Cyber Resilience Act · Annex I Part II

Essential cybersecurity requirements: vulnerability handling

Binds
manufacturer
Applies from
Evidence
process

Annex I Part II (1)

manufacturer · Annex I Part II (1)

identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products;

How to satisfy it: The most automatable row in the corpus and the natural bridge from CI evidence. Top-level dependencies are the floor, not the target.

Annex I Part II (1) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (2)

manufacturer · Annex I Part II (2)

in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;

How to satisfy it: Separating security updates from functionality updates where technically feasible is an explicit design requirement, not a release-process preference.

Annex I Part II (2) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (3)

manufacturer · Annex I Part II (3)

apply effective and regular tests and reviews of the security of the product with digital elements;

How to satisfy it: 'Regular' means a cadence you can evidence. Record dates and scope rather than describing a practice.

Annex I Part II (3) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (4)

manufacturer · Annex I Part II (4)

once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;

How to satisfy it: The delay is permitted but conditional on the security risks of publication outweighing the benefits. Record the justification whenever it is used.

Annex I Part II (4) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (5)

manufacturer · Annex I Part II (5)

put in place and enforce a policy on coordinated vulnerability disclosure;

How to satisfy it: One of the cheapest rows to satisfy and one of the most visible to a customer doing diligence.

Annex I Part II (5) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (6)

manufacturer · Annex I Part II (6)

take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements;

How to satisfy it: Covers third-party components too. A monitored contact address is the minimum artifact and is trivially verifiable by an outsider.

Annex I Part II (6) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (7)

manufacturer · Annex I Part II (7)

provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner;

How to satisfy it: Signing and integrity of the update channel is the substance here.

Annex I Part II (7) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Annex I Part II (8)

manufacturer · Annex I Part II (8)

ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.

How to satisfy it: Free of charge is the default and the tailor-made exception is narrow. Advisory messages are part of the obligation.

Annex I Part II (8) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847

Every quoted requirement on this page is verbatim Official Journal text. The surrounding guidance is Legalithm’s commentary and is not regulation. This page states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.