Skip to main content

Clause 7.10 — Third-party component cybersecurity management

Subclause 7.10 specifies requirements for due diligence, risk assessment, and continuous monitoring of third-party commercial and open-source (FOSS) components under FprEN 40000-1-2:2026.

What Clause 7.10 requires

Requirements

  • [CLA-10-RQ-01]: Due diligence shall be performed on third-party components during selection and prior to integration into products.
  • [CLA-10-RQ-02]: Third-party components and their integration shall be included in risk assessment and treatment activities (Clause 6).
  • [CLA-10-RQ-03]: Third-party components shall be securely implemented and integrated (7.5).
  • [CLA-10-RQ-04]: Third-party components shall be validated and verified (7.6).
  • [CLA-10-RQ-05]: Third-party components shall be monitored over their lifecycle to identify and address relevant vulnerabilities (7.8).

Due diligence checks include:

  • Assessing intended purpose alignment.
  • Checking for CRA CE marking or EU Declaration of Conformity where available.
  • Verifying absence of known vulnerabilities in databases (e.g., EUVD).
  • Assessing patch availability and vulnerability handling processes.
  • Evaluating FOSS project maintenance activity, open-source stewards, and security practices.
  • Upstream fix contribution (submitting patches back to original projects).

Outputs & Assessment

  • Output: Documented evidence of third-party component due diligence, risk integration, testing, and lifecycle monitoring.
  • Assessment Criteria: PASS assigned when documented due diligence evidence exists and satisfies requirement criteria.

How CVD Portal supports compliance

CVD Portal automates third-party supply chain due diligence and vulnerability management:

  • SBOM Registry & Dependency Scanning: Ingests SBOMs, extracts all third-party libraries, and maps component dependencies instantly.
  • Automated vulnerability matching: Continuously queries EUVD, GCVE, and OSV databases to detect open advisories in integrated components.
  • FOSS maintenance & exposure signals: Calculates component exposure scores, flagging unmaintained or deprecated open-source packages.
  • Upstream reporting connector: Allows you to report discovered third-party vulnerabilities to upstream maintainers or vendor security contacts directly from the dashboard.