What does the CRA require manufacturers to do for vulnerability handling over the product lifecycle?
Annex I Part II requires manufacturers to:
- identify and document vulnerabilities and components, including a software bill of materials
- address and remediate vulnerabilities without delay, including through security updates
- apply effective and regular security tests and reviews
- disclose information about fixed vulnerabilities once a security update is available, subject to a limited justified delay option
- enforce a coordinated vulnerability disclosure policy
- facilitate vulnerability reporting, including for third-party components in the product
- provide secure update-distribution mechanisms and, where applicable, automatic security updates
- disseminate security updates without delay and, unless the tailor-made exception applies, free of charge
Article 13(6)-(11), Annex I Part II