Clause 3 — Terms and definitions
Clause 3 establishes the terms and definitions applicable to FprEN 40000-1-2:2026. It incorporates definitions from Regulation (EU) 2024/2847 (Cyber Resilience Act) and FprEN 40000-1-1:2026.
What Clause 3 requires
Key terms used throughout the standard must be understood in accordance with official EU legal and technical frameworks:
- Product with digital elements: Any software or hardware product and its remote data processing solutions (RDPS).
- Intended purpose and reasonably foreseeable use (IPRFU): Conditions of use specified by the manufacturer or expected from reasonable human behavior.
- Vulnerability: A weakness, susceptibility, or flaw that can be exploited by a threat actor.
- Active exploitation: Confirmed evidence that an attacker is exploiting a vulnerability in a live system.
How CVD Portal supports compliance
CVD Portal embeds these exact concepts directly into workflow tooling:
- Product context definition: The product setup workflow prompts you to define IPRFU, remote data processing dependencies, and user classifications using official legal definitions.
- Article 14 reporting: The early warning and notification engine uses the strict legal definition of actively exploited vulnerabilities to trigger mandatory 24-hour reporting workflows.
- Standardized role assignment: Platform permissions use defined roles (Admin, Member, Coordinator) to ensure clear accountability across security activities.