← All EN 40000 parts
Draft harmonised standardCRA Annex I, Part I

prEN 40000-1-4, generic security requirements

The part of the EN 40000 series intended to catalogue the generic security requirements that map to the CRA Annex I Part I essential requirements. It is a draft, and it sits further back than the parts that have completed enquiry.

Draft standard, no presumption of conformity yet

prEN 40000-1-4 is a draft in development at CEN-CENELEC and has not reached the enquiry stage that parts 1-1, 1-2 and 1-3 have completed. It is not cited in the Official Journal of the European Union, so it confers no presumption of conformity. Treat it as a signal of where the requirement catalogue is heading rather than as something to build a technical file against.

What this part is for

CEN-CENELEC JTC 13 is developing the EN 40000 series under the Commission standardisation request M/606, issued by Commission Implementing Decision C(2025) 618 final and accepted by CEN, CENELEC and ETSI in April 2025. The series is horizontal, so its parts apply across every product with digital elements rather than to one product category.

Within that series, prEN 40000-1-4 is the requirement catalogue. Part 1-2 sets out the principles for cyber resilience and the risk methodology behind Annex I Part I, and 1-4 is intended to express the resulting generic security requirement areas in a form a manufacturer can work against directly and an assessor can check.

It carries no product-category detail. Requirements specific to an Annex III category sit in the vertical standards instead, which are covered on the EN 304 6xx page.

Why there is no clause mapping on this page

The page for prEN 40000-1-3 carries a clause-by-clause mapping because that part reached CEN Enquiry and its structure is public. prEN 40000-1-4 is at an earlier development phase, so no comparable public clause list exists.

Publishing invented section numbers would look authoritative and prove nothing, and anyone building a technical file on them would have to redo the work when the real text lands. This page will gain a clause mapping when there is a public draft to map.

Where it sits in the series

  • prEN 40000-1-1

    The shared vocabulary the rest of the series is written in.

  • prEN 40000-1-2

    The principles, risk methodology and lifecycle activities behind Annex I Part I.

  • prEN 40000-1-3

    The vulnerability handling process, mapping to Annex I Part II.

  • TR 40000-1-5

    A Technical Report on threats and security objectives. Informative, not normative.

The full part-by-part breakdown is on the EN 40000 series page.

What to do while it is still a draft

The Annex I Part I essential requirements are binding whether or not a standard has catalogued them, and which of them apply to your product is decided by your own risk assessment rather than by the standard. So the work that a published 1-4 would later structure is work you can do now, and it does not change shape when the catalogue arrives.

Waiting also has a specific cost. Article 32(2) sends an Annex III class I product to third-party conformity assessment precisely where the manufacturer has not applied a harmonised standard or where none exists, which is the situation today for every CRA product. Starting from Annex I directly keeps the self-assessment route open.

Questions

What does prEN 40000-1-4 cover?

It is the catalogue of generic security requirement areas that map to the essential cybersecurity requirements in CRA Annex I, Part I. Where prEN 40000-1-2 sets out the principles and the risk methodology, 1-4 is intended to be the requirement catalogue those principles produce.

Is prEN 40000-1-4 published?

No. Every part of the EN 40000 series is a draft moving through CEN and CENELEC, and none has been cited in the Official Journal of the European Union. prEN 40000-1-4 is at an earlier development phase than parts 1-1, 1-2 and 1-3, which have completed enquiry.

Does applying prEN 40000-1-4 give me presumption of conformity?

Not today. Presumption of conformity under Article 27(1) requires the reference to be cited in the Official Journal. Until that happens, applying a draft is a defensible way to structure your work but it does not carry the legal effect.

Should I wait for prEN 40000-1-4 before doing my Annex I work?

No, and waiting is expensive. Article 32(2) routes an Annex III class I product to third-party assessment precisely where the manufacturer has not applied a harmonised standard or where none exists, which is the position today. The Annex I Part I requirements are already binding regardless of whether a standard has catalogued them.

How does prEN 40000-1-4 relate to the vertical standards?

EN 40000 is horizontal, so it applies across all products with digital elements. Product-category requirements sit in the vertical standards instead, mostly ETSI's EN 304 6xx series, plus CENELEC's prEN 50764 to prEN 50766 for semiconductors and smartcards and the prEN 50770 series for operational technology.