50.20 Proof sent to secretariat or FDIS ballot initiated: 8 weeks Aug 6, 2026
CEN/CENELEC
CEN/CLC/JTC 13 Cybersecurity and Data Protection
European Norm
35.030 IT Security
This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.
Legislation related to this standard
IN_DEVELOPMENT
FprEN 40000-1-2
50.20
Proof sent to secretariat or FDIS ballot initiated: 8 weeks
Aug 6, 2026