Clause 6 — Risk management activities overview
Clause 6 specifies normative requirements for managing product cybersecurity risks across the entire product lifecycle under FprEN 40000-1-2:2026.
What Clause 6 requires
Clause 6 establishes a cyclic risk management framework applicable at any lifecycle stage. Each subclause uses a standardized normative structure (Input, Requirement, Output, Assessment Criteria) with normative requirement IDs (RMA-01 through RMA-09).
The clause spans six interconnected activities:
- Product context (6.2,
RMA-01): Defining IPRFU, operational environment, architecture, user classifications, and RDPS. - Risk acceptance criteria (6.3,
RMA-02): Establishing acceptable risk boundaries. - Risk assessment (6.4,
RMA-03toRMA-06): Identifying assets, threats, analyzing likelihood/impact, and evaluating residual risks. - Risk treatment (6.5,
RMA-07): Avoiding or mitigating unacceptable risks and re-evaluating. - Risk communication (6.6,
RMA-08): Disclosing transferred risks and conditions of secure use to users. - Risk review (6.7,
RMA-09): Re-evaluating risks on regular schedules or triggered events.
How CVD Portal supports compliance
CVD Portal implements Clause 6 as a dynamic, continuous risk loop rather than a static document:
- Normative control mapping: The Control Register tracks every
RMA-*requirement ID as an explicit compliance item. - PASS/FAIL verdict engine: Automated checks evaluate documentation completeness and live configurations against normative assessment criteria.
- Product compliance workspace: The product Assess tab walks teams through context setup, asset mapping, threat modeling, and risk evaluation.
- Audit trail capture: Every risk decision, justification, and treatment update is logged with timestamps and user details.