Draft status checked: 7 October 2026. The linked Genorma offer is prEN 40000-1-3, labelled Draft and In development. This guide does not link to an assumed final EN 40000-1-3:2026 edition.
prEN 40000-1-3 addresses vulnerability handling for manufacturers of products with digital elements. It is relevant when your team needs to connect security reports with technical investigation, remediation and communication to users.
The buying question is practical: do you need a focused document for reviewing that process? If the immediate task is to improve your product security response, Part 1-3 is a closer match than a vocabulary reference or a general product planning document.
Check the current Part 1-3 draft
Genorma offers prEN 40000-1-3 as a draft. Review the document status, language, licence and current price before purchasing.
Check prEN 40000-1-3 draft and price on Genorma
This is the direct product page for the draft discussed here.
What work does Part 1-3 support?
Genorma’s scope description addresses manufacturers’ vulnerability processes across product categories. It includes component information, remediation, security testing, coordinated disclosure and secure delivery of updates. Use the actual document to assess its detailed provisions; this page offers an independent explanation of the buying decision.
The natural readers are product security incident response teams, often called PSIRTs, and the engineers, support staff and release managers who work with them. A company without a formal PSIRT can still identify the people responsible for these tasks before reviewing the document.
A useful review starts with the handovers
Our recommended preparation is to map one vulnerability case from arrival to closure. This makes your document review specific: you can examine how the proposed process compares with the steps your organisation actually follows.
- Receiving the report: identify where a researcher, supplier or customer would send it, who monitors that route and how an acknowledgement is issued.
- Establishing impact: identify the affected product versions and who can determine whether the reported behaviour is reproducible.
- Deciding the response: record who approves the engineering work, temporary mitigation and customer advice.
- Releasing and communicating: connect the fix with the appropriate update route and the information customers need to act.
- Closing the case: retain the decision trail, confirm the release details and feed relevant lessons back to product planning.
This checklist is an original review aid, not a list of mandatory clauses from the draft. Bring your current process and a sample case to the reading session, then record gaps against the licensed document.
Vulnerability handling and CRA reporting are different tasks
The European Commission’s reporting guidance says manufacturers’ CRA reporting obligations have applied since 11 September 2026. They concern actively exploited vulnerabilities and severe incidents affecting product security. The guidance describes a 24-hour early warning and a 72-hour notification, with later reporting stages depending on the event.
A vulnerability report from a researcher does not automatically establish that exploitation is active. Your internal process needs an escalation decision based on the facts, while technical work and communication continue. Reading Part 1-3 should support a wider process review; it does not replace the legal assessment of a reporting trigger or a submission through the CRA Single Reporting Platform.
Full CRA application is 11 December 2027, according to the Commission’s implementation timeline. Keep present reporting responsibilities and preparation for the broader regime clearly identified in your work plan.
Example: a component issue in connected equipment
Imagine a supplier reports a weakness in a component used by several versions of your device. Before a customer notice can be useful, your team needs to establish which releases contain it, what the practical exposure is and what action is available.
For a review workshop, ask who can answer each question, where the evidence is kept and who can approve an update. Then test whether support staff can explain the affected versions and the recommended customer action. This is an illustrative scenario, not a claim that purchasing the draft will deliver a compliant process.
Choose Part 1-3 alongside the right companion
Part 1-2 is the companion for general cybersecurity principles, product risk management and lifecycle planning. Part 1-1 supports consistent terminology. Use our EN 40000 comparison to choose by the work your team needs to perform.
Draft edition and purchase questions
Can I buy the final EN 40000-1-3 edition here?
The purchase route currently verified here is the prEN draft. BSI also lists a draft Part 1-3 document. Check the live Genorma listing for any subsequent final edition before ordering.
Does using the draft establish CRA conformity?
No such conclusion follows from the purchase. The Commission’s CRA standardisation information distinguishes horizontal work from product-specific standards. Check the applicable final documents and Official Journal references when assessing a conformity route.