prEN 40000-1-3 Vulnerability Handling
prEN 40000-1-3 is the draft horizontal standard for vulnerability handling. It supports Annex I Part II by turning vulnerability intake, verification, remediation, release, and post-release work into a structured manufacturer process.
Draft status
The local source is a draft European Standard submitted to CEN enquiry. It is useful for planning vulnerability-handling capability, but it should not be described as a final EN or as a cited harmonised standard unless that status is verified.
M/606 entry 15 asks for European standards on vulnerability handling for products with digital elements. The M/606 deadline for that entry is 30 August 2026.
Annex I Part II role
Annex I Part II is about the manufacturer's process. It covers finding and documenting vulnerabilities, component visibility, remediation, testing, disclosure, update distribution, and user information after a security update is available.
prEN 40000-1-3 is designed around that process. It does not decide whether Article 14 reporting is triggered. Article 14 reporting is a separate legal duty for actively exploited vulnerabilities and severe incidents affecting product security.
Vulnerability-handling process
The draft uses a lifecycle model. The process starts before a report arrives, because the manufacturer needs policies, contact routes, component information, and update mechanisms in place.
Policies, disclosure routes, secure communication, product identification, component information, test planning, and update distribution are prepared.
The manufacturer receives reports and monitors internal and external sources for vulnerabilities affecting the product or its components.
The manufacturer checks whether the report is valid, whether the product is affected, and how severe the vulnerability is.
The manufacturer decides on remediation, develops the fix or mitigation, and tests it before release.
The manufacturer releases the security update, publishes clear information, monitors effectiveness, and improves the process.
Building blocks
The draft builds on existing vulnerability standards. It uses vulnerability disclosure, vulnerability handling, and multi-party coordinated disclosure concepts, then adapts them for products with digital elements and the CRA support-period model.
Disclosure policy
A public route tells researchers and users how to report a potential vulnerability.
Component visibility
Software and hardware component information supports impact analysis when a vulnerability is found.
Update release
Secure update distribution and clear advisory information connect remediation with user action.
Extra controls from risk
The draft includes requirement enhancements. These are additional measures that apply when the product risk assessment shows that more rigour is needed.
Higher-risk products may need stronger controls for how vulnerability information is exchanged with reporters, coordinators, upstream suppliers, or affected users.
The level of component detail can increase when the product risk justifies faster or more precise vulnerability impact analysis.
Hashes can help identify exactly which software component version is present when names and version strings are not enough.
Structured advisories can help customers and downstream operators process vulnerability information at scale.
Boundary with reporting
Vulnerability handling is the continuing product process. Article 14 reporting is a separate notification duty when the legal trigger is met. A vulnerability may be handled under the process without being reportable under Article 14, and a reportable vulnerability still needs the handling process to remediate and communicate it.
- Use prEN 40000-1-3 thinking for the vulnerability-handling process.
- Use Article 14 analysis for actively exploited vulnerabilities and severe incidents affecting product security.
- Use the support-period page for how long vulnerability handling must continue.
The Article 14 trigger is explained in Vulnerability Reporting.