Skip to main content

Clause 5 — Product cybersecurity principles

Clause 5 establishes the foundational product cybersecurity principles under FprEN 40000-1-2:2026. While informative in nature, these principles define the overarching design philosophy for CRA Annex I Part I compliance.

What Clause 5 requires

Clause 5 sets out four core principles that guide all risk management (Clause 6) and product lifecycle (Clause 7) activities:

  • Risk-based approach (5.2): Implement controls tailored to identified risks throughout the product lifecycle.
  • Product security by design (5.3): Integrate security controls from the concept phase rather than adding them later.
  • Secure by default product (5.4): Deliver products in a secure state out of the box without requiring complex user action.
  • Transparency in product security (5.5): Provide clear, usable security information to users, integrators, and supply chain partners.

How CVD Portal supports compliance

CVD Portal embeds these four principles into platform workflows:

  • Unified governance: The platform connects high-level cybersecurity principles directly to actionable controls, automated checks, and audit trails.
  • Continuous evaluation: The Product Compliance Workspace automatically assesses whether your product design and vulnerability handling processes fulfill the four principles.
  • Standardized policy library: Pre-built policy templates translate abstract principles into operational procedures for engineering and product teams.