Skip to main content

Clause 5.5 — Transparency in product security

Subclause 5.5 defines the transparency principle in FprEN 40000-1-2:2026. Manufacturers must make relevant cybersecurity information available to users, integrators, and supply chain partners in accessible formats.

What Clause 5.5 requires

Effective transparency requires clear communication regarding:

  • Security instructions and user documentation.
  • Availability and installation of security updates.
  • Potential risks of delayed update installation.
  • Current security state of the product and residual risks.
  • Clear instructions during security incidents.

Information must be delivered in accessible, plain, non-technical language tailored to target user capabilities.

How CVD Portal supports compliance

CVD Portal delivers full transparency tooling across public and private stakeholder channels:

  • Whitelabel CVD Portal: Every company gets a branded public security page (acme.cvdportal.com) where researchers submit reports and users inspect vulnerability disclosure policies.
  • Automated CSAF 2.0 advisories: One-click CSAF advisory generation exports machine-readable vulnerability notifications for downstream integrators and enterprise users.
  • Public Trust Portal: Enterprise plans can publish real-time compliance status, security attestations, and support period commitments to customers.
  • Accessible communication: Public portal forms and advisories adhere to WCAG 2.2 AA accessibility standards to ensure all user demographics can access critical security information.