prEN 40000-1-3 Vulnerability Handling

prEN 40000-1-3 is the draft horizontal standard for vulnerability handling. It supports Annex I Part II by turning vulnerability intake, verification, remediation, release, and post-release work into a structured manufacturer process.

Draft status

The local source is a draft European Standard submitted to CEN enquiry. It is useful for planning vulnerability-handling capability, but it should not be described as a final EN or as a cited harmonised standard unless that status is verified.

M/606 entry 15 asks for European standards on vulnerability handling for products with digital elements. The M/606 deadline for that entry is 30 August 2026.

Annex I Part II role

Annex I Part II is about the manufacturer's process. It covers finding and documenting vulnerabilities, component visibility, remediation, testing, disclosure, update distribution, and user information after a security update is available.

prEN 40000-1-3 is designed around that process. It does not decide whether Article 14 reporting is triggered. Article 14 reporting is a separate legal duty for actively exploited vulnerabilities and severe incidents affecting product security.

Vulnerability-handling process

The draft uses a lifecycle model. The process starts before a report arrives, because the manufacturer needs policies, contact routes, component information, and update mechanisms in place.

1
Preparation
Before reports

Policies, disclosure routes, secure communication, product identification, component information, test planning, and update distribution are prepared.

2
Receipt
Report intake

The manufacturer receives reports and monitors internal and external sources for vulnerabilities affecting the product or its components.

3
Verification
Triage

The manufacturer checks whether the report is valid, whether the product is affected, and how severe the vulnerability is.

4
Remediation
Fix or mitigation

The manufacturer decides on remediation, develops the fix or mitigation, and tests it before release.

5
Release and post-release
User action

The manufacturer releases the security update, publishes clear information, monitors effectiveness, and improves the process.

Building blocks

The draft builds on existing vulnerability standards. It uses vulnerability disclosure, vulnerability handling, and multi-party coordinated disclosure concepts, then adapts them for products with digital elements and the CRA support-period model.

Disclosure policy

A public route tells researchers and users how to report a potential vulnerability.

Component visibility

Software and hardware component information supports impact analysis when a vulnerability is found.

Update release

Secure update distribution and clear advisory information connect remediation with user action.

Extra controls from risk

The draft includes requirement enhancements. These are additional measures that apply when the product risk assessment shows that more rigour is needed.

Boundary with reporting

Vulnerability handling is the continuing product process. Article 14 reporting is a separate notification duty when the legal trigger is met. A vulnerability may be handled under the process without being reportable under Article 14, and a reportable vulnerability still needs the handling process to remediate and communicate it.

  • Use prEN 40000-1-3 thinking for the vulnerability-handling process.
  • Use Article 14 analysis for actively exploited vulnerabilities and severe incidents affecting product security.
  • Use the support-period page for how long vulnerability handling must continue.

The Article 14 trigger is explained in Vulnerability Reporting.

Sources