Annex I, Part II ยท Regulation (EU) 2024/2847

What are the CRA vulnerability handling requirements?

Verified against the Official Journal text on

Annex I, Part II lists eight vulnerability handling duties that bind manufacturers throughout the support period. You must identify and document components and vulnerabilities (including an SBOM), remediate vulnerabilities without delay through security updates, run regular security tests and reviews, disclose information about fixed vulnerabilities once an update is out, put in place and enforce a coordinated vulnerability disclosure policy, provide a contact address for reports, distribute updates securely, and disseminate security updates without delay and, as a rule, free of charge. These are ongoing process duties, not one-off tasks.

Basis: Annex I Part II (1)-(8), Art. 13(8)

Judgment call: Annex I, Part II is written as manufacturer duties and is made binding through Article 13(8), which ties effective vulnerability handling to the support period.

The eight duties, and what makes them binding Art. 13(8), Annex I Part II

The vulnerability handling requirements are not in the operative articles but in Annex I, Part II. They become binding because Article 13(8) requires manufacturers to ensure, when placing a product on the market and for the support period, that vulnerabilities in the product and its components are handled effectively and in accordance with those essential requirements. So Part II is the checklist, and Article 13(8) is the hook that gives it force and sets its duration.

Read them as a continuous programme rather than a launch gate. Every one of the eight applies across the support period, which is why the connected duties (a support period of its own, and reporting) sit close to this obligation.

Identify, remediate, test Annex I Part II (1), Annex I Part II (2), Annex I Part II (3)

The first three duties are about knowing and fixing what is in the product. Point (1): identify and document the vulnerabilities and components, including by drawing up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies. Point (2): address and remediate vulnerabilities without delay, including by providing security updates, and where technically feasible provide security updates separately from functionality updates. Point (3): apply effective and regular tests and reviews of the security of the product.

Disclose, coordinate, and receive reports Annex I Part II (4), Annex I Part II (5), Annex I Part II (6)

The next three are about how vulnerability information flows. Point (4): once a security update is available, share and publicly disclose information about the fixed vulnerabilities, including a description, affected-product information, impact, severity, and remediation guidance; in duly justified cases you may delay making that public until users have had the chance to apply the patch. Point (5): put in place and enforce a policy on coordinated vulnerability disclosure. Point (6): facilitate the sharing of information about potential vulnerabilities, including a contact address for reporting them.

Distribute updates securely and free of charge Annex I Part II (7), Annex I Part II (8)

The last two are about delivery. Point (7): provide mechanisms to securely distribute updates, so that vulnerabilities are fixed or mitigated in a timely manner and, where applicable, automatically. Point (8): ensure that available security updates are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user for a tailor-made product, free of charge, accompanied by advisory messages telling users what they need to know and any action to take.

The "free of charge" qualifier is narrow: the only carve-out is a tailor-made product where a business user has agreed otherwise. For an off-the-shelf product sold to the public, security updates during the support period are free.

What you must do

  • Identify and document components and vulnerabilities (including an SBOM), remediate without delay via security updates, and run regular security tests and reviews. (Annex I Part II (1)-(3))
  • Disclose fixed-vulnerability information once an update is available, operate a coordinated vulnerability disclosure policy, and provide a reporting contact address. (Annex I Part II (4)-(6))
  • Distribute updates securely and disseminate security updates without delay and, as a rule, free of charge, with advisory messages. (Annex I Part II (7), Annex I Part II (8))

Frequently asked

Do I have to provide security updates for free?

As a rule, yes. Security updates must be disseminated without delay and free of charge, with the only carve-out being a tailor-made product where a business user has agreed otherwise. For products sold to the public, updates during the support period are free. (Annex I Part II (8))

When do I have to publish vulnerability details?

Once a security update has been made available, you must share and publicly disclose information about the fixed vulnerability. In duly justified cases you may delay that disclosure until users have had the chance to apply the patch. (Annex I Part II (4))

Is a coordinated vulnerability disclosure policy mandatory?

Yes. Putting in place and enforcing a policy on coordinated vulnerability disclosure is one of the eight vulnerability handling duties, made binding on manufacturers through Article 13(8). (Annex I Part II (5), Art. 13(8))

How long do these duties last?

Throughout the support period. Article 13(8) requires effective vulnerability handling when the product is placed on the market and for the support period, so the eight duties are continuous, not a one-time launch checklist. (Art. 13(8))

Do these duties fall on you?

The free Vexwatch Scope Checker confirms whether you are a manufacturer under the CRA and therefore carry the vulnerability handling duties, before you build the process around them.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.