Skip to main content

Clause 5.3 — Product security by design

Subclause 5.3 defines the security by design principle in FprEN 40000-1-2:2026. Security measures must be integrated into products from the initial concept phase and maintained through the whole lifecycle.

What Clause 5.3 requires

Manufacturers must employ proven security architecture techniques, including:

  • Least privilege: Restricting resource access to the absolute minimum necessary.
  • Attack surface minimization: Removing unneeded interfaces, ports, and protocols.
  • Defense in depth: Layering multiple security controls to eliminate single points of failure.
  • Secure coding practices: Eliminating common software defects (memory safety, injection flaws) during implementation.
  • No security by obscurity: Relying on robust mechanisms rather than hidden algorithms.
  • User-centric design: Minimizing friction while preventing security circumvention.

How CVD Portal supports compliance

CVD Portal reinforces security by design principles across your product architecture and team workflows:

  • Architecture and design artifact tracking: The platform technical file generator captures design decisions, trust boundaries, and interface protection controls.
  • Automated dependency verification: Integrating with GitHub and SBOM registries ensures third-party libraries meet secure coding and maintenance criteria before integration.
  • Policy library controls: Pre-formatted secure coding and architecture guidelines provide development teams with actionable compliance requirements.
  • Audit trail proof: The platform records design reviews and control verification events in an immutable audit log for assessment bodies.