Skip to content

Independent standards discovery and compliance platform

How we work

EN 40000 Cybersecurity Standards: Which Document Do You Need?

Document status checked: 7 October 2026. Genorma currently labels all three buying options Draft and In development, including the entries headed EN 40000-1-1:2026 and EN 40000-1-2:2026. Check the status shown on the product page before ordering.

EN 40000 cybersecurity standards address different questions for teams making products with digital elements: which terms to use, how to organise product cybersecurity, and how to handle vulnerabilities. Choosing the right document starts with the decision your team needs to make.

This comparison helps manufacturers, software developers, product security teams and compliance leads choose between Parts 1-1, 1-2 and 1-3. Our practical recommendations below are buying guidance, rather than a substitute for the documents.

Planning product cybersecurity? Start with Part 1-2

For a team reviewing cybersecurity across design, development and product support, Part 1-2 is the broadest starting point of these three documents. Add Part 1-1 for terminology and Part 1-3 for a focused vulnerability-handling review.

Check Part 1-2 draft and price on Genorma

Compare the current edition, language, licence and purchase options before checkout.

Compare the three EN 40000 documents

Part 1-1 · Shared terminology

EN 40000-1-1: Vocabulary

Useful when engineering, legal, procurement and suppliers need to use cybersecurity terms consistently. Genorma lists this document as EN 40000-1-1:2026, with a Draft buying status.

Read the Part 1-1 buying guide

Check Part 1-1 draft and price

Part 1-2 · Product planning

EN 40000-1-2: Principles and lifecycle

Covers general cybersecurity principles, product risk management and lifecycle activities. A practical starting point for product-wide planning. Genorma currently shows Draft for its EN 40000-1-2:2026 entry.

Read the Part 1-2 buying guide

Check Part 1-2 draft and price

Part 1-3 · Product security response

prEN 40000-1-3: Vulnerability handling

Focuses on the manufacturer’s vulnerability-handling processes. Consider it when reviewing how reports become fixes and user communications. The linked Genorma offer is explicitly a draft.

Read the Part 1-3 buying guide

Check Part 1-3 draft and price

Choose by the work on your desk

  • Preparing a product cybersecurity plan: review Part 1-2 first. List the product, relevant lifecycle stages and decisions the team needs to document before assigning the review.
  • Agreeing wording with suppliers: use Part 1-1 as a terminology reference alongside the substantive document relevant to the work. A vocabulary document alone will not design your security process.
  • Improving vulnerability response: review Part 1-3 with the people responsible for incoming reports, engineering fixes, release approval and customer support.

For example, a connected-equipment manufacturer planning a new release might assign Part 1-2 to its product lead and Part 1-3 to its security response team. Purchasing Part 1-1 can help those teams keep their shared terminology consistent. This is an illustrative allocation, not a requirement to buy a three-document bundle.

Why the Cyber Resilience Act makes the timing relevant

The European Commission’s CRA implementation timeline distinguishes two milestones: reporting obligations began on 11 September 2026, while full application is 11 December 2027. Treat these as separate workstreams in your programme.

The Commission’s reporting guidance concerns actively exploited vulnerabilities and severe security incidents. A broader vulnerability process also needs to address reports that do not meet those reporting triggers.

The CRA standardisation programme includes horizontal and product-specific work. These three documents should therefore be evaluated alongside the standards relevant to your particular product. Buying or applying a draft does not by itself demonstrate CRA conformity. Check final publication and the relevant Official Journal references before relying on any presumption of conformity.

Before you order

Confirm the exact reference and draft or final status, then check the offered language and licence. Decide who will read it and whether your intended use requires access for several people. Keep a record of the edition used in your review so that later changes can be assessed.

For the wider selection, browse the EN 40000-1 series on Genorma. The document-specific buttons above take you directly to the three offers compared here.

Common buying questions

Do I need all three documents?

That depends on your work. Start with the document matching the decision you need to make. The other parts can support adjacent tasks, but this guide does not assume a mandatory package purchase.

Does the 2026 label mean the offer is a final standard?

Use the current buying and lifecycle status on Genorma, rather than the year in the page heading alone. At our check, all three offers were labelled Draft and In development.

For broader regulatory planning, see our EU compliance and CRA preparation guide or browse the standards buying guides.