What is the core CRA vulnerability-handling duty?
Manufacturers must ensure, when placing a product with digital elements on the market and throughout the support period, that vulnerabilities of the product, including its components, are handled effectively.
In practical terms, Article 13 and Annex I Part II require a process that can identify and document vulnerabilities, track components, remediate vulnerabilities without delay in light of the risk, test and review security regularly, run coordinated vulnerability disclosure, receive vulnerability reports, securely distribute updates, and provide security updates without delay when they are available.
Article 13(8) and Annex I Part II establish the lifecycle vulnerability-handling obligation for products and integrated components.
FAQ sections 4.1.3 and 4.3 explain that Annex I Part II vulnerability-handling requirements apply throughout the support period.