Clause 6.7 — Product cybersecurity risk review
Subclause 6.7 specifies requirements for reviewing and updating product cybersecurity risk management activities under FprEN 40000-1-2:2026. Risk review ensures security stays aligned with evolving threats.
What Clause 6.7 requires
Requirements
[RMA-09-RQ-01]: Risk management activities shall be reviewed at planned intervals based on risk assessment and product context.[RMA-09-RQ-02]: Risk reviews shall also be triggered by specific events:- Product modifications impacting cybersecurity.
- Product context or risk acceptance criteria changes.
- Risk exposure changes (threat landscape shifts).
- Discovery of known exploitable or actively exploited vulnerabilities.
- Severe cybersecurity incidents.
- Component obsolescence impacting product security.
[RMA-09-RQ-03]: If impacted, relevant risk assessment documentation shall be updated.
Outputs & Assessment
- Output: Documentary evidence of completed reviews and updated Clause 6 documentation.
- Assessment Criteria: PASS assigned when review records exist and updated documentation addresses the review triggers.
How CVD Portal supports compliance
CVD Portal automates both periodic and event-triggered risk reviews:
- Automated threat triggers: Ingestion of a new CISA KEV match, active exploitation signal, or critical component CVE automatically flags the affected product for risk review.
- Substantial modification tracking: The workspace records product version changes and prompts a formal risk review when substantial modifications occur.
- Scheduled review cadences: Automated platform checks monitor documentation freshness, warning you when a annual or periodic review deadline approaches.
- Versioned technical file records: Updated risk assessments automatically create version-stamped technical file revisions in the compliance repository.