Skip to main content

Clause 1 — Scope

Clause 1 defines the scope of FprEN 40000-1-2:2026. This horizontal draft standard specifies generic product cybersecurity principles, baseline risk management requirements, and lifecycle activities for products with digital elements.

What Clause 1 requires

The standard applies to all products with digital elements across their full lifecycle, from concept and design to decommission. It also provides the baseline framework for product-category vertical standards developed under European Commission standardization request M/606.

Clause 1 establishes three core coverage areas:

  • Generic cybersecurity principles for all interested parties.
  • Baseline requirements to manage product cybersecurity risks.
  • Lifecycle requirements to maintain product security from development to end of support.

How CVD Portal supports compliance

CVD Portal provides an end-to-end compliance workspace that covers the full product lifecycle:

  • Full lifecycle coverage: You can manage product security from initial product context definition through active vulnerability monitoring to end-of-support decommissioning.
  • Product compliance workspace: Every registered product gets a dedicated workspace that aligns risk assessment, SBOM component tracking, and technical file generation with CRA Annex I Part I requirements.
  • Vertical standard alignment: The platform product classifier identifies whether your product falls under an Annex III category covered by a vertical standard (such as ETSI EN 304 series or CENELEC standards) and links the relevant control sets.
  • Continuous readiness tracking: Daily automated checks monitor your live setup against the baseline requirements of the standard, giving you an immediate verdict on your compliance state.