EN 40000-1-2, the first part of the EN 40000 series of horizontal standards supporting the Cyber Resilience Act, has been approved in the CEN-CENELEC formal vote with 100 percent of the votes in favour.
The standard, formally titled “Cybersecurity requirements for products with digital elements - Part 1-2: Principles, product risk management, and lifecycle activities”, specifies general cybersecurity principles and general risk management activities for all products with digital elements, covering every stage of the product lifecycle.
It was developed by CEN/CLC/JTC13 WG9, the working group responsible for the CRA security standards under the standardization request M/606, in which I am contributing.
As the first building block of the EN 40000 series, it anchors the process side of CRA compliance: the cybersecurity principles, the risk management methodology, and the lifecycle activities behind the essential requirements of the regulation.
What this means for manufacturers
The standard is not meant to be harmonized under the CRA, so it will not provide presumption of conformity. That does not make it less relevant: once published, it will be the first standard covering the CRA process requirements.
The CRA obliges manufacturers to perform a documented cybersecurity risk assessment and to keep products secure over the support period. EN 40000-1-2 turns these obligations into concrete principles, risk management activities, and lifecycle activities, making it the practical reference for building and demonstrating CRA-ready processes.
If you are preparing for the CRA, aligning your product security processes with EN 40000-1-2 is the most direct route: when published, it is likely to become the benchmark for CRA process readiness against which your processes are compared.
For background on the regulation itself, see the Cyber Resilience Act guide and Cyber Resilience Act: an Overview.