Vulnerability Handling Records
Vulnerability handling records show how the manufacturer finds, documents, assesses, remediates, discloses, and communicates vulnerabilities during the support period.
Process duty
Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.
Regulation (EU) 2024/2847, Article 13(8)
The duty starts when the product is placed on the market and continues during the support period. It covers the product and its components.
Main record types
Annex I requires the manufacturer to identify and document vulnerabilities and components, including an SBOM covering at least top-level dependencies.
Records should show how vulnerabilities were assessed, addressed, remediated, and distributed through security updates when needed.
Annex I requires a coordinated vulnerability disclosure policy. Annex VII asks for the policy and evidence of the contact address for vulnerability reports.
Annex I requires effective and regular tests and reviews of product security. Annex VII asks for reports of tests carried out to verify product and process conformity.
Annex VII link
Annex VII asks the technical documentation to include necessary information and specifications for the vulnerability-handling processes, including the SBOM, the coordinated vulnerability disclosure policy, the reporting contact, and secure update distribution.
- records that support the product's vulnerability history;
- records that explain how vulnerabilities are triaged and fixed;
- records that show update distribution and user communication;
- test and review reports that support conformity assessment.
The draft prEN 40000-1-3 page explains the current vulnerability-handling standard draft in more detail.
Records are not the report trigger
These records support vulnerability handling. Article 14 reporting is a separate duty triggered by actively exploited vulnerabilities and severe product-security incidents.