Vulnerability handling is an ongoing manufacturer responsibility. Annex I Part II addresses effective handling over the support period; Article 14 sets notification duties for specified exploited vulnerabilities and severe incidents.
Check Article 14 separately for notification triggers and timing.
A practical response loop
Use this as an operational model, not a verbatim legal sequence.
- Receive and record reports, including third-party component issues.
- Assess impact, exploitability and affected versions.
- Develop and verify a correction.
- Coordinate disclosure and distribute security updates.
- Document decisions and revisit product risk.
Separate reporting from disclosure
From 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents affecting product security under Article 14. The Commission describes an early warning within 24 hours and a main notification within 72 hours of awareness, with distinct final-report rules. Check the full legal conditions and the Single Reporting Platform before acting.
Make support visible
The manufacturer determines a support period and communicates its end date at purchase. Vulnerability processes and updates should be planned across that period.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.