Clause 7.10 — Third-party component cybersecurity management
Subclause 7.10 specifies requirements for due diligence, risk assessment, and continuous monitoring of third-party commercial and open-source (FOSS) components under FprEN 40000-1-2:2026.
What Clause 7.10 requires
Requirements
[CLA-10-RQ-01]: Due diligence shall be performed on third-party components during selection and prior to integration into products.[CLA-10-RQ-02]: Third-party components and their integration shall be included in risk assessment and treatment activities (Clause 6).[CLA-10-RQ-03]: Third-party components shall be securely implemented and integrated (7.5).[CLA-10-RQ-04]: Third-party components shall be validated and verified (7.6).[CLA-10-RQ-05]: Third-party components shall be monitored over their lifecycle to identify and address relevant vulnerabilities (7.8).
Due diligence checks include:
- Assessing intended purpose alignment.
- Checking for CRA CE marking or EU Declaration of Conformity where available.
- Verifying absence of known vulnerabilities in databases (e.g., EUVD).
- Assessing patch availability and vulnerability handling processes.
- Evaluating FOSS project maintenance activity, open-source stewards, and security practices.
- Upstream fix contribution (submitting patches back to original projects).
Outputs & Assessment
- Output: Documented evidence of third-party component due diligence, risk integration, testing, and lifecycle monitoring.
- Assessment Criteria: PASS assigned when documented due diligence evidence exists and satisfies requirement criteria.
How CVD Portal supports compliance
CVD Portal automates third-party supply chain due diligence and vulnerability management:
- SBOM Registry & Dependency Scanning: Ingests SBOMs, extracts all third-party libraries, and maps component dependencies instantly.
- Automated vulnerability matching: Continuously queries EUVD, GCVE, and OSV databases to detect open advisories in integrated components.
- FOSS maintenance & exposure signals: Calculates component exposure scores, flagging unmaintained or deprecated open-source packages.
- Upstream reporting connector: Allows you to report discovered third-party vulnerabilities to upstream maintainers or vendor security contacts directly from the dashboard.