Skip to main content

Clause 3 — Terms and definitions

Clause 3 establishes the terms and definitions applicable to FprEN 40000-1-2:2026. It incorporates definitions from Regulation (EU) 2024/2847 (Cyber Resilience Act) and FprEN 40000-1-1:2026.

What Clause 3 requires

Key terms used throughout the standard must be understood in accordance with official EU legal and technical frameworks:

  • Product with digital elements: Any software or hardware product and its remote data processing solutions (RDPS).
  • Intended purpose and reasonably foreseeable use (IPRFU): Conditions of use specified by the manufacturer or expected from reasonable human behavior.
  • Vulnerability: A weakness, susceptibility, or flaw that can be exploited by a threat actor.
  • Active exploitation: Confirmed evidence that an attacker is exploiting a vulnerability in a live system.

How CVD Portal supports compliance

CVD Portal embeds these exact concepts directly into workflow tooling:

  • Product context definition: The product setup workflow prompts you to define IPRFU, remote data processing dependencies, and user classifications using official legal definitions.
  • Article 14 reporting: The early warning and notification engine uses the strict legal definition of actively exploited vulnerabilities to trigger mandatory 24-hour reporting workflows.
  • Standardized role assignment: Platform permissions use defined roles (Admin, Member, Coordinator) to ensure clear accountability across security activities.