Clause 5.5 — Transparency in product security
Subclause 5.5 defines the transparency principle in FprEN 40000-1-2:2026. Manufacturers must make relevant cybersecurity information available to users, integrators, and supply chain partners in accessible formats.
What Clause 5.5 requires
Effective transparency requires clear communication regarding:
- Security instructions and user documentation.
- Availability and installation of security updates.
- Potential risks of delayed update installation.
- Current security state of the product and residual risks.
- Clear instructions during security incidents.
Information must be delivered in accessible, plain, non-technical language tailored to target user capabilities.
How CVD Portal supports compliance
CVD Portal delivers full transparency tooling across public and private stakeholder channels:
- Whitelabel CVD Portal: Every company gets a branded public security page (
acme.cvdportal.com) where researchers submit reports and users inspect vulnerability disclosure policies. - Automated CSAF 2.0 advisories: One-click CSAF advisory generation exports machine-readable vulnerability notifications for downstream integrators and enterprise users.
- Public Trust Portal: Enterprise plans can publish real-time compliance status, security attestations, and support period commitments to customers.
- Accessible communication: Public portal forms and advisories adhere to WCAG 2.2 AA accessibility standards to ensure all user demographics can access critical security information.