Skip to main content

Clause 6.7 — Product cybersecurity risk review

Subclause 6.7 specifies requirements for reviewing and updating product cybersecurity risk management activities under FprEN 40000-1-2:2026. Risk review ensures security stays aligned with evolving threats.

What Clause 6.7 requires

Requirements

  • [RMA-09-RQ-01]: Risk management activities shall be reviewed at planned intervals based on risk assessment and product context.
  • [RMA-09-RQ-02]: Risk reviews shall also be triggered by specific events:
    • Product modifications impacting cybersecurity.
    • Product context or risk acceptance criteria changes.
    • Risk exposure changes (threat landscape shifts).
    • Discovery of known exploitable or actively exploited vulnerabilities.
    • Severe cybersecurity incidents.
    • Component obsolescence impacting product security.
  • [RMA-09-RQ-03]: If impacted, relevant risk assessment documentation shall be updated.

Outputs & Assessment

  • Output: Documentary evidence of completed reviews and updated Clause 6 documentation.
  • Assessment Criteria: PASS assigned when review records exist and updated documentation addresses the review triggers.

How CVD Portal supports compliance

CVD Portal automates both periodic and event-triggered risk reviews:

  • Automated threat triggers: Ingestion of a new CISA KEV match, active exploitation signal, or critical component CVE automatically flags the affected product for risk review.
  • Substantial modification tracking: The workspace records product version changes and prompts a formal risk review when substantial modifications occur.
  • Scheduled review cadences: Automated platform checks monitor documentation freshness, warning you when a annual or periodic review deadline approaches.
  • Versioned technical file records: Updated risk assessments automatically create version-stamped technical file revisions in the compliance repository.