Skip to main content

Clause 7.2 — Product cybersecurity planning

Subclause 7.2 specifies requirements for product cybersecurity planning under FprEN 40000-1-2:2026. Planning describes and tracks all security activities throughout a product's lifecycle.

What Clause 7.2 requires

Requirements

  • [CLA-01-RQ-01]: Product cybersecurity planning shall cover at least applicable activities in Clause 6 (risk management) and subclauses 7.3 through 7.10 (lifecycle activities).
  • [CLA-01-RQ-02]: For the complete product lifecycle, cybersecurity planning activities shall:
    • Be maintained and reviewed on a regular basis.
    • Have their execution tracked.

Inputs & Outputs

  • Input: Product context output from 6.2.
  • Output: Documented product cybersecurity plan covering all required activities.
  • Assessment Criteria: PASS assigned when documented planning exists, covers all mandatory clauses, and includes active execution tracking.

How CVD Portal supports compliance

CVD Portal turns static security plans into actionable, trackable workspace workflows:

  • Automated plan generation: Creating a product workspace automatically initializes a cybersecurity plan covering Clauses 6 and 7.3–7.10.
  • Ownership and due-date management: You can assign specific colleagues as owners for each activity and set calendar due dates in UTC.
  • Progress tracking: The dashboard readiness chart records daily progress across planned controls, flagging overdue or unassigned activities.
  • Audit trail proof: The platform logs every plan modification, review event, and owner reassignment with user identity and timestamp.