Vulnerability handling under the CRA
Annex I Part II of the Cyber Resilience Act requires manufacturers to identify, document and remediate vulnerabilities without delay for the whole support period. It also requires regular security testing, a coordinated vulnerability disclosure policy, a contact address and secure distribution of updates.
Last updated:
The Annex I Part II requirements
- Identify and document vulnerabilities and components, including an SBOM.
- Remediate without delay, including by providing security updates, separately from functional updates where technically feasible.
- Test regularly: apply effective and regular tests and reviews of the product's security.
- Disclose fixed vulnerabilities once an update is available: description, affected products, impact, severity and remediation guidance.
- Coordinated vulnerability disclosure (CVD) policy: put one in place and enforce it.
- Contact address: make it easy to report vulnerabilities in your product and its components.
- Secure updates: distribute them securely and, where applicable, automatically, free of charge, with advisory messages.
Triage by exploitability
Not every CVE in a dependency affects your product. Effective triage checks whether the vulnerable code is reachable, whether the configuration exposes it and whether there is evidence of active exploitation. Actively exploited vulnerabilities trigger the 24h / 72h reporting obligations.
A practical process
- Intake: security contact (for example security.txt), internal findings, scanners, advisories.
- Assessment: severity, exploitability, affected versions.
- Remediation: fix, backport to supported versions, release.
- Communication: advisory, user information, and a report where required.
- Evidence: document each step for the technical documentation.
How Nuowei helps
Nuowei's security agents continuously check code and dependencies (CVE monitoring, supply-chain monitoring, secret scanning, static analysis; agentic pentesting in Defend), prioritise findings and track them through a vulnerability handling workflow that produces evidence for your documentation.