InsideCRA
InsideCRA › Topics › Vulnerability handling

Topic

Vulnerability handling

The Part II process duties, translated into an operating rhythm.

Annex I Part II is a process specification F-018: identify and document vulnerabilities and components F-019, remediate them without delay including through security updates, test security regularly, run a coordinated vulnerability disclosure policy with a contact address F-043, provide a single point of contact for reporters and users F-042, disclose fixed vulnerabilities once an update is available F-044, and distribute security updates securely and free of charge F-045.

The operating rhythm

Prompt triage of the intake F-042, a disclosure template keyed to the fix-available moment F-044, and an update channel you would trust with your own machine F-045 — with regular testing and remediation without delay, that is the core discipline, run for the support period F-018.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Ready to work through your obligations? Get your CE readiness verdict on CEMarque.