Skip to main content

Clause 6 — Risk management activities overview

Clause 6 specifies normative requirements for managing product cybersecurity risks across the entire product lifecycle under FprEN 40000-1-2:2026.

What Clause 6 requires

Clause 6 establishes a cyclic risk management framework applicable at any lifecycle stage. Each subclause uses a standardized normative structure (Input, Requirement, Output, Assessment Criteria) with normative requirement IDs (RMA-01 through RMA-09).

The clause spans six interconnected activities:

  1. Product context (6.2, RMA-01): Defining IPRFU, operational environment, architecture, user classifications, and RDPS.
  2. Risk acceptance criteria (6.3, RMA-02): Establishing acceptable risk boundaries.
  3. Risk assessment (6.4, RMA-03 to RMA-06): Identifying assets, threats, analyzing likelihood/impact, and evaluating residual risks.
  4. Risk treatment (6.5, RMA-07): Avoiding or mitigating unacceptable risks and re-evaluating.
  5. Risk communication (6.6, RMA-08): Disclosing transferred risks and conditions of secure use to users.
  6. Risk review (6.7, RMA-09): Re-evaluating risks on regular schedules or triggered events.

How CVD Portal supports compliance

CVD Portal implements Clause 6 as a dynamic, continuous risk loop rather than a static document:

  • Normative control mapping: The Control Register tracks every RMA-* requirement ID as an explicit compliance item.
  • PASS/FAIL verdict engine: Automated checks evaluate documentation completeness and live configurations against normative assessment criteria.
  • Product compliance workspace: The product Assess tab walks teams through context setup, asset mapping, threat modeling, and risk evaluation.
  • Audit trail capture: Every risk decision, justification, and treatment update is logged with timestamps and user details.