FprEN 40000-1-2

Cybersecurity requirements for products with digital elements - Part 1-2: Principles, product risk management, and lifecycle activities FprEN 40000-1-2

Publication date:   Aug 6, 2026

General information

50.20   Proof sent to secretariat or FDIS ballot initiated: 8 weeks   Aug 6, 2026

CEN/CENELEC

CEN/CLC/JTC 13 Cybersecurity and Data Protection

European Norm

35.030   IT Security

Buying

Draft

Language in which you want to receive the document.

Scope

This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.

Related legislation

Legislation related to this standard

2024/2847

Life cycle

NOW

IN_DEVELOPMENT
FprEN 40000-1-2
50.20 Proof sent to secretariat or FDIS ballot initiated: 8 weeks
Aug 6, 2026




Access Genorma App Everywhere

Get fast and easy access to top European and International standards (EN, ISO, IEC) via your mobile phone, tablet or the web.