The eight duties, and what makes them binding Art. 13(8), Annex I Part II
The vulnerability handling requirements are not in the operative articles but in Annex I, Part II. They become binding because Article 13(8) requires manufacturers to ensure, when placing a product on the market and for the support period, that vulnerabilities in the product and its components are handled effectively and in accordance with those essential requirements. So Part II is the checklist, and Article 13(8) is the hook that gives it force and sets its duration.
Read them as a continuous programme rather than a launch gate. Every one of the eight applies across the support period, which is why the connected duties (a support period of its own, and reporting) sit close to this obligation.
Identify, remediate, test Annex I Part II (1), Annex I Part II (2), Annex I Part II (3)
The first three duties are about knowing and fixing what is in the product. Point (1): identify and document the vulnerabilities and components, including by drawing up an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies. Point (2): address and remediate vulnerabilities without delay, including by providing security updates, and where technically feasible provide security updates separately from functionality updates. Point (3): apply effective and regular tests and reviews of the security of the product.
Disclose, coordinate, and receive reports Annex I Part II (4), Annex I Part II (5), Annex I Part II (6)
The next three are about how vulnerability information flows. Point (4): once a security update is available, share and publicly disclose information about the fixed vulnerabilities, including a description, affected-product information, impact, severity, and remediation guidance; in duly justified cases you may delay making that public until users have had the chance to apply the patch. Point (5): put in place and enforce a policy on coordinated vulnerability disclosure. Point (6): facilitate the sharing of information about potential vulnerabilities, including a contact address for reporting them.
Distribute updates securely and free of charge Annex I Part II (7), Annex I Part II (8)
The last two are about delivery. Point (7): provide mechanisms to securely distribute updates, so that vulnerabilities are fixed or mitigated in a timely manner and, where applicable, automatically. Point (8): ensure that available security updates are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user for a tailor-made product, free of charge, accompanied by advisory messages telling users what they need to know and any action to take.
The "free of charge" qualifier is narrow: the only carve-out is a tailor-made product where a business user has agreed otherwise. For an off-the-shelf product sold to the public, security updates during the support period are free.