Clause 6.3 — Risk acceptance criteria
Subclause 6.3 specifies requirements to define risk acceptance criteria under FprEN 40000-1-2:2026. Acceptance criteria determine whether identified risks require active treatment or can be accepted.
What Clause 6.3 requires
Requirements
[RMA-02-RQ-01]: Define, justify, and document risk acceptance criteria for the product context (6.2), including:- Relevant regulatory factors (safety and privacy legislation).
- Supply chain considerations (contractual agreements, downstream integrators, risk sharing).
- Nature of known risks (user health and safety, impact severity, inherent functional risks).
- State of the art.
Outputs and Assessment
- Output: Documented product cybersecurity risk acceptance criteria (
C6.3-OUT-01) and applied methodology (C6.3-OUT-02). - Assessment Criteria: PASS assigned when documented criteria exist, align with the product context, and cover all required factors.
How CVD Portal supports compliance
CVD Portal provides structured risk criteria documentation, evaluable acceptance rules, and deterministic artifact generation:
- Evaluable acceptance rules: Define ordered acceptance rules with condition triggers (impact, likelihood, interface restrictions, user capabilities) and mandatory justifications.
- Automated acceptance decisions: Evaluate risks against configured rules to determine whether a risk is acceptable, not acceptable (naming the triggering rule), or undecided (when no rules are configured).
- Standard 5x5 scoring grid: Score each risk from its likelihood (1 to 5) and impact (1 to 5) into Low, Medium, High, or Critical bands on a fixed 1 to 25 scale.
- Six-factor basis (6.3.3): Record the six required factors (regulatory requirements, contractual obligations, known risks, user nature, product nature, state of the art) in the assessment data.
- Risk criteria documentation (
C6.3-OUT-01): Generate the product risk acceptance criteria document from the standard scoring scales, the six-factor basis, and the evaluated acceptance rules. - Standardized risk methodology (
C6.3-OUT-02): Generate the CRA risk assessment and treatment methodology document automatically. - Enforced treatment justifications: Enforce written justifications for any risk marked as accepted or transferred during validation.