Clause 7.2 — Product cybersecurity planning
Subclause 7.2 specifies requirements for product cybersecurity planning under FprEN 40000-1-2:2026. Planning describes and tracks all security activities throughout a product's lifecycle.
What Clause 7.2 requires
Requirements
[CLA-01-RQ-01]: Product cybersecurity planning shall cover at least applicable activities in Clause 6 (risk management) and subclauses 7.3 through 7.10 (lifecycle activities).[CLA-01-RQ-02]: For the complete product lifecycle, cybersecurity planning activities shall:- Be maintained and reviewed on a regular basis.
- Have their execution tracked.
Inputs & Outputs
- Input: Product context output from 6.2.
- Output: Documented product cybersecurity plan covering all required activities.
- Assessment Criteria: PASS assigned when documented planning exists, covers all mandatory clauses, and includes active execution tracking.
How CVD Portal supports compliance
CVD Portal turns static security plans into actionable, trackable workspace workflows:
- Automated plan generation: Creating a product workspace automatically initializes a cybersecurity plan covering Clauses 6 and 7.3–7.10.
- Ownership and due-date management: You can assign specific colleagues as owners for each activity and set calendar due dates in UTC.
- Progress tracking: The dashboard readiness chart records daily progress across planned controls, flagging overdue or unassigned activities.
- Audit trail proof: The platform logs every plan modification, review event, and owner reassignment with user identity and timestamp.