Clause 5 — Product cybersecurity principles
Clause 5 establishes the foundational product cybersecurity principles under FprEN 40000-1-2:2026. While informative in nature, these principles define the overarching design philosophy for CRA Annex I Part I compliance.
What Clause 5 requires
Clause 5 sets out four core principles that guide all risk management (Clause 6) and product lifecycle (Clause 7) activities:
- Risk-based approach (5.2): Implement controls tailored to identified risks throughout the product lifecycle.
- Product security by design (5.3): Integrate security controls from the concept phase rather than adding them later.
- Secure by default product (5.4): Deliver products in a secure state out of the box without requiring complex user action.
- Transparency in product security (5.5): Provide clear, usable security information to users, integrators, and supply chain partners.
How CVD Portal supports compliance
CVD Portal embeds these four principles into platform workflows:
- Unified governance: The platform connects high-level cybersecurity principles directly to actionable controls, automated checks, and audit trails.
- Continuous evaluation: The Product Compliance Workspace automatically assesses whether your product design and vulnerability handling processes fulfill the four principles.
- Standardized policy library: Pre-built policy templates translate abstract principles into operational procedures for engineering and product teams.