Phone: (011) 7541-421, 3409-301, 3409-335, 6547-293, 3409-310
E-mail: Standards sales: prodaja@iss.rs Education: iss-edukacija@iss.rs Information about standards: infocentar@iss.rs
Stevana Brakusa 2, 11030 Beograd
Main menu

naSRPS EN 40000-1-2:2025

Cybersecurity requirements for products with digital elements - Part 1-2: Principles, product risk management, and lifecycle activities

General information

40.60     Dec 8, 2025

ISS

I224

European Norm

35.030  

English  

Scope

This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.

Related directives

NOTE: If the word "harmonized" (marked in green) is not found in the field with the name of the directive, it means that the European standard is not cited in the OJEU.

2024/2847

Life cycle

NOW

PROJECT
naSRPS EN 40000-1-2:2025
40.60 Close of voting
Dec 8, 2025

Related project

Adopted from prEN 40000-1-2 IDENTICAL

Adopted from prEN 40000-1-2 IDENTICAL