← Back to blogEN 40000 Europe’s new cybersecurity standard for CRA products with digital elements

    EN 40000 Europe’s new cybersecurity standard for CRA products with digital elements

    6/29/2026 · By Conny Broberg

    EN 40000: Your guide to the new standard for the Cyber Resilience Act (CRA)

    The Cyber Resilience Act (Regulation (EU) 2024/2847) is now a reality. It is the legislation that sets mandatory security requirements for virtually all products with digital elements sold within the EU. From connected consumer gadgets to advanced industrial software – CRA requires manufacturers to build in security from the start and maintain it throughout the product's lifecycle.

    However, a regulation rarely tells you how to practically implement it. This is where the harmonised standards come in, and most important of all is the new EN 40000 series.

    Why EN 40000 is crucial now

    The EN 40000 series is being developed to directly support CRA compliance. Once these standards are cited in the Official Journal of the EU (OJEU), it means that companies following them will gain a "presumption of conformity." Simply put: following EN 40000 is the most straightforward and predictable way to demonstrate that your product meets the legal requirements.

    The entire series is currently under development and is expected to be fully completed before the CRA becomes fully applicable on December 11, 2027. However, given the extensive requirements, manufacturers should not wait for completion before beginning their preparatory work.

    The EN 40000 family at a glance

    The series consists of five parts that together cover all aspects of product security:

    1. EN 40000-1-1 (Vocabulary): Common definitions to avoid misunderstandings regarding terms such as "risk," "vulnerability," and "asset."
    2. EN 40000-1-2 (Principles for Cyber Resilience): The very heart of the series, defining risk management methodology and lifecycle activities.
    3. EN 40000-1-3 (Vulnerability Management): Requirements on how to handle vulnerabilities – from detection to patching.
    4. EN 40000-1-4 (Generic Security Requirements): A catalogue of technical requirements that map directly to Annex I of the CRA.
    5. TR 40000-1-5 (Threats and Security Objectives): A technical report that assists in risk analysis by mapping threats to specific objectives.

    Core Principles: Security by Design

    EN 40000-1-2 establishes four fundamental principles:

    • Risk-based approach: Security measures should be proportionate to the risk. A connected pacemaker requires more protection than a smart light bulb.
    • Security by Design: Security must be integrated from the earliest development stages, not added as an afterthought.
    • Secure by Default: Products should be secure right out of the box (no default passwords or unnecessary open ports).
    • Transparency: Manufacturers must be open about the product's security features and limitations.

    The standard also defines ten lifecycle activities, where the management of third-party components and the requirement for a Software Bill of Materials (SBOM) are expected to be the most resource-intensive for many companies.

    Vulnerability Management: A legal requirement, not a choice

    EN 40000-1-3 makes it clear that vulnerability management is a mandatory part of product responsibility. Already from September 2026, manufacturers must report actively exploited vulnerabilities to national authorities within 24 hours. The standard requires a robust process for:

    • Receiving reports (Coordinated Vulnerability Disclosure).
    • Verification and risk assessment.
    • Remediation (patches and security updates).
    • Distribution of fixes to end-users.

    What do you need to do now?

    Even though the standards are still in draft format, the direction is clear. Here are iThing's recommendations to stay ahead:

    1. Perform a gap analysis: Map your current development processes against the ten activities in EN 40000-1-2.
    2. Build up your SBOM capability: Knowing exactly what software is in your products is fundamental for CRA compliance.
    3. Establish vulnerability management: Don't wait until late 2026 to set up processes for receiving and acting on vulnerability reports.
    4. Document: Start building the technical documentation required to demonstrate conformity.

    Does your organisation need help navigating the new regulatory framework? At iThing AB, we support companies in implementing secure development processes and ensuring that tomorrow's products meet today's requirements.

    Contact us for a no-obligation discussion on how EN 40000 affects your business.