What is the core CRA vulnerability-handling duty?
Manufacturers must ensure, when placing a product with digital elements on the market and throughout the , that vulnerabilities of the product, including its components, are handled effectively.
In practical terms, Article 13 and Annex I Part II require a process that can identify and document vulnerabilities, track components, remediate vulnerabilities without delay in light of the risk, test and review security regularly, run , receive vulnerability reports, securely distribute updates, and provide security updates without delay when they are available.
Article 13(8) and Annex I Part II establish the lifecycle vulnerability-handling obligation for products and integrated components.
FAQ sections 4.1.3 and 4.3 explain that Annex I Part II vulnerability-handling requirements apply throughout the support period.