← All standards
CEN / CENELECCRA harmonised standards

The EN 40000 series of CRA harmonised standards

EN 40000 is the horizontal family of standards that CEN and CENELEC are drafting to support the Cyber Resilience Act. Once cited in the Official Journal, its parts give manufacturers a presumption of conformity with the CRA essential requirements.

Draft standards, no presumption of conformity yet

This assessment is structured to the emerging harmonised standard the prEN 40000 series. That reference is a draft at CEN Enquiry stage and is not yet cited in the Official Journal of the European Union, so following it does not confer presumption of conformity. It is used here as the working blueprint for a defensible, traceable assessment.

What the EN 40000 series is

The technical committee CEN-CENELEC JTC 13 is developing the EN 40000 series under the Commission standardisation request M/606. The series is horizontal, so its parts apply across all products with digital elements rather than to a single product category. Following the series is expected to be the most direct route to demonstrating CRA conformity once the references are cited in the Official Journal.

The numbered parts split the CRA essential requirements into a shared vocabulary, the product security and risk principles, the vulnerability handling process, and a catalogue of generic security requirements. A supporting Technical Report maps threats to security objectives.

The parts, one by one

PartScopeCRA mappingStatus
prEN 40000-1-1
Vocabulary
Common terminology and definitions used across the whole series.FoundationalDraft, CEN Enquiry
Principles for cyber resilience
Cybersecurity principles, the risk-management methodology, and the product lifecycle activities behind the Annex I Part I product requirements.Annex I, Part IDraft, CEN Enquiry
Vulnerability handling
Requirements for handling vulnerabilities across the product lifecycle, from intake through coordinated disclosure and post-release monitoring.Annex I, Part IIDraft, CEN Enquiry
prEN 40000-1-4
Generic security requirements
The catalogue of technical security requirement areas that map to the Annex I Part I essential requirements.Annex I, Part IDraft, earlier development phase
TR 40000-1-5
Threats and security objectives
A Technical Report, informative rather than normative, mapping threats to security objectives to support risk assessment.Supporting reportTechnical Report, in vote

Part titles and stages follow the CEN-CENELEC JTC 13 work programme and can change as drafts progress. Confirm the current stage on the CEN-CENELEC site before relying on it.

How presumption of conformity works

Under Article 27 of the CRA, a manufacturer that fully applies a harmonised standard cited in the Official Journal can presume conformity with the essential requirements the standard covers. That removes the burden of independently proving each requirement.

Until a citation appears, the drafts are still the best working blueprint. Building your process against the current EN 40000 drafts now means you inherit the presumption automatically the day a part is cited, with no rework.

EN 40000 questions

Is EN 40000 published yet?

No. Every part is a draft moving through CEN and CENELEC. None has been cited in the Official Journal of the European Union, so applying a draft does not yet confer presumption of conformity with the CRA.

What is the difference between prEN 40000 and EN 40000?

The prEN prefix marks a draft (a proposed European Norm). Once a part is approved and, where relevant, cited in the Official Journal, it drops the pr and becomes EN 40000.

Which EN 40000 part covers vulnerability handling?

prEN 40000-1-3 covers vulnerability handling, mapping to the CRA Annex I Part II obligations. prEN 40000-1-2 covers the Part I product security and risk requirements.

Build against EN 40000 today

Map your vulnerability handling and product security to the EN 40000 drafts and export an audit-ready Annex VII technical file.

Get Started for Free