prEN 40000-1-2 Principles for Cyber Resilience
prEN 40000-1-2 is the draft horizontal standard for principles for cyber resilience. It explains the risk-based lifecycle work behind Annex I Part I, especially the requirement to design, develop, and produce products with an appropriate level of cybersecurity based on the risks.
Draft status
The local source is a draft European Standard submitted for enquiry. It should be read as a developing standard, not as a final EN and not as a harmonised standard already cited in the Official Journal.
M/606 entry 1 asks for a European standard on designing, developing, and producing products with digital elements so that they ensure an appropriate level of cybersecurity based on the risks. The M/606 deadline for that entry is 30 August 2026.
Annex I role
Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.
Regulation (EU) 2024/2847, Annex I, Part I, point (1)
prEN 40000-1-2 is closest to this general Part I requirement. It is a process and lifecycle standard. It does not replace the more specific product-security requirements in Annex I Part I points 2(a) to 2(m), and it is not the vulnerability-handling standard.
Cybersecurity principles
The draft organises its explanation around three plain ideas. They are useful because they connect legal words with engineering decisions made during product planning, design, implementation, production, and maintenance.
Risk-based approach
Security measures are selected and reviewed against product risks, intended purpose, and reasonably foreseeable use.
Security by design
Cybersecurity is built into product design and development, rather than added after the product is complete.
Secure by default
The product starts from a secure configuration that fits its intended use and operating environment.
Risk management structure
The draft treats risk management as a repeated product activity, not a one-time form. The product context comes first because the same software or hardware can create different risks in different use cases.
The context describes the product, intended purpose, expected users, operating environment, assets, interfaces, dependencies, and lifecycle assumptions.
The method defines how risks are identified, estimated, evaluated, treated, accepted, communicated, monitored, and recorded.
The assessment identifies assets, cybersecurity objectives, threats, and risk levels. Treatment then selects measures and residual-risk decisions.
Risk work continues when the product, threat environment, components, support assumptions, or deployment context changes.
Lifecycle activities
The draft then turns the principles into lifecycle activities. These activities can fit different development models; the important point is that the security work is planned, performed, checked, and kept up to date.
- product cybersecurity planning;
- product cybersecurity requirements;
- cybersecurity architecture and design;
- secure implementation;
- cybersecurity verification and validation;
- secure production and distribution;
- cybersecurity issue management;
- product monitoring;
- planning for secure decommissioning;
- third-party component cybersecurity management.
Boundary with other standards
prEN 40000-1-2 is the principles and lifecycle risk standard. Vulnerability handling belongs to prEN 40000-1-3 Vulnerability Handling. Product-specific standards can add category-specific requirements for browsers, routers, firewalls, secure elements, and other important or critical products.
The broader standard landscape is explained in Standards and Harmonised Standards.