The EN 40000 series of CRA harmonised standards
EN 40000 is the horizontal family of standards that CEN and CENELEC are drafting to support the Cyber Resilience Act. Once cited in the Official Journal, its parts give manufacturers a presumption of conformity with the CRA essential requirements.
Draft standards, no presumption of conformity yet
This assessment is structured to the emerging harmonised standard the prEN 40000 series. That reference is a draft at CEN Enquiry stage and is not yet cited in the Official Journal of the European Union, so following it does not confer presumption of conformity. It is used here as the working blueprint for a defensible, traceable assessment.
What the EN 40000 series is
The technical committee CEN-CENELEC JTC 13 is developing the EN 40000 series under the Commission standardisation request M/606. The series is horizontal, so its parts apply across all products with digital elements rather than to a single product category. Following the series is expected to be the most direct route to demonstrating CRA conformity once the references are cited in the Official Journal.
The numbered parts split the CRA essential requirements into a shared vocabulary, the product security and risk principles, the vulnerability handling process, and a catalogue of generic security requirements. A supporting Technical Report maps threats to security objectives.
The parts, one by one
| Part | Scope | CRA mapping | Status |
|---|---|---|---|
prEN 40000-1-1 Vocabulary | Common terminology and definitions used across the whole series. | Foundational | Draft, CEN Enquiry |
Principles for cyber resilience | Cybersecurity principles, the risk-management methodology, and the product lifecycle activities behind the Annex I Part I product requirements. | Annex I, Part I | Draft, CEN Enquiry |
Vulnerability handling | Requirements for handling vulnerabilities across the product lifecycle, from intake through coordinated disclosure and post-release monitoring. | Annex I, Part II | Draft, CEN Enquiry |
prEN 40000-1-4 Generic security requirements | The catalogue of technical security requirement areas that map to the Annex I Part I essential requirements. | Annex I, Part I | Draft, earlier development phase |
TR 40000-1-5 Threats and security objectives | A Technical Report, informative rather than normative, mapping threats to security objectives to support risk assessment. | Supporting report | Technical Report, in vote |
Part titles and stages follow the CEN-CENELEC JTC 13 work programme and can change as drafts progress. Confirm the current stage on the CEN-CENELEC site before relying on it.
How presumption of conformity works
Under Article 27 of the CRA, a manufacturer that fully applies a harmonised standard cited in the Official Journal can presume conformity with the essential requirements the standard covers. That removes the burden of independently proving each requirement.
Until a citation appears, the drafts are still the best working blueprint. Building your process against the current EN 40000 drafts now means you inherit the presumption automatically the day a part is cited, with no rework.
EN 40000 questions
Is EN 40000 published yet?
No. Every part is a draft moving through CEN and CENELEC. None has been cited in the Official Journal of the European Union, so applying a draft does not yet confer presumption of conformity with the CRA.
What is the difference between prEN 40000 and EN 40000?
The prEN prefix marks a draft (a proposed European Norm). Once a part is approved and, where relevant, cited in the Official Journal, it drops the pr and becomes EN 40000.
Which EN 40000 part covers vulnerability handling?
prEN 40000-1-3 covers vulnerability handling, mapping to the CRA Annex I Part II obligations. prEN 40000-1-2 covers the Part I product security and risk requirements.
Build against EN 40000 today
Map your vulnerability handling and product security to the EN 40000 drafts and export an audit-ready Annex VII technical file.
Get Started for Free