster the emergence of global industry standards under EU leadership for key 5G/6G technologies (radio access network, core network) and network architectures notably through the exploitation of 5G public-private partnership results in key EU and international standardisation bodies (3GPP, ITU, ETSI).
Action 2: Ensure that 5G/6G standards are compatible with innovative use-cases of vertical industries and ensure sufficient spectrum-sharing capabilities, notably through broader participation of industries and authorities with sector-specific needs and in close collaboration with other industry specific standards developing organisations, in 5G standardisation organisations. Several projects funded by the European Commission, as well as the 5G PPP are dealing with 5G standardisation.
Action 3: Lawful access related standards. Foster the emergence of standards that ensure proper provisions for enabling targeted lawful access to data mechanisms in the context of 5G and upcoming 6G networks by encouraging and coordinating law enforcement involvement in relevant standardisation committees, such as (ETSI TC LI, ETSI NFV-SEC, 3GPP SA3-LI) and promoting a European approach based on its legal system.
Action 4: SDOs to work with the stakeholders in standardisation to deliver a report on the standardisation needs and specific requirements for the uptake of 5G in vertical sectors (e.g. transportation, healthcare, manufacturing, energy).
Interactions between IETF and 5G developments fall into several categories:
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-311-5g-and-beyond
RP:
Action 1: Identify cloud service customer needs for ICT standards, practices, rules, open source technologies, and (as exceptional fallback case) open specifications to support the interoperability of cloud services and portability of workloads, and continue or start respective ESO activities. In particular, there is a need to address (1) customer access to and use of data, (2) data sharing across parties, including data intermediaries and altruism organizations and (3) data processing services interoperability, in support of customers aiming to switch between providers of data processing services.
Action 2: MSP to discuss ways for promoting the use of standards, ICT technical specifications and open source technologies needed to further improve the interoperability, data sovereignty, data protection and portability of cloud services as well as multi-cloud management.
Action 3: SDOs and open source communities to strengthen the interlock between standardisation, open interoperability specifications, and open source solutions in the area of cloud, and establish and support bilateral actions for close collaboration of open source initiatives and standardisation. Foster a level playing field that allows the use of open source procedures and deliverables.
Action 4: ESOs and SDOs to consider the ISO/IEC JTC 1 reference cloud architecture and generic cloud architecture building blocks, taking into account available international standards. Available standards and open source technologies should be mapped to the generic cloud architecture building blocks, including privacy, security and test standards for each building block. This will also help determine which standards can be used for open cloud platforms and architectures taking, into account the key role of open source for cloud infrastructure design and implementations.
Action 5: Promote the development of adequate standards/open source developments to ensure a competitive playing field for cloud services provision in Europe and contribute to the green agenda.
Action 6: SDOs, EU-funded projects, and open source communities to foster their collaboration, mutual exchange, integration of Open Source outcomes in ESO deliverables and identification of technologies, e.g. APIs, that have been developed in open source and could be standardised also to enable new automation capabilities.
Action 7: SDOs should focus on addressing the edge/cloud X-continuum paradigm and standardisation challenges, taking into account available international standards. In particular, due to huge increase of connected devices and systems, several computing deployments are embracing the notion of computing continuum, where the right compute resources are placed at optimal processing points, i.e., cloud data centre, edge computing systems and end devices, This requires the support of: (1) continuum of technologies across sensors, connectivity, gateways, edge processing, robotics, platforms, applications, Al, and analytics, including underlying technologies like optical, wireless (cellular and non-cellular) and satellite communications, (2) continuum of intelligence and edge capabilities, (3) continuum of edge applications across vertical sectors and seamless integration.
Action 8: SDOs to contribute to the preparation of an overview of relevant harmonised standards and open interoperability specifications that respond to the legal requirements outlined in the Data Act Art. 35 and that could be recognised in the to-be-established common Union repository for the interoperability of data processing services.
Action 9: SDOs to Promote the development of a standard or a set of standards for processor sockets for cloud computing infrastructure.
Action 10: SDOs to analyse the need and eventually work on promoting the development of standards for multi-cloud and hybrid-cloud management for telecommunication applications and networks.
The IETF has multiple groups working on standards for virtualization techniques, including techniques used in cloud computing and datacenters.
The Workload Identity in Multi System Environments (wimse) Working Group is chartered to address the challenges associated with implementing fine-grained, least privilege access control for workloads deployed across multiple service platforms, spanning both public and private clouds. The work will build on existing standards, open source projects, and community practices, focusing on combining them in a coherent manner to address multi-service workload identity use cases.
The Network Virtualization Overlays (nvo3) Working Group develops a set of protocols and extensions that enable network virtualization within a datacenter environment that assumes an IP-based underlay. An NVO3 solution provides layer 2 and/or layer 3 services for virtual networks enabling multi-tenancy and workload mobility, addressing management and security issues.
The System for Cross-domain Identity Management (scim) Working Group works on standardising methods for creating, reading, searching, modifying, and deleting user identities and identity-related objects across administrative domains, with the goal of simplifying common tasks related to user identity management in services and applications.
The Open Cloud Mesh (ocm) Working Group is working to formally specify OCM. OCM is a server-to-server protocol designed to enable federation between Enterprise File Sync and Share (EFSS) platforms. Initially conceived of in 2015 and deployed since 2016, OCM has been implemented by several platforms.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-312-cloud-and-edge-computing
RP:
Action 1: SDOs to optimize the management of DCAT and DCAT-AP (data discovery) in line with the standardisation request on a European Trusted Data Framework.
Action 2: SDOs to define a framework for the sharing of data from smart devices (data sharing, data usage, data retention, security of data in transit and data at rest)
Action 3: SDOs to consider existing standards and open source developments in the definition of a framework for the sharing of consent-based data (data altruism by organisations or persons), including metadata standards to define the consent attributes (e.g. purpose) and mechanisms to manage withdrawal of consent (data sharing, data governance).
Action 4: SDOs to optimize the management of domain ontologies:
Action 5: SDOs to identify standards for data integration, semantic mapping / tagging, data fabric. Also addressing the way this can help to leverage common domain ontologies (data usage)
Action 6: SDOs to identify standardisation needs and gaps in existing standards and, where needed, define or update standards for data governance, addressing the following levels:
Action 7: Support standardisation needs of the European open data infrastructure, especially the European Data Portal and the SEMIC
The following IETF Working Group is active in this area:
The A Semantic Definition Format for Data and Interactions of Things (asdf) Working Group is tasked with developing Semantic Definition Format (SDF) into a standards-track specification for thing interaction and data modelling. In the process of developing this specification, further functional requirements that emerge in the usage of SDF for model harmonization will be addressed.
The JSON Schema (jsonschema) Working Group will produce a stable, reference specification of JSON Schema as a Proposed Standard. JSON Schema is a JSON language for describing the data structures of other JSON documents. JSON Schema is widely referenced within the IETF and by other organizations such as 3GPP, W3C, HR Open Standards, OpenBanking UK, OpenAPI Initiative, ETSI, C2PA, and more. JSON Schema is widely used in many open source projects and commercial offerings. The working group will liaise with other organizations, including but not limited to, ETSI, 3GPP, and OpenAPI Initiative regarding known uses of JSON Schema mechanisms.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-313-data-interoperability
RP:
Topic 1: IoT interoperability
Action 1.1 Extending SAREF: SDOs to continue ongoing work in the area of semantic standards for better data interoperability (both domain-specific and cross-domain), with special focus on further extending the SAREF ontology—both in number of extensions and the maturity of each extension—and on evolving it towards the requirements of common European Data Spaces and related interoperability frameworks. Additionally, define and provide guidance on a process to reuse, extend, and maintain ontologies based on a common information model, taking into account the needs of the application domains (e.g. health, energy, agriculture, manufacturing, …).
Action 1.2 Contributing to SAREF: Stakeholders, including those who are not ETSI members, should continue to contribute to the SAREF ontology suite via the ETSI SAREF portal and ETSI Labs contribution workflow. Following the ETSI reorganization, governance and maintenance of SAREF are now ensured within ETSI TC DATA (Data Solutions). ETSI EN 303760 provides the European normative guidance for developing, applying and evolving SAREF-compliant ontologies and should be used as the reference framework for future SAREF-related work. In this context, the further evolution of SAREF should be aligned with the European Trusted Data Framework standardisation request, notably the technical specification on an implementation framework for semantic assets, and should help provide reusable ontology governance patterns, extension rules and semantic interoperability guidance for Common European Data Spaces.
Action 1.3 SAREF Profiles: Define SAREF interoperability profiles that would extend current standards and contribute to the ISO/IEC 21823 series on IoT Interoperability.
Action 1.4 SAREF support of digital twins: Provide guidance on how SAREF can be used to support digital twin interoperability. Concepts for digital twins require additional property types for operational use compared to the purely descriptive properties of an asset. These are states and parameters of the assets as well as their measured and actor values (dynamic data). Commands and entire functions (often called technical functions) must also be described using the same concepts. The concept of properties in today’s standards is to extend such semantics in the data models to be able to represent dynamic values correctly. Models for functions/commands are to be developed or existing ones defined in standards.
Action 1.5 SAREF support of technologies and data spaces: SAREF should also be adapted for new realities such as (federated) machine learning and (Generative) AI, Digital twins and other emerging data-rich environments. SDOs should also continue ongoing work for existing standards (e.g. ISO 13584-1 or IEC 61360/ Common Data Dictionary) on semantics and should contribute to guidance on integrating IoT and digital twins with data spaces, taking into account the role of SAREF and related interoperability assets. Contributions on ISO/IEC 30151 (extraction and transaction of data products) and ISO/IEC 30152 (guidance on the integration of IoT and digital twin to data spaces) should be provided taking into account the support of SAREF.
Topic 2: IoT infrastructure
Action 2.1 Landscape study: SDOs to work on a landscape overview report and a gap analysis for IoT standardisation in a decentralized and swarm context addressing a distributed intelligence approach for a collective behaviour of decentralized, self-organized IoT systems.
Action 2.2 Architecture: Promote the development and foster the adoption of Reference Architectures for IoT by contributing architecture patterns to ISO/IEC JTC 1/SC 41, aligned with ISO/IEC 30141 Ed2, ISO/IEC 40141, ISO/IEC 30188, ISO/IEC 40188 and OneM2M. These architectures should interconnect highly heterogeneous and distributed edge nodes and (resource-constrained) devices and should reflect the latest developments in distributed computing, distributed intelligence and learning, mesh networking, swarm computing, digital twins and the broader cloud-edge-IoT continuum.
Action 2.3 Data spaces: SDOs should get involved in the definition of the technical common ground of the Common European Data Spaces to be developed and deployed under the Digital Europe and Horizon Europe programmes and leverage the IoT interoperability standardisation assets for that purpose. This should include, where relevant, the management of data lifecycle, common interoperability and discovery mechanisms, common data models, data curation capabilities, trustworthiness, governance models, decentralised architecture, scale-up methodologies. Particular attention should be given to the European Trusted Data Framework standardisation request, including the deliverables on the data catalogue implementation framework and the semantic assets implementation framework, so that catalogue metadata, semantic assets and domain ontologies evolve coherently. In this respect, IoT standards and SAREF-based semantic assets can support consistent dataset description, discovery, interpretation and reuse across data spaces.. Alignment of specifications should be undertaken between relevant international standards, the DSSC blueprint, the CEEDS (Common European Energy Data Space) blueprint and other European interoperability frameworks.
Action 2.4 Distributed systems: SDOs should consider addressing standardisation challenges for service discovery and authentication in the context of distributed and federated computing systems and in particular, for scenarios where multiple mobile devices are used that require services simultaneously and uninterruptedly. There is a challenge of effectively managing billions of IoT devices, ensuring that they are suitably configured, running appropriate software, kept up-to-date with security updates and patches, and run only properly authenticated and authorised applications. Authentication of services and service providers, while accounting for resource usage, is also an essential part of the economics of the network of the future. There is a need of ensuring interoperability across platforms, devices, and locations, by enabling assets to be securely purchased and transferred between virtual and real-world locations, authenticated and validated, using various consensus methods that support the validation of identity, ownership, and usage rights of any asset subject to relevant rights.
Action 2.5 Swarm systems: SDOs should get involved in the standardisation of loT Swarm Systems. In particular, focus on concepts for loT intelligence clustering to promote collaboration and share of resources and functions for performing specific tasks. These concepts impose standardisation challenges in the required architecture, such as interfaces, data models and ontologies and as well as security and privacy models.
Action 2.6 Green solutions: SDOs should investigate and elaborate on system-level optimisation techniques combining lower power consumption and energy harvesting technologies, E2E energy methods and models for data compression and exchange in edge-cloud IoT platforms, benchmarking methods for energy-efficient and low CO2 footprint of distributed IoT infrastructure and technical solutions, energy-efficient data aggregation mechanisms in intelligent edge IoT systems considering the associated processing and connectivity capabilities across the computing continuum. Specify (or modify existing) interfaces that help monitor and control of the energy usage in communication protocol layer stacks applied in IoT and edge computing solutions. Specify (or modify existing) IoT and edge computing related standards, interfaces, data models and ontologies to reduce the energy and carbon footprint.
Topic 3: Cloud edge IoT
Action 3.1 Platform to integrate verticals: SDOs should look in the standardisation needs arising from IoT deployments that use edge computing as an enabler. The analysis should investigate the impact of the specific use cases of the verticals (such as energy, mobility, agriculture, health and other). Specific concepts such as software containers, APIs and interfaces, etc. should be explored.
Action 3.2 Standards for the continuum: SDOs should focus on standardisation needs for distributed IoT and edge computing integration and interoperability and continuum across sectors and platforms, with contributions to ISO/IEC JTC 1/ SC41 to the PWI JTC1-SC41-22 (Architecture considerations for IoT, edge and cloud) initiated by EUCloudEdgeIoT, to the pattern repository. This should cover the management and deployment of CEI assets, the use of end-to-end capabilities of IoT technologies across the edge granularity and beyond impose continuum standardisation challenges, such as support of interoperability by the means of new interfaces, data models, semantic interoperability and security and privacy models.
Action 3.3 AI and federation: SDOs should consider addressing the standardisation of federated Learning and (Generative) AI for the distributed-IoT-related challenges. In particular, federated Learning brings Al models close to the edge to enhance data protection, improve inference reliability, and increase autonomy of end clusters (e.g., end loT/lloT devices, on-premises servers, etc.). The cloud plays a federation role for aggregating insights from different loT distributed clusters to generate a federated model shared with each individual cluster. Such standardisation challenges are: (1) workflow standardisation, (2) interfaces edge/cloud, orchestration, (3) model contamination, and (4) pipes for handling distributed traffic.
Action 3.4 Agentic AI: SDOs to address standardisation for agentic AI in IoT, including: (1) reference architecture for autonomous AI agents operating in IoT environments, (2) communication protocols and ontologies for agent-to-agent and agent-to-human interaction, (3) goal and task description languages, (4) safety and alignment constraints for autonomous IoT agents.
Topic 4: IoT cybersecurity
Action 4.1 Compliance: Develop a European standard for cyber security compliance of products and systems that is aligned with the current compliance framework of organisations based on the ISO 27000 Information Security Management Standards series, and contribute to standards on the cybersecurity and evaluation of system of systems (ISO/IEC 27115-1, 27115-2, 27115-3, PWI 26601) and on the reuse of evaluation schemes (ISO/IEC PWI 27116) and the GDPR regulation and the future compliance framework of systems based on standards such as ISO/IEC 27100, ISO/IEC 27400, 27402, 27403, ISO 31700-1, ISO 31700-2. Preferably the standard could be used to facilitate compliance with cybersecurity regulations (CRA, NIS 2, or DORA)
Action 4.2 Consumer products: SDOs to assess further gaps and develop standards on the safety and cybersecurity of IoT consumer products under the European Cybersecurity Act or sectorial legislation.
Topic 5: IoT standards Actions
Action 5.1 Inclusion of application domains: SDOs should consider further inclusion of and outreach to verticals.
Action 5.2 Integration of technology domains : SDOs to provide standards supporting compliance as well as standards enabling the integration of (Generative) AI, autonomous AI agents, data processing capabilities and digital twin systems into IoT products, systems, applications and processes. The digital twin part should cover aspects such as identifiers, trust, security, privacy, APIs, provisioning, monitoring, vocabularies and ontologies, metadata, etc.
Action 5.3 Virtualisation and automation: SDOs should investigate IoT system-level and network function virtualisation and AI-based zero-touch operations automation including automated reconfiguration and setup, as well as agent-based coordination and goal-driven reconfiguration for distributed IoT systems.
Action 5.4 Standardisation cycle: SDOs to work towards a faster standardisation cycle more adapted to the fast pace of IoT technology developments. Some examples already exist (e.g. for SAREF).
Action 5.5 Collaboration: Increased collaboration and synchronization between standardisation bodies (e.g., ETSI TC DATA/SAREF, W3C SOSA/SSN, IEEE 1872.2 Autonomous Robotics Ontology, ISO 21823- 3 IoT Semantic Interoperability, OneM2M, ITU-T Study Group 20) especially where semantic interoperability, digital twins, AI-enabled IoT and data spaces intersect. European and international SDOs to increase collaboration, information exchange and contribution with relevant EU projects. Collaboration is already ongoing with ETSI TC DATA, OneM2M and ISO/IEC JTC1 SC41. It should be deepened further especially with ITU-T Study Group 20 and other relevant SDOs.
The IETF has a number of Working Groups chartered to develop standards to support the Internet of Things.
Security aspects of the IoT are being addressed in the following Working Groups:
While the IoT-oriented IETF working groups have already produced the first wave of mature standards for IoT, new research questions are emerging based on the use of those standards. The IRTF Thing-to-Thing Research Group (t2trg) was chartered in 2015 and investigates open research issues in the Internet of Things, including IoT architecture, interoperability, security, constrained environments, and interactions between IoT, edge, and cloud systems. Its work provides research input on architectural and protocol issues that may inform future Internet and IoT standardisation.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-314-internet-of-things
RP:
Action 1. SDOs to take ongoing EU policy activities into account in standardisation, e.g. in ISO/IEC JTC 1/SC 27/WG 5 (identity management and privacy technologies) and other working groups of ISO/IEC JTC 1/SC 27. Also, the standards being developed by ISO/IEC JTC1 SC17 including on mobile driving licenses and identity management via mobile devices are particularly relevant to electronic identification. Furthermore, in order to promote the strengths of the European approach to electronic identification and trust services at global level and to foster mutual recognition of electronic identification and trust services with non-EU countries, ESOs should keep European and international standards aligned wherever possible. The promotion and maintenance of related European approaches, which especially take into account data protection considerations, in international standards should be supported.
Action 2: As required by the revised eIDAS Regulation prepare standards for:
Action 3: SDOs to cooperate and work in the areas of identifiers, vocabularies, semantics, taxonomies, ontologies for electronic attestations, considering work from stakeholders that are already involved in these activities in their respective sectors.
Action 4: The impact of quantum computing technologies on the cryptographic algorithms, in particular public key cryptography, used for electronic identification and trust services including electronic signatures needs to be analysed, and the potential impact on the relevant standards identified. This should lead to guidance on the migration to Quantum Safe Cryptography.
Action 5: SDOs to engage in a collaborative process to address the gaps between existing standards/technical specifications and the requirements of the EUDI Wallet ecosystem. This involves reviewing the initial gap analysis and participating in discussions to agree on the necessary steps for addressing these gaps. Additionally, SDOs are to contribute to identifying key functionalities that need new or updated standards/technical specifications and be involved in their development to support the successful implementation of the EUDI Wallet as outlined in the eIDAS 2 regulations.
Action 6: SDOs to develop technical interoperability mechanisms between wallets released in different regions of the world, such as EUDIW, LACnet. Technical interoperability could set the grounds for the future adoption of political and regulatory decisions that allow, in the long term, for mutual recognition of digital identities with legal effects that would support international trade and commerce and would providing a way to evaluate the trustworthiness of a wallet or an attestation in cross-regional contexts.
The following IETF Working Groups are active in this area:
The Secure Patterns for Internet Credentials (spice) Working Group is chartered to analyze existing and emerging IETF technologies and address any remaining gaps to facilitate their application in digital credentials and presentations.
The SPICE WG will develop digital credential profiles that support various use cases. The profiles developed by the SPICE WG will enable digital credentials to leverage existing IETF technologies. Privacy by design, confidentiality, and consent will be considered, and implementation guidance will be given for each proposed standard in the program of work.
The Web Authorization Protocol (oauth) Working Group is developing a protocol suite that allows a user to grant a third-party Web site or application access to the user's protected resources, without necessarily revealing their long-term credentials, or even their identity. It also developed security schemes for presenting authorisation tokens to access a protected resource.
The ongoing standardisation effort within the OAUTH working group is focusing on these topics:
The Public Notary Transparency (trans) Working Group developed a standards-track specification of the Certificate Transparency protocol (RFC6962) that allows detection of the mis-issuance of certificates issued by CAs or via ad-hoc mapping by maintaining cryptographically verifiable audit logs.
The Automated Certificate Management Environment (acme) Working Group specifies conventions for automated X.509 certificate management, including validation of control over an identifier, certificate issuance, certificate renewal, and certificate revocation. The initial focus of the ACME WG is on domain name certificates (as used by web servers), but other uses of certificates can be considered as work progresses.
The Supply Chain Integrity, Tranparency, and Trust (scitt) Working Group works to define a set of interoperable building blocks that will allow implementers to build integrity and accountability into software supply chain systems to help assure trustworthy operation. For example, a public computer interface system could report its software composition that can then be compared against known software compositions or certifications for such a device thereby giving confidence that the system is running the software expected and has not been modified, either by attack or accident, in the supply chain.
The Digital Emblems (diem) Working Group is chartered to define an architecture and discovery mechanism enabling digital emblems to be presented and validated across applications and platforms in a cohesive way.
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: SDOs to work on the development and revisions of the harmonised standards and technical reports, as requested by standardisation request Mandate 587.
Action 2: SDOs to produce a report describing requirements for ICT products and services to be designed to meet the needs of persons with cognitive and learning disabilities; the report should propose enhancements to relevant existing standards and identify needs for further standardisation such as the development of measurable requirements to address cognitive accessibility to be included in the standards implementing relevant legislation. The report should take into account the latest research in the field of cognitive and learning disabilities and give guidance on which aspects of cognitive and learning disabilities are sufficiently well understood so that support for people with such disabilities can be standardised (and tested) in a technically meaningful way.
Action 3: SDOs to produce a report on the possible accessibility requirements and standardisation needs of ICT products and services that are based on emerging technologies, such as natural language processing, wearables, virtual and augmented reality, AI, as well as biometrics and enhanced ICT security. These technologies must be designed to meet the needs of persons with disabilities, which includes cognitive and learning disabilities.
Action 4: SDOs to continue work on the implementation of the methodology developed under M/473, providing that new standardisation deliverables including the European standards comply with the methodology for mainstream accessibility in standardisation processes and the revision of existing standards in line with what it was agreed in the Standardisation Request, deliverable 3.1.
Action 5: SDOs to develop design principles for better supporting the use of accessibility features by end users of ICT devices and services. The whole range of options for supporting users shall be considered, from traditional solutions like user guides to innovative options like pro-active, AI supported on-device assistants.
Relevant work may be found in the ART area. For instance RFC 3551 identifies the requirements for SIP to support the hearing impaired and RFC4103 defines the RTP payload for text conversation.
RFCs 4103 and 5194 are being referenced in various accessibility regulations being proposed in the US (Section 255/508) and EU (e.g. M376).
RP:
Action 1: SDOs should establish coordinated linkages with, and adequately consider European requirements or expectations from initiatives, including policy initiatives, and organisations contributing to the discourse on AI standardisation. This in particular includes the contents of the AI Act, the standardisation request on AI issued by the European Commission, as well as the orientations set in the 2021 review of the Coordinated Plan.
Action 2: SDOs should further increase their coordination efforts around AI standardisation both in Europe and internationally in order to avoid overlap or unnecessary duplication of efforts. A particular attention should be given to potential overlap with standardisation initiatives that aim to support European legislation.
Action 3: ESOs should coordinate with the Commission and appropriately direct their activities to ensure that the objectives set in the standardisation request on AI are adequately and timely fulfilled. This includes ensuring active participation of representatives from SMEs and civil society organisations in their activities, as well as cooperation with international SDOs.
Action 4: SDOs should timely define and manage the cross-sectorial aspects of the AI Act, interactions between the AI Act and existing or future sectorial safety legislation, and cross-cutting aspects of the standards being developed under the amended M/613.
Action 5: EC and ESOs should coordinate to promote mobilisation of stakeholders around AI standardisation activities.
Action 6: SDOs are invited to participate to the task force that will be set up under the Code of Practice on Transparency of AI-Generated Content to advance the state of the art in marking techniques and detection mechanisms for AI-generated and manipulated content.
The AI Preferences (aipref) Working Group will standardize building blocks that allow for the expression of preferences about how content is collected and processed for Artificial Intelligence (AI) model development, deployment, and use. There are many ways that preferences regarding content might be expressed. The Working Group will focus on attaching preferences to content either by including preferences in content metadata or by signaling preferences using the protocol that delivers content.
The Web Bot Auth (webbotauth) Working Group is developing methods for cryptographically authenticating automated clients and providing additional information about their operators to Web sites.
The Workload Identity in Multi System Environments (wimse) Working Group is chartered to address the challenges associated with implementing fine-grained, least privilege access control for workloads deployed across multiple service platforms, spanning both public and private clouds. AI agents can be viewed as workloads in this context. The work will build on existing standards, open source projects, and community practices, focusing on combining them in a coherent manner to address multi-service workload identity use cases.
AI/ML training/inference and cloud services, require networks with various combinations of high bandwidth, low loss, low delay, and low jitter. To maintain service continuity and experience, these networks must rapidly adapt to adverse conditions like link faults, degradation, and congestion. However, existing routing technologies often face limitations in reacting in a timely manner to such network conditions, especially in large-scale, high-bandwidth data center (DC) and data center interconnect (DCI) networks. The Fast Network Notifications (fann) Working Group is chartered to investigate the need and develop a comprehensive solution to convey locally detected adverse conditions (and their recovery) to remote nodes that can then react to them for enabling efficient and timely handling of traffic flows.
The Internet Research Task Force Network Management Research Group (nmrg) investigates the application of AI and machine learning to network management and automation, including intent-based networking and autonomous networking. More broadly, the IRTF provides a venue for research into emerging interactions between AI systems and Internet architecture and protocols, including distributed AI systems and communication involving AI agents.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-319-artificial-intelligence
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: CEN & CENELEC JTC22 to continue their standardisation work on the most recent topics for quantum technology that were suggested by the Focus Group on Quantum Technologies and their published standardisation roadmap.
Action 2: SDOs should develop standards for supply chains for modular quantum computers and communication architectures, and their enabling technologies. Initially the focus should be on QT research infrastructure, evolving towards QT commercial infrastructure
Action 3: In the MSP, initiate the creation of an intelligent Dashboard to support SMEs, in which the existing standards as well the work relating to quantum technologies of the main standardisation bodies are presented. The dashboard will facilitate SMEs to identify relevant open-source projects in the field of Quantum Computing and Communications, e.g. providing tools for testing, benchmarking etc.
Action 4: SDOs to set up processes for eliciting industry standardisation needs, and industry alliances to coordinate their experts' efforts to contribute to standardisation.
Action 5: SDOs should further increase their coordination efforts in Europe and internationally around Quantum Technologies standardisation in order to avoid overlap or unnecessary duplication of efforts, and to strengthen the visibility and influence of EU priorities in global standardisation fora.
Action 6: SDOs should appropriately consider the effect of quantum computing and Quantum communication technologies on cybersecurity and provide an overview and analyse whether new standards or updates of existing standards on security and privacy are required. Beyond the migration to PQC (TR 103 619), work should encompass benchmarking activities, as well as work on QKD for long-term confidentiality for those use cases requiring such capability, acknowledging that QKD remains a longer-term solution with significant deployment and infrastructure challenges.
Action 7: SDOs should devote specific attention to the standardisation processes (public documents) and existing or future sectorial export control legislation.
Action 8: The EuroQCI should cooperate with SDOs to create the necessary pre-standards/standards for the commercial quantum communication technology in synergy with the specific requirements that are being explored for a certification of the technology.
Action 9: The EuroHPC Joint Undertaking should cooperate with SDOs to create the necessary pre-standards/standards for quantum computing technology in synergy with the specific requirements that are being explored for a certification of the technology.
Action 10: The Chips Joint Undertaking should cooperate with SDOs to create the necessary pre-standards/standards for quantum chips, ensuring alignment with emerging hardware architectures, control systems, and error correction requirements, in synergy with the specific requirements that are being explored for a certification of the technology.
Action 11: CEN-CENELEC JTC22 continue its work to establish benchmarking frameworks for evaluating the performance and quality of algorithmic outputs from quantum computers, ensuring these benchmarks evolve with advancements in hardware and software and align with ongoing standardization efforts in testing, validation, and certification.
Action 12: SDOs should work towards developing standardized quantum computing programming frameworks. These standards should foster interoperability, reducing fragmentation across different platforms.
Action 13: ESOs should closely coordinate to assure proper complementarity, to prevent duplication of European work, and to limit dilution of the currently scarce European pool of quantum standardisation experts.
Action 14: EC DG CNECT should assure that funding of higher-TRL quantum-technology development includes the requirement to projects of developing and executing a standardisation strategy as part of their supply-chains and market development.
Action 15: EuroQCI, and quantum projects under EuroHPC and the Chips JU should include the requirement to grantees of developing and executing a standardisation strategy as part of their supply-chains and market development.
Action 16: EuroQCI, and quantum projects under the EuroHPC and Chips JU should enable and stimulate active contribution of results into European standardisation.
With specific reference to Commission Recommendation (EU) C(2024) 2393 of 11 April 2024 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography (PQC), the IETF has established the Post-Quantum Use In Protocols (pquip) Working Group which provides a standing venue to discuss PQC (operational and engineering) transition issues and experiences to date relevant to work in the IETF. The WG will document operational and design guidance which supports PQC transition.
The PKI, Logs and Tree Signatures (plants) Working Group is working to reduce the costs of large post-quantum signatures on PKIs with Certificate Transparency.
The Internet Research Task Force (IRTF) has hosted the Quantum Internet Research Group (QIRG) since the IETF 101 meeting in March 2018. The QIRG has no official membership and participation is open to everybody. The Research Group communicates primarily through its mailing list which can be freely subscribed and posted to. The entire mailing list archive is publicly available online. The QIRG also holds two or three meetings per year, virtually or in-person, usually at the IETF meetings. The scope of the QIRG’s work is defined in its charter. A key goal of the QIRG is the development of an architectural framework delineating network node roles and definitions that will serve as the first step toward a quantum network architecture. However, it is important to note that the QIRG focuses on fully entanglement-based quantum networks. QKD and trusted repeater networks are also often discussed, but usually in the context of being a stepping stone towards such a full quantum internet. The QIRG, just like all the other IRTF Research Groups, does not work on standards. It is instead focused on developing research collaborations and teamwork in exploring research issues related to the Internet. Nevertheless, the Research Group does also work on producing technical documents on quantum networks. The research group has produced two documents:
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-3111-quantum-technologies
RP:
Action 1: An overview of existing standards and specifications addressing the trusted and secure chips supply chain and existing gaps
Action 2: Develop technical specifications for verification at device level the trustworthiness of advance chips (<5 nm CMOS process node).
Action 3: Develop technical specifications for Anti-counterfeit (premetive controls) for a) design & verification and b) packaging
Action 4: Develop technical specification for design & verify traceability
The Supply Chain Integrity, Tranparency, and Trust (scitt) Working Group works to define a set of interoperable building blocks that will allow implementers to build integrity and accountability into software supply chain systems to help assure trustworthy operation. For example, a public computer interface system could report its software composition that can then be compared against known software compositions or certifications for such a device thereby giving confidence that the system is running the software expected and has not been modified, either by attack or accident, in the supply chain.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-3112-trusted-and-secure-chips
RP:
Action 1: SDOs, industry, operators, technical communities, academia, and civil society are encouraged to contribute to the multistakeholder forum for Internet standards deployment referenced in the NIS2 Implementing Regulation, by identifying best available standards, sharing deployment experience, and supporting the timely implementation of secure, interoperable network infrastructures aligned with the Regulation’s legal requirements and broader EU policy goals.
Action 2: SDOs should share insights, roadmaps, technical gaps and interdependencies that can support the EU’s mapping of Future Internet standardisation priorities, particularly for networking protocols and architectural needs for Web 4.0 shaped by AI, extended reality (XR), blockchain, and quantum technologies.
Action 3: SDOs are invited to contribute to the Open Internet Stack by identifying and maintaining open standards for open-source, interoperable digital infrastructure layers as an alternative to proprietary solutions, updating existing protocols to reflect emerging societal and technological needs, and embedding EU policy principles such as privacy, data protection, and transparency. Their engagement is essential in ensuring the interoperability, global usability, and trustworthiness of the Open Internet Stack. and to contribute to the EU’s competitiveness and startup strategies by lowering entry barriers, enabling open and royalty-free innovation, and supporting the development of interoperable digital services that help European innovators scale and compete globally—while fostering greater inclusion of open, values-driven innovation communities in standardisation processes.
Action 4: SDOs should consider the conclusions of the 2025 Global Multistakeholder High-Level Conference on the Governance of Web 4.0 and Virtual Worlds — as reflected in its outcome document — when developing and prioritising new Internet standards. The conclusions advance shared goals of an open, interoperable, inclusive and resilient future Internet. SDOs are invited to take into account the policy and technical principles and the recommendations outlined in the outcome document, including the creation of multistakeholder governance sandboxes. These elements align with the EU’s broader strategic Internet governance view which highlights the risks of fragmentation, closed ecosystems and conflicting standards frameworks.
The Internet Research Task Force conducts longer-term research on the evolution of Internet architecture, protocols, and technologies. Relevant activities include path-aware networking (PANRG), information-centric networking (ICNRG), Internet decentralization (DINRG), global Internet access (GAIA), empirical Internet measurement (MAPRG), human-rights considerations in Internet protocols (HRPC), and sustainability and resilience (SUSTAIN). The Research and Analysis of Standard-Setting Processes Research Group (RASPRG) complements this technical research with empirical and interdisciplinary research on Internet standard-setting processes, including participation and diversity, decision-making, and interactions between research and standards communities. Together, these activities can provide research evidence, identify architectural and technical gaps, and inform future Internet standardisation priorities.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-3113-internet
RP:
Action 1: ESOs and SDOs, in the framework of the EU Multi-Stakeholder Platform for ICT standardisation, to exchange best practices on cooperation models and participation mechanisms and to describe their engagement practices with Open Source communities, adaptations of processes and policies that were made, and the experience and possible areas of work for further facilitating the interaction between standardisation and Open Source.
Action 2: Open Source organisations, in the framework of the EU Multi-Stakeholder Platform for ICT standardisation, to share information about their experience in interacting with standardisation organisations.
Action 3: In line with the open source strategy that calls for structural engagement of Open Source communities to help deliver high quality standards required by EU law, as is the case with the CRA and the AI Act, ESOs and relevant SDOs are invited to engage with open source communities in developing those standards, to propose and shape their content, contributing efficiently to their development.
Action 4: Reflecting the Open Source Strategy’s commitments to fund open source and to better integrate it into standard setting, the ESOs and Open Source organisations are invited to hold a joint working session, for instance, at one of the meetings of the Multi-Stakeholder Platform for ICT standardisation. Such a session could address issues like compatibility between standardisation IPR and licensing policies and open source licensing, including royalty-free implementability, and structural and financial support for the participation by communities, foundations and maintainers on which open source depends.
Action 5: ESOs to collaboratively explore and establish structured ways and cooperation models with Open Source communities. This includes the development of Open Source (Reference) Implementations accompanying European standards. These should support implementation guidance, interoperability testing, conformity assessment and faster market adoption, particularly in support of EU legislation and policies. it should also consider moving towards digital annexes and machine-readable standardisation assets and how to adopt specifications for use in the EU.
Action 6: ESOs, SDOs, and Open Source organisations, to collaborate on developing common guidance on licensing, intellectual property and copyright aspects that facilitates the development of Open Source implementations of European standards while respecting the intellectual property frameworks of standardisation organisations.
Action 7: Encourage European and national funding programmes to explicitly support projects that promote integration of open source processes and communities into standardisation, combine standardisation activities with Open Source development, including open source implementations of key standards in support of EU policy priorities (e.g. DPP, CRA, other) to enable ease of implementation of standards-compliant solutions by EU SMEs and Startups. Also support the long-term maintenance of reference implementations and implementation support for European standards.
The IETF has created a non-working group mailing list for Open Source at IETF Team (opensource)
There is also a routing open source mailing list to facilitate the discussion among those working or using Open Source and participating or interested in participating in the IETF Routing Area. The intention is to share experiences, what works, where interactions could be better, and - of course - share pointers to each others work to improve collaboration.
IETF Hackathons are held in conjunction with IETF meetings three times per year. IETF Hackathons encourage developers and subject matter experts to collaborate and develop utilities, ideas, sample code and solutions that show practical implementations of IETF standards. The IETF Hackathons aim to advance the pace and relevance of IETF standards activities by bringing the speed and collaborative spirit of open source development into the IETF; and, bring developers and young people into the IETF community. IETF Hackathons are free to attend and open to everyone. They are collaborative events, not competitions.
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: SDOs to develop technical specification and standards for the implementation of eCall in vehicles of categories other than M1 and N1, taking into account requirements included within type-approval regulation.
Action 2: SDOs to lay down physical and operating requirements for aftermarket in-vehicle devices.
Action 3: SDOs to draft guidelines on certification of eCall Systems including aftermarket in-vehicle devices.
Action 4: SDOs to develop conformance and performance tests for recently developed technical specifications / standards for the provision of the eCall service eCall via shared vehicle platforms (C-ITS).
Action 5: SDOs to produce detailed conformity test specifications in support of certification schemes and periodic testing on IVS equipment.
Action 6: SDOs to carry out plugtest interoperability events, taking into account the technological evolution of the system.
Action 7: SDOs to collect feedback about the early versions of the standards and their implementation with technical representatives from vendors and implementers, in particular taking into account the evolution of the networks.
Action 8: SDOs to collect feedback from the relevant stakeholders on the real operation of the eCall service and when needed improve the standards, including through the European eCall Implementation Platform.
Action 9: SDOs to consider any changes to eCall that may be relevant in a 5G paradigm.
The Emergency Context Resolution with Internet Technologies (ECRIT) Working Group has developed a general architecture for enabling IP applications to discover and connect to emergency services.
The Geographic Location/Privacy (GEOPRIV) Working Group has developed protocols that allow IP networks to inform end devices about their geolocation, a critical pre-requisite for emergency calling.
The application-specific working groups in the IETF (for example, the Session Initiation Protocol Core (SIPCORE) Working Group) have developed extensions to support emergency calling as required.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-325-ecall
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Relevant Internet Research Task Force (IRTF) efforts include the Human Rights Protocol Considerations Research Group (HRPC) studies the relationship between Internet protocols, architecture, and human rights, including freedom of expression, freedom of association, and privacy. The Privacy Enhancements and Assessments Research Group (PEARG) investigates privacy risks and privacy-enhancing technologies for Internet protocols and systems. This research can inform consideration of the technical implications of measures addressing online safety, transparency, and accountability.
RP:
Action 1: SDOs to update the existing standards to reflect the conceptual framework of the Directive (EU) 2018/1972, in particular where the concept of 'emergency services' is not consistently used to reflect the 'public safety answering points' or 'emergency communications' (for example ETSI TS 103 479).
Action 2: SDOs to address data protection and privacy requirements (privacy by design) in ongoing standardisation activities concerning emergency communications and processing and transmission of caller location information.
Action 3: SDOs to identify the applicable specifications and standardisation needs for the transmission of handset derived caller location to the most appropriate PSAPs by mobile network operators in both, user plane and control plane modes.
Action 4: SDOs to identify interoperability issues for packet switched emergency communications (e.g: VoLTE) at network and handset level, in particular when using roaming services.
Action 5: SDOs to set requirements, functional architecture, protocol and procedures specification for a Pan European mobile emergency application. Identify standardisation needs for the deployment of emergency applications enhanced with caller location information and accessibility features for the widest range of users, including end-users living with disabilities.
Action 6: ESOs to elaborate standards on accessibility of emergency communications as arising under the European Accessibility Act.
Action 7: to support the standardization of emergency SMS, in particular to '112', to enable the correct routing while roaming services are used.
Action 8: SDOs to define dictionaries for public warning messages for emergency communication services based on the input of various civil protection agencies.
Action 9: SDOs to identify standardisation needs for the establishment of a Union wide public warning system in line with recital 294 of Directive (EU) 2018/1972.
The Emergency Context Resolution with Internet Technologies (ECRIT) Working Group has developed a general architecture for enabling IP applications to discover and connect to emergency services.
The Geographic Location/Privacy (GEOPRIV) Working Group developed protocols that allow IP networks to inform end devices about their geolocation, a critical pre-requisite for emergency calling.
The application-specific working groups in the IETF (for example, the Session Initiation Protocol Core (SIPCORE) Working Group) have developed extensions to support emergency calling as required.
The Secure Telephone Identity Revisited (STIR) WG is developing Internet-based mechanisms that allow verification of the calling party's authorisation to use a particular telephone number for an incoming call. The main focus is on the SIP as one of the main VoIP technologies used by parties that want to misrepresent their origin, in this context the telephone number of origin. See, for example, RFC7375 "Secure telephone identity threat model".
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: The standardisation community should continue analysing possible standardisation gaps and identify solutions to fill them, taking into account also other chapters in the Rolling Plan including actions and references to Blockchain and DLT and their applications. Activities may focus on governance and interoperability, electronic ledgers, organisational frameworks and methodologies, processes and products evaluation schemes, Blockchain and distributed ledger guidelines, smart technologies, objects, distributed computing devices and data services.
Action 2: Continue identifying use cases which are relevant for EU (including EU regulatory requirements like from GDPR, AI Act, Data Act, ePrivacy, eIDAS, AMLD, TOOP, CSRD, etc.) also leveraging on the yearly event “Joining Forces for Blockchain Standardisation” co-organised by the European Commission and INATBA (see section C.2) with special focus on Smart Contracts, Digital Identity, Governance, Interoperability, CBDC/Crypto Assets; submit them to standardisation bodies, including CEN & CENELEC and ETSI, and also ISO, ITU.
Action 3: Continue identification of actual blockchain/DLT implementations in the EU and assess the need for standardisation, harmonisation and workforce training or adaptation, including interoperability with solutions based on other technologies.
Action 4: Standardisation of the operation and reference implementation of permissioned and permissionless distributed ledgers and distributed applications, with the purpose of creating an open ecosystem of industrial interoperable solutions.
Action 5: Standards Development Organisations active in blockchain/DLT standardisation to liaise and coordinate to take advantage of synergies and maximise resources, including with relevant public and private partnerships
Action 6: ESOs to develop standards in line with the Data Act Regulation, in particular regarding essential requirements for smart-contracts. In addition, it would be recommended to explore a general framework for Governance of the European networks based on DLT to allow the flow of smart contracts between different networks.
Action 7: ESOs when relevant to develop the standards needed for the introduction of Digital Euro (CBDC), if the European Central Bank (ECB) decides to its issuance, and for digital assets (MiCA Regulation), in particular to ensure interoperability with smart-contracts, legacy systems, etc, linked with either CBDCs or private money. As per Art. 24 of the draft digital euro Regulation proposed by the Commission in June 2023, to ensure conditional payments on digital euro, the ECB may adopt detailed measures, rules and standards that PSPs can use to ensure interoperable conditional digital euro payment transactions. ESOs to liaise with ECB and in particular with the Digital euro scheme rulebook development group to ensure coordination between the standards for conditional payments involving digital euro and other existing or future standards.
Action 8: SDOs to develop standards and technical guidance, methods and tools for environmental and innovation management of DLTs to support the industry competitiveness and sustainable growth and ensure sustainability and safety for consumers. In particular In the context of the standardisation described in Action 7, SDOs to develop standards towards assessing environmental and sustainability impact including, in particular, CO2 footprint and energy consumption of different blockchains/DLTs, MiCA, EU Sustainable Finance taxonomy.
Action 9: Standardisation efforts to analyze and if needed, enhance the interoperability and international compatibility of the current and pending EBSI topics and capabilities previously mentioned.
Action 10: ESOs to develop standards in line with the EUDI Framework regulation, in particular regarding essential requirements for electronic ledgers.
The Decentralized Internet Infrastructure Research Group (DINRG) investigates open research issues in decentralizing infrastructure services such as trust management, identity management, name resolution, resource/asset ownership management, and resource discovery. The focus of DINRG is on infrastructure services that can benefit from decentralization or that are difficult to realize in local, potentially connectivity-constrained networks. Other topics of interest are the investigation of economic drivers and incentives and the development and operation of experimental platforms. DINRG will operate in a technology- and solution-neutral manner, i.e., while the RG has an interest in distributed ledger technologies, it is not limited to specific technologies or implementation aspects.
In the Internet Research Task Force research on information-centric networking (ICNRG) and Internet decentralization (DINRG) explores alternative approaches to naming, data access, trust, and decentralized Internet architectures that may be relevant to the evolution of future Web and distributed application environments.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-336-web-40-and-virtual-worlds
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: Active involvement and participation of CEN & CENELEC CG-SG experts in the ongoing work of the Smart Energy Expert Group, including regarding the activity on interoperability for access to data in a smart grid environment currently performed under the Joint Working Group of ENTSO-E/EU DSO entity, building upon available standards. This is to prepare the ground for implementing acts on interoperability requirements and transparent and non-discriminatory procedures for access and exchange of data.
Action 2: ETSI, CEN & CENELEC and the other relevant SDOs and related organisations (such as DLMS, KNX and others) should combine their efforts to further enrich and extend the SAREF4ENER extension as well as the main SAREF ontology (including interoperability profiles and associated justifications (interoperability cases) from large-scale projects or initiatives like the EU code of conduct on energy management related interoperability of Energy Smart Appliances). The ETSI SAREF portal and the ETSI labs, which was launched recently, could be the tools to be leveraged for this purpose. Security aspects should be investigated. All new additions to the SAREF specifications should be transposed into the OneM2M specifications. A number of European projects could contribute to a larger scale deployment of SAREF-based solutions such as the Operational Digital Platforms under CEF Digital and the deployment of a common European data space in the DIGITAL programme, which is being prepared in Horizon Europe.
Action 3: CEN & CENELEC, IEEE and OASIS to foster their cooperation to ensure complementary parallel standardisation efforts, to avoid serious conflicts between their respective standardisation deliverables. This action should notably be undertaken in the context of H2-type standards (the interface used for smart grid communication), distributed energy resources and the smart grids architecture model as developed under M/490.
Action 4: ETSI, CEN & CENELEC should include the outcomes and recommendations from the H2020 IoT Large Scale Pilot on Smart Grids and Smart Homes INTERCONNECT into the SAREF4ENER and SAREF4BLDG standards. All new additions to the SAREF specifications should be transposed into the OneM2M specifications. The principles of SAREFisation should also be included.
Action 5: ETSI, CEN & CENELEC should collaborate with (or participate in) the Horizon Europe projects, which will establish the foundations for a Common European Energy Dataspace, and help identify, develop and standardise a set of common technical specifications for it, as well as the deployment action for the energy data space within the DIGITAL Europe programme. They should also collaborate with an upcoming Horizon Europe project on establishing an interoperable ecosystem in the energy area through creating a set of Minimum Interoperability Mechanisms for the energy sector.
Action 6: SDOs and related stakeholders and initiatives should work towards cross-sector interoperability, in particular for data exchange between grid, building and mobility domains.
Action 7: SDOs, in particular their grid-oriented, mobility-oriented, DER-oriented and storage-oriented technical committees, should cooperate to develop standards enabling the electric vehicles (with their – on-board or off-board – chargers) to play an active role through demand-response up to offering grid services.
Action 8: SDOs should collaborate with the project(s) ODEON and HEDGE-IoT resulting from call HORIZON-CL5-2023-D3-01-15 “Supporting the green and digital transformation of the energy ecosystem and enhancing its resilience through the development and piloting of AI-IoT Edge-cloud and platform solutions” to modify existing standards or adopt new ones based on the standardisation work and deliverables of the project(s).
Action 9: SDOs should collaborate with the European Commission and its initiatives to develop and standardise a (Generative)-AI-based “digital spine” of the European Energy System, which is incorporating all functionalities of the digital layer of the energy system, enables multiple innovative energy services, has the needed distributed cloud-edge architecture to support the evolving energy system and which is highly resilient, flexible and automated.
RFC6272 identifies the key infrastructure protocols of the Internet Protocol Suite for use in the Smart Grid. The target audience is those people seeking guidance on how to construct an appropriate Internet Protocol Suite profile for the Smart Grid. In practice, such a profile would consist of selecting what is needed for Smart Grid deployment from the picture presented here.
The Energy Management (EMAN) WG has produced several specifications for an energy management framework, for power/energy monitoring and configuration. See this page for the details. The framework focuses on energy management for IP-based network equipment (routers, switches, PCs, IP cameras, phones and the like).
Many of the IETF Working Groups listed under section 3.1.4 Internet of Things above are developing standards for embedded devices that may also be applicable to Smart grids.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-341-smart-grids-and-smart-metering
Editor's note: No relevant ongoing work identified in the IETF or IRTF
RP:
Action 1: Definition of Global KPIs for Energy Management of Fixed and Mobile access, and Core networks.
Action 2: Guidelines for the use of Global KPIs for Data Centres.
Action 3: Definition of Global KPIs for Data Services.
Action 4: Guidelines for the definition of Green Data Services.
Action 5: Definition and guidelines of KPIs for ICT networks.
Action 6: SDOs to identify needs and develop standards to support UN SDGs, in particular KPI for both synergies and conflicts in Digital transformation and Green transition projects.
Action 7: ETSI, in collaboration with the EGDC, to consider possible paths for ITU L.1480 and L.1333 to be made available for European standardisation to meet EU policy objectives.
Action 8: SDOs to intensify the work on standardisation of resource efficiency aspects of ICT products (including durability, reliability, repairability, reusability, recyclability and recycled content), by product groups and then by products.
The Energy Management (EMAN) Working Group produced several specifications for an energy management framework, for power/energy monitoring and configuration. See http://datatracker.ietf.org/wg/eman/documents/ for the details. The framework focuses on energy management for IP-based network equipment (routers, switches, PCs, IP cameras, phones and the like). A standards track specification (RFC7603) presents the applicability of the EMAN information model in a variety of scenarios with cases and target devices. These use cases are useful for identifying requirements for the framework and MIBs. Further, it describes the relationship of the EMAN framework to other relevant energy monitoring standards and architectures. The EMAN Working Group previously worked on a closely related technology area, but the standards didn’t achieve wide industry adoption, and as illustrated in RFC 9547, the absence of standardized interfaces for measuring, reporting, and managing energy consumption across diverse network setups remains a significant challenge.
The Getting Ready for Energy Efficient Networking (green) Working Group will examine the EMAN work to re-use where applicable but also consider updated operator input and requirements over those previously documented in RFC 6988. Similarly, it will examine the framework previously described in RFC 7326. It will develop new data models, specified in YANG rather than as MIBs. It is necessary to support heterogeneous deployment where energy-related statistics and management may be provided via other models and mechanisms. Guidance will be provided to operators in these heterogeneous environments to cover the incremental deployment of energy-efficient features in both network devices and the management of energy-efficient networks. The GREEN Working Group is chartered to explore use cases, derive requirements, and provide solutions for identifying and characterizing energy efficiency metrics, methods related to energy consumption of network devices, and optimizing energy efficiency across the network.
The Internet Research Task Force have established the Sustainability and the Internet Research Group (SUSTAIN) that investigates how Internet technologies and systems can contribute to environmentally sustainable and resilient societies. Its multidisciplinary research considers sustainability and resilience across Internet architecture, protocols, infrastructure, and operation, providing evidence and research perspectives that can inform future standards development.
https://wiki.ietf.org/en/group/iab/Multi-Stake-Holder-Platform#h-343-ict-environmental-impact
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
Editor's note: No relevant ongoing work identified in the IETF or IRTF
2026-08-21: Incorporating feedback from IRTF chair to add references to IRTF work where appropriate.
2026-08-20: Editorial fixes
2026-08-18: Incorporating feedback from IAB to include reference to relevant IETF and IRTF work including §3.4.3 remove reference to e-Impact IAB program, add reference to SUSTAIN research group, §3.1.14 add reference to IETF Hackathons, §3.1.9 add references to wimse, fann and nmrg
2026-07-21: Updated to reflect RP2027 changes from MSP, added updated text on RP Actions, updated references to relevant IETF work including §3.0.1 jsonschema, §3.0.2 plants, seat, §3.1.2 ocm, §3.1.3 jsonschema, §3.1.4 seat, §3.1.9 webbotauth, §3.1.11 plants
2025-08-19: Updated to reflect RP2026 changes from MSP, added updated text on RP Actions, updated references to relevant IETF work including §3.0.1 wimse, §3.1.5 diem, §3.1.9 aipref, §3.4.3 green
2024-08-08: Updated to reflect RP2025 changes from MSP, added updated text on RP Actions, updated references to relevant IETF work including §3.0.2 pquip, §3.0.3 dult, §3.1.2 wimse, §3.1.4 lwig, §3.1.5 spice
2023-09-22: Archived RP2023, updates to reflect RP2024 changes from MSP, added updated text on RP Actions, updated references to relevant IETF work, updated all links from old trac instance to new IETF wiki.
2022-09-21: Archived RP2022, updates to reflect RP2023 changes from MSP, added text on qirg, ohai, ppm, httpapi, and tigress WGs.
2021-09-24: Archived RP2021, updates to reflect RP2022 changes from MSP, added text on asdf, iotops and madinas WGs.
2020-10-02: Revise text on QUIC prior to submission
2020-09-18: Archived RP2020, numerous updates to reflect RP2021 changes
2019-09-10: Minor updates to prepare for RP2020 draft submission deadline
2019-09-03: Archived RP2019, updates to reflect RP2020 changes
2018-09-19: Final updates prior to submission to EC RP 2019
2018-08-27: Archived RP2018, updates to reflect RP2019 changes
2017-09-22: More updates to reflect current IETF/IRTF work
2017-09-20: Update to reflect current IETF and IRTF work, and to include updated text from RP2018 regarding EC perspectives
2017-09-12: Backup RP2017, created template RP2018
2016-08-23: A round of updates to reflect current work
2016-08-08: Changed the structure, moving the materials related to RP2016 to a separate page. Updated with the current draft of the RP 2017
2015-08-27: Updated the document reflecting the draft 2016 Rolling Plan
2014-03-12: Added link to the final document and modified link to point to more accessible MSP pages
2013-08-04: Added reference to Emun WG in section 3.3.2
2013-07-04: Initial layout and first draft descriptions added.
Attachments:
089_draft_rolling_plan_tfrp055r3_rp.pdf
118_rev_1_rolling_plan_draft_final.pdf