Vulnerability Handling Records

Vulnerability handling records show how the manufacturer finds, documents, assesses, remediates, discloses, and communicates vulnerabilities during the support period.

Process duty

Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.

Regulation (EU) 2024/2847, Article 13(8)

The duty starts when the product is placed on the market and continues during the support period. It covers the product and its components.

Main record types

Annex VII link

Annex VII asks the technical documentation to include necessary information and specifications for the vulnerability-handling processes, including the SBOM, the coordinated vulnerability disclosure policy, the reporting contact, and secure update distribution.

  • records that support the product's vulnerability history;
  • records that explain how vulnerabilities are triaged and fixed;
  • records that show update distribution and user communication;
  • test and review reports that support conformity assessment.

The draft prEN 40000-1-3 page explains the current vulnerability-handling standard draft in more detail.

Records are not the report trigger

These records support vulnerability handling. Article 14 reporting is a separate duty triggered by actively exploited vulnerabilities and severe product-security incidents.

Sources