Topic
Security updates
Free, timely, and — for consumer products — installed automatically by default.
The update rules are where Annex I gets concrete. Security updates are provided free of charge, in a timely manner, distributed securely, and accompanied by advisory messages F-045. For consumer products they install automatically by default, with a clear and easy opt-out F-041.
The design consequences
Automatic-by-default is an architecture decision, not a settings toggle: it needs an update channel, integrity protection on that channel, and rollback thinking F-041 F-045. Products are also made available without known exploitable vulnerabilities and secure by default in the first place — updates maintain that state rather than create it F-040.
The disclosure pairing
Once a fix ships, information about the fixed vulnerability is disclosed publicly — description, affected products, impact F-044. Update engineering and disclosure policy are one workflow seen from two sides F-044 F-045.
Verified facts this page relies on
- F-041 Security updates are installed automatically by default for consumer products, with a clear and easy-to-use opt-out mechanism. Annex I Part I(2)(c), Recital 56
- F-045 Manufacturers ensure secure distribution of updates and that security updates are provided free of charge, in a timely manner, with advisory messages. Annex I Part II(7)–(8)
- F-040 Products are made available without known exploitable vulnerabilities and with a secure-by-default configuration. Annex I Part I(2)(a)–(b)
- F-044 Manufacturers publicly disclose information about fixed vulnerabilities after a security update is available, including a description, affected products, impacts, severity and remediation information. Annex I Part II(4)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Annex I — Essential cybersecurity requirements
- Topic: Support period
- Topic: Secure by design and default
- Topic: Vulnerability handling