Topic
Vulnerability handling
The Part II process duties, translated into an operating rhythm.
Annex I Part II is a process specification F-018: identify and document vulnerabilities and components F-019, remediate them without delay including through security updates, test security regularly, run a coordinated vulnerability disclosure policy with a contact address F-043, provide a single point of contact for reporters and users F-042, disclose fixed vulnerabilities once an update is available F-044, and distribute security updates securely and free of charge F-045.
The operating rhythm
Prompt triage of the intake F-042, a disclosure template keyed to the fix-available moment F-044, and an update channel you would trust with your own machine F-045 — with regular testing and remediation without delay, that is the core discipline, run for the support period F-018.
Verified facts this page relies on
- F-018 Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8). Annex I Part II
- F-042 The manufacturer provides a single point of contact for users to report vulnerabilities and to receive information about vulnerabilities. Art. 13(17), Annex I Part II(6)
- F-043 Manufacturers have a coordinated vulnerability disclosure policy in place and a contact address for reporting. Annex I Part II(5)–(6)
- F-044 Manufacturers publicly disclose information about fixed vulnerabilities after a security update is available, including a description, affected products, impacts, severity and remediation information. Annex I Part II(4)
- F-045 Manufacturers ensure secure distribution of updates and that security updates are provided free of charge, in a timely manner, with advisory messages. Annex I Part II(7)–(8)
- F-019 Manufacturers identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used machine-readable format covering at the very least the top-level dependencies. Annex I Part II(1), Art. 13(8), (24)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Annex I — Essential cybersecurity requirements
- Topic: Coordinated vulnerability disclosure
- Topic: Software bill of materials (SBOM)