Clause 7.4 — Cybersecurity architecture and design
Subclause 7.4 specifies requirements for product cybersecurity architecture and design under FprEN 40000-1-2:2026. Design decisions select controls that fulfill specified security requirements.
What Clause 7.4 requires
Requirements
[CLA-03-RQ-01]: Cybersecurity architecture and design shall be specified, including selection of appropriate cybersecurity controls to fulfill requirements (7.3). Considers security by design (5.3) and secure by default (5.4).[CLA-03-RQ-02]: Cybersecurity architecture and design shall ensure product security is maintained during component integration, including third-party components and RDPS.
Design artifacts include:
- Secure-by-default settings of components.
- Internal and external interface protection definitions.
- Data-flow and trust-boundary diagrams (highlighting RDPS boundaries).
- Separation mechanisms for functional versus security updates.
Outputs & Assessment
- Output: Documented cybersecurity architecture and design specification.
- Assessment Criteria: PASS assigned when architecture documentation exists, meets requirement criteria, and aligns with specified cybersecurity requirements.
How CVD Portal supports compliance
CVD Portal provides structured artifact repositories for architectural evidence:
- Technical file artifact store: You can upload and store architecture diagrams, interface protection specs, and trust boundary documentation.
- RDPS security boundary tracking: The platform explicitly records remote data processing solutions, documenting boundary encryption and access controls.
- Component interface mapping: Third-party components registered in the SBOM map directly to architectural trust boundaries.
- Control catalog alignment: Built-in control catalogs map design choices to standards such as EN 40000-1-4, ETSI EN 303 645, and EN IEC 62443-4-2.