How are third-party component vulnerabilities handled?
If an actively exploited vulnerability in an integrated component is contained in the finished product, the finished-product manufacturer must notify it under Article 14 when aware of it. If the component manufacturer placed that component on the market separately, it may have its own Article 14 duty as well.
If the manufacturer knows the integrated component has a vulnerability but that vulnerability cannot be exploited in the finished product, the Commission FAQ says it is not an actively exploited vulnerability in that finished product for mandatory Article 14 reporting. Voluntary Article 15 reporting may still be used, and Article 13(6) can require upstream reporting to the person or entity manufacturing or maintaining the component.
Section 5.4 explains Article 14 reporting for actively exploited vulnerabilities originating in integrated components and the non-exploitable-component limit.
Article 14(1), Article 15, and Article 13(6) support mandatory reporting, voluntary reporting, and upstream component reporting.