Clause 1 — Scope
Clause 1 defines the scope of FprEN 40000-1-2:2026. This horizontal draft standard specifies generic product cybersecurity principles, baseline risk management requirements, and lifecycle activities for products with digital elements.
What Clause 1 requires
The standard applies to all products with digital elements across their full lifecycle, from concept and design to decommission. It also provides the baseline framework for product-category vertical standards developed under European Commission standardization request M/606.
Clause 1 establishes three core coverage areas:
- Generic cybersecurity principles for all interested parties.
- Baseline requirements to manage product cybersecurity risks.
- Lifecycle requirements to maintain product security from development to end of support.
How CVD Portal supports compliance
CVD Portal provides an end-to-end compliance workspace that covers the full product lifecycle:
- Full lifecycle coverage: You can manage product security from initial product context definition through active vulnerability monitoring to end-of-support decommissioning.
- Product compliance workspace: Every registered product gets a dedicated workspace that aligns risk assessment, SBOM component tracking, and technical file generation with CRA Annex I Part I requirements.
- Vertical standard alignment: The platform product classifier identifies whether your product falls under an Annex III category covered by a vertical standard (such as ETSI EN 304 series or CENELEC standards) and links the relevant control sets.
- Continuous readiness tracking: Daily automated checks monitor your live setup against the baseline requirements of the standard, giving you an immediate verdict on your compliance state.