Home
About us
News
Team
Updates
Contact
21 Jul 2026

SafeShark updates cryptographic assessment policy following new ETSI guidance

SafeShark has updated its assessment approach following new ETSI guidance on acceptable cryptographic key sizes, with important implications for manufacturers using RSA-2048 certificates in connected products.

In June 2026, ETSI TS 119 312 V2.1.1 (Electronic Signatures and Trust Infrastructures (ESI); Cryptographic Suites) introduced updated guidance on acceptable cryptographic key sizes.

As ETSI TS 119 312 is referenced within relevant evaluation methodologies and aligns with European standards used in security assessments, SafeShark has incorporated the new guidance into its CRY-1 assessment approach.

ETSI TS 119 312 V2.1.1 states that RSA keys with a length of at least 1,900 bits and less than 3,000 bits – including RSA-2048 – shall not be used to issue new certificates after 31 December 2026.

Certificates issued on or before that date using such keys must have a validity period ending no later than 31 December 2028. After 31 December 2026, newly issued certificates must use RSA keys of at least 3,000 bits or another ETSI-recommended signature scheme. [etsi.org]

In line with this guidance, SafeShark’s internal test procedure treats RSA-2048 certificates used to protect security, network or privacy assets as non-compliant where their validity extends beyond 31 December 2028. SafeShark will also assess RSA-2048 certificates issued after 31 December 2026 as non-compliant with this policy.

Manufacturers whose devices rely on hardcoded RSA-2048 trust anchors or certificate infrastructures are strongly encouraged to migrate to RSA keys of at least 3,072 bits, or an approved alternative such as NIST P-256 or another approved cryptographic scheme, before 31 December 2028.

New hardware or platform revisions finalised after 31 December 2026 should not introduce new RSA-2048 certificate deployments.

Manufacturers should review their certificate infrastructure and product roadmaps now, particularly where cryptographic components cannot easily be updated once products have entered the market.

If you are unsure how the updated guidance affects your products or upcoming security assessments, contact SafeShark to discuss your current certificate architecture and the steps needed to maintain compliance.

5th Floor
89 Albert Embankment
Vauxhall, London
SE1 7TP
Site by Fortico