EN 40000-1-2, product security and risk
The draft harmonised standard for the CRA product security and risk-management requirements, the essential requirements set out in Annex I Part I.
prEN 40000-1-2:2025 (CEN Enquiry, October 2025)
Draft standard, no presumption of conformity yet
This assessment is structured to the emerging harmonised standard prEN 40000-1-2:2025 (CEN Enquiry, October 2025). That reference is a draft at CEN Enquiry stage and is not yet cited in the Official Journal of the European Union, so following it does not confer presumption of conformity. It is used here as the working blueprint for a defensible, traceable assessment.
What prEN 40000-1-2 covers
prEN 40000-1-2 sets out the cybersecurity principles, the risk-management methodology, and the product lifecycle activities that sit behind the CRA Annex I Part I essential requirements. Where prEN 40000-1-3 governs how a manufacturer handles vulnerabilities once a product ships, prEN 40000-1-2 governs how the product is designed, built, and maintained to be secure in the first place.
The two parts are complementary. A manufacturer aiming for CRA conformity through the EN 40000 route works to both, one for the product requirements and one for the vulnerability handling process.
Evidencing the Annex I Part I requirements
CVD Portal structures the CRA risk assessment, the Annex I Part I control mapping, and the Annex VII technical file so the evidence you produce lines up with the prEN 40000-1-2 structure. When the standard is cited in the Official Journal, that mapping supports presumption of conformity without a rebuild.
Prepare for EN 40000-1-2
Structure your product security evidence to the emerging harmonised standard and export an audit-ready technical file.
Get Started for Free