← All EN 40000 parts
Draft harmonised standardFoundational, no Annex I mapping

EN 40000-1-1 draft: the vocabulary for the CRA harmonised standards

prEN 40000-1-1 defines the common terms and definitions used across the EN 40000 series of CRA harmonised standards. The document is a draft in approval. The standard carries no technical security requirements for products.

Draft standard, no presumption of conformity yet

prEN 40000-1-1 has completed its CEN public enquiry and sits in approval. It is not cited in the Official Journal of the European Union, so it confers no presumption of conformity. A vocabulary part defines terms rather than requirements, so no product is built against it.

What this part is for

CEN-CLC/JTC 13 WG 9 is developing the EN 40000 series under the Commission standardisation request M/606. The Commission issued request M/606 by Commission Implementing Decision C(2025) 618 final on 3 February 2025. CEN, CENELEC and ETSI accepted the request on 3 April 2025. The request covers 41 standards split between horizontal and vertical standards.

The EN 40000 family is the horizontal series. Its parts apply across all products with digital elements. Within the series, prEN 40000-1-1 provides the shared terminology and definitions. The vocabulary establishes common concepts for the principles and risk methodology in FprEN 40000-1-2, the vulnerability handling processes in prEN 40000-1-3, and the generic security requirements in prEN 40000-1-4.

A shared vocabulary exists so that one term carries one meaning across every part of the series. Manufacturers, assessors and market surveillance authorities then read the same word the same way.

Why there is no clause mapping on this page

The page for prEN 40000-1-3 provides a clause-by-clause mapping to product features. prEN 40000-1-1 carries no clause mapping because it contains no technical or process requirements.

A vocabulary standard contains defined terms rather than normative compliance obligations. Manufacturers do not implement technical controls or write technical documentation against defined terms. The part serves as the foundation for the normative requirements in the other parts of the series.

Where it sits in the series

  • FprEN 40000-1-2

    The principles, risk methodology and lifecycle activities behind Annex I Part I.

  • prEN 40000-1-3

    The vulnerability handling process, mapping to Annex I Part II.

  • prEN 40000-1-4

    Generic cybersecurity requirements catalogued for Annex I Part I.

  • TR 40000-1-5

    A Technical Report on threats and security objectives. Informative, not normative.

The full part-by-part breakdown is on the EN 40000 series page.

Sources

Questions

What does prEN 40000-1-1 cover?

prEN 40000-1-1 provides the common terminology and definitions used across the EN 40000 series of CRA harmonised standards. It establishes shared concepts for the whole horizontal series and contains no product requirements of its own.

Is prEN 40000-1-1 published?

No. prEN 40000-1-1 is a draft that has completed its CEN public enquiry and sits in approval. No part of the EN 40000 series has been ratified as an EN or cited in the Official Journal of the European Union.

Does applying prEN 40000-1-1 give me presumption of conformity?

No. Presumption of conformity under Article 27(1) requires publication of the reference in the Official Journal of the European Union. A draft confers no presumption, and a vocabulary standard defines terms rather than essential requirements.

Do I need prEN 40000-1-1 to start my Annex I work?

No. The essential requirements in Annex I are directly binding on manufacturers. Article 32(2) routes an Annex III class I product to third-party assessment where no harmonised standard exists or where none is applied, so waiting for standards is not required to begin compliance.

Which EN 40000 part should I read first?

The vocabulary part is useful for reading the rest of the series. However, the parts that carry normative requirements are where the primary compliance work is, including FprEN 40000-1-2 for product security principles and prEN 40000-1-3 for vulnerability handling.