prEN 40000-1-2 Principles for Cyber Resilience

prEN 40000-1-2 is the draft horizontal standard for principles for cyber resilience. It explains the risk-based lifecycle work behind Annex I Part I, especially the requirement to design, develop, and produce products with an appropriate level of cybersecurity based on the risks.

Draft status

The local source is a draft European Standard submitted for enquiry. It should be read as a developing standard, not as a final EN and not as a harmonised standard already cited in the Official Journal.

M/606 entry 1 asks for a European standard on designing, developing, and producing products with digital elements so that they ensure an appropriate level of cybersecurity based on the risks. The M/606 deadline for that entry is 30 August 2026.

Annex I role

Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.

Regulation (EU) 2024/2847, Annex I, Part I, point (1)

prEN 40000-1-2 is closest to this general Part I requirement. It is a process and lifecycle standard. It does not replace the more specific product-security requirements in Annex I Part I points 2(a) to 2(m), and it is not the vulnerability-handling standard.

Cybersecurity principles

The draft organises its explanation around three plain ideas. They are useful because they connect legal words with engineering decisions made during product planning, design, implementation, production, and maintenance.

Risk-based approach

Security measures are selected and reviewed against product risks, intended purpose, and reasonably foreseeable use.

Security by design

Cybersecurity is built into product design and development, rather than added after the product is complete.

Secure by default

The product starts from a secure configuration that fits its intended use and operating environment.

Risk management structure

The draft treats risk management as a repeated product activity, not a one-time form. The product context comes first because the same software or hardware can create different risks in different use cases.

Lifecycle activities

The draft then turns the principles into lifecycle activities. These activities can fit different development models; the important point is that the security work is planned, performed, checked, and kept up to date.

  • product cybersecurity planning;
  • product cybersecurity requirements;
  • cybersecurity architecture and design;
  • secure implementation;
  • cybersecurity verification and validation;
  • secure production and distribution;
  • cybersecurity issue management;
  • product monitoring;
  • planning for secure decommissioning;
  • third-party component cybersecurity management.

Boundary with other standards

prEN 40000-1-2 is the principles and lifecycle risk standard. Vulnerability handling belongs to prEN 40000-1-3 Vulnerability Handling. Product-specific standards can add category-specific requirements for browsers, routers, firewalls, secure elements, and other important or critical products.

The broader standard landscape is explained in Standards and Harmonised Standards.

Sources