Definition
Vulnerability handling
The Annex I Part II process requirements: identify, remediate, test, disclose, coordinate, share and update — for the whole support period.
The set of processes a manufacturer must operate for each product throughout its support period: identify and document components and vulnerabilities (SBOM), remediate without delay, test regularly, publicly disclose fixed vulnerabilities, run a coordinated vulnerability disclosure policy, share information, distribute updates securely and provide security updates free of charge. Article 13(8) ties these processes to the support period; Annex VII requires them to be described in the technical documentation.
Reference: Annex I Part II; Art. 13(8) · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.