EN 40000-1-1 is the vocabulary document in the cybersecurity standards family for products with digital elements. Its practical role is to give the people writing, reviewing and using product-security documentation a shared reference for terminology. If your engineers, suppliers and compliance team use the same words differently, this is the part to examine before building a larger documentation set.
Document status checked: 7 October 2026. Genorma’s offer uses the catalogue reference EN 40000-1-1:2026 but currently labels the document Draft / In development. The year in the reference does not establish that a final European Standard has been published. Check the current document status before ordering.
Get the EN 40000-1-1 vocabulary document
For a team preparing EN 40000 documentation, this is the terminology companion. Check the offered draft, language, licence and current price on Genorma.
Check draft and price on Genorma
Choosing between parts? Compare the EN 40000 cybersecurity documents.
What does EN 40000-1-1 cover?
The NEN catalogue description identifies its purpose as common terminology for this standards family and lists the document as under development. It is a vocabulary part, so its principal value is consistency when reading related documents and preparing technical material.
It should not be treated as a complete cybersecurity implementation plan, a product test specification or proof of regulatory conformity. A team that needs a structured approach to product risk and lifecycle work should examine EN 40000-1-2. A team organising how it receives, evaluates and responds to vulnerabilities should examine prEN 40000-1-3.
Who is most likely to benefit?
The strongest reason to obtain Part 1-1 is to reduce ambiguity between people who contribute to the same product file. This can be useful for a product-security lead reviewing supplier material, a technical writer creating reusable templates, or a compliance manager checking that several product teams describe their work consistently. These are practical uses, rather than claims that the document requires a particular organisational structure.
| Your immediate task | Best starting point |
|---|---|
| Align terminology across specifications and supplier documents | Part 1-1: vocabulary |
| Organise product cybersecurity risk and lifecycle activities | Part 1-2: principles for cyber resilience |
| Develop a process for receiving and handling vulnerabilities | Part 1-3: vulnerability handling |
| Select detailed requirements for a particular product category | Investigate the relevant product-specific documents as well |
A practical way to use the vocabulary
Start with the documents your organisation already produces. List the terms that appear in product requirements, risk records, supplier questionnaires and customer guidance. Ask the owners where definitions differ, then consult the purchased document before agreeing a controlled glossary. Record which document and version each definition comes from.
Keep the glossary connected to your templates. A terminology decision that exists only in a meeting note will be difficult to apply when another supplier joins the project. Avoid copying an entire copyrighted vocabulary into a public website or unrestricted shared folder; check the licence for the intended number of users.
Illustrative example: a fictional connected-sensor manufacturer receives three supplier questionnaires written by different teams. Before expanding them into a common assessment form, its security lead uses a controlled terminology reference to identify inconsistent wording. The example shows a documentation workflow, not a requirement or an interpretation of any particular definition.
Check these details before you purchase
Confirm the exact reference, draft status, language and permitted use on the merchant page. If you need an approved final edition for a contract, ask whether the offered document satisfies that request. Where your team already owns a national adoption, compare the underlying European text and edition before buying another copy. Access to a draft should not be assumed to include a later final edition.
Questions buyers ask
Is EN 40000-1-1:2026 already a final standard?
Not on the Genorma offer checked for this guide: it was labelled Draft and In development on 7 October 2026. Verify the live status when you order.
Will buying the vocabulary make my product CRA compliant?
No. Common terminology can support clear documentation, but compliance depends on applicable legal obligations and the product’s actual evidence. Purchasing a document does not demonstrate those obligations have been met.
Should I obtain this before Part 1-2?
It is a useful companion when your team is working across the series. If your immediate need is product risk and lifecycle planning, review Part 1-2’s scope first and decide who also needs the vocabulary.
Related reading: EN 40000 series comparison and the European Commission’s Cyber Resilience Act overview. This guide explains document selection; it does not reproduce the normative text.