Skip to main content

Clause 7.6 — Cybersecurity verification and validation

Subclause 7.6 specifies requirements for cybersecurity verification and validation (V&V) under FprEN 40000-1-2:2026. V&V confirms that implemented security controls satisfy all requirements and operate effectively.

What Clause 7.6 requires

Requirements

  • [CLA-05-RQ-01]: Controls shall be verified to meet specified cybersecurity requirements (7.3).
  • [CLA-05-RQ-02]: The product shall be validated as secure within its context (6.2), based on the risk assessment (6.4).
  • [CLA-05-RQ-03]: V&V activities shall include:
    • Analyzing implementation artifacts (including third-party components).
    • Validating error handling and input data validation.
    • Verifying external interfaces and protocols.
    • Conducting security testing (penetration testing, static/dynamic code analysis, fuzzing, stress testing).
    • Reviewing technical documentation and user instructions for accuracy.
    • Verifying risk treatment alignment.
  • [CLA-05-RQ-04]: V&V activities shall be performed on a recurring basis.
  • [CLA-05-RQ-05]: V&V shall confirm third-party component risks are addressed.
  • [CLA-05-RQ-06]: Test methods shall be explicitly selected and documented.

Outputs & Assessment

  • Output: V&V results documentation (test reports, scan outputs, selected test methods).
  • Assessment Criteria: PASS assigned when V&V documentation exists, meets requirement criteria, and proves controls fulfill requirements in the product context.

How CVD Portal supports compliance

CVD Portal tracks, stores, and verifies testing evidence:

  • Test report repository: You can upload penetration test reports, code audit summaries, and automated scan outputs directly to requirement rows.
  • Automated vulnerability scanning: The platform scans stored SBOM components against live advisory feeds (EUVD, GCVE) to automate component vulnerability V&V.
  • Recurring testing reminders: Automated checks monitor V&V report freshness, warning you when recurring penetration test intervals expire.
  • Auditor evidence drawer: Audit trail drawers display the last thirty test runs and check outcomes for every control row.