Ready for the rest of the Regulation

The reporting duty applies now. The manufacturer obligations in Article 13 and the vulnerability-handling requirements in Annex I apply from 11 December 2027, and they are the larger piece of work: a process, a policy, an inventory, and the documentation that proves each exists.Art. 71⁠(2)⁠

These are the 22 questions the readiness assessment asks, in the words it asks them. 8 are marked as blocking: a “no” there is not a gap to close over time but a duty that is unconditional. Read them before you buy anything, from anyone.

Knowing what you ship

Annex I Part II(1). You cannot handle a vulnerability in a component you cannot name.

  1. Do you keep a software bill of materials for every version you still support?blockingAnnex I Part II⁠(1)⁠

    A machine-readable SBOM in CycloneDX or SPDX, covering at least the top-level dependencies, kept per released version rather than only for the current build.

  2. Is the SBOM regenerated whenever you release?Annex I Part II⁠(1)⁠

    Generated by the build rather than by hand, so it cannot drift from what shipped.

  3. Have you set and published a support period for each product?blockingArt. 13⁠(8)⁠

    The period during which you will supply security updates, at least five years unless the expected product lifetime is shorter.

  4. Do you check the security of third-party components before including them?Art. 13⁠(5)⁠

    Some recorded due diligence: known vulnerabilities, whether the component is maintained, and what happens if it stops being maintained.

Handling vulnerabilities

Annex I Part II(2) and (3). Finding, fixing and testing, on a clock.

  1. Do you monitor advisory feeds against your components continuously?blockingAnnex I Part II⁠(2)⁠

    Automatic matching of new advisories against what you ship, rather than someone reading a mailing list when they have time.

  2. Do you have a written timeframe for triaging a new vulnerability?Annex I Part II⁠(2)⁠

    A stated target from “advisory lands” to “we have decided whether it affects us”, with an owner.

  3. Are vulnerabilities remediated without delay, including by security update?blockingAnnex I Part II⁠(2)⁠

    A route from a confirmed vulnerability to a released fix, with the decision recorded when you choose not to fix.

  4. Do you test and review the security of the product regularly?Annex I Part II⁠(3)⁠

    Regular means on a schedule you can name: dependency scanning per build, plus periodic review of the product itself.

Coordinated disclosure

Annex I Part II(5) and (6). A way in for a researcher, and a policy behind it.

  1. Do you have a published coordinated vulnerability disclosure policy?blockingAnnex I Part II⁠(5)⁠

    A public page saying how to report, what you commit to, and how long you take.

  2. Is there a single contact address for reporting vulnerabilities?blockingAnnex I Part II⁠(6)⁠, Art. 13⁠(19)⁠

    One address, published where a researcher will look, monitored by someone who can act.

  3. Do you publish information about fixed vulnerabilities once an update is available?Annex I Part II⁠(4)⁠

    An advisory naming the vulnerability, its impact, and what a user must do, published when the fix ships.

Getting fixes to users

Annex I Part II(7) and (8). A patch nobody receives is not a remedy.

  1. Can you distribute security updates securely to deployed products?blockingAnnex I Part II⁠(7)⁠

    Signed updates over an authenticated channel, and a way to reach products already in the field.

  2. Are security updates free of charge and separate from feature updates?Annex I Part II⁠(8)⁠

    Security fixes must not be behind a paid tier, and must be installable without taking unrelated changes.

  3. Does each security update come with an advisory message telling users what to do?Annex I Part II⁠(8)⁠

    What was fixed, what the risk is, and the action required.

Reporting to authorities

Article 14. The 24-hour, 72-hour and final notifications.

  1. Is there a named person responsible for filing the Article 14 notifications?blockingArt. 14⁠(1)⁠

    A named owner and a deputy. Twenty-four hours is short enough that “whoever is around” is not a plan.

  2. Do you know which CSIRT and which single reporting platform you would use?Art. 14⁠(7)⁠

    The CSIRT designated as coordinator by the member state where you have your main establishment in the Union.

  3. Have you rehearsed the reporting flow at least once?Art. 14⁠(2)⁠

    A dry run producing the three notifications from a real or invented incident.

  4. Can you notify affected users of an actively exploited vulnerability without undue delay?Art. 14⁠(8)⁠

    A route to the users of a specific product version, not only a blog post.

Governance and documentation

Articles 13 and 31, Annex VII. Who decides, and what you can show.

  1. Have you carried out a cybersecurity risk assessment for each product?Art. 13⁠(2)⁠-⁠(3)⁠

    Documented, covering intended use and reasonably foreseeable misuse, and revisited when the product changes.

  2. Do you keep technical documentation covering the essential requirements?Art. 31, Annex VII

    The Annex VII set: product description, design and development, risk assessment, and the vulnerability handling process.

  3. Are records kept long enough to evidence what you did?Art. 13⁠(15)⁠, Art. 31⁠(4)⁠

    Ten years for technical documentation and conformity, or the support period if longer.

  4. Do you know which conformity assessment route applies to your product?Art. 32, Annex VIII

    Self-assessment for default class products; a notified body or applicable standards for important and critical classes.

The five documents

Each is drafted from the answers above and from what the workspace already holds. Every fact the product does not hold is left as a visible placeholder, and the count of placeholders is shown beside each document, because a policy that quietly invents a support period is worse than one that is obviously unfinished.

Vulnerability handling processThe process Annex I Part II requires you to have, written from what you told us you do.7 sections · show outline
  1. Purpose and scopeAnnex I Part II
  2. Knowing what we shipAnnex I Part II⁠(1)⁠
  3. Detection and triageAnnex I Part II⁠(2)⁠
  4. RemediationAnnex I Part II⁠(2)⁠, ⁠(3)⁠
  5. Distributing updatesAnnex I Part II⁠(7)⁠, ⁠(8)⁠
  6. Reporting to authoritiesArt. 14
  7. RecordsArt. 13⁠(15)⁠, Art. 31⁠(4)⁠
Coordinated vulnerability disclosure policyA public policy and reporting address, ready to publish.5 sections · show outline
  1. How to report a vulnerabilityAnnex I Part II⁠(6)⁠
  2. What to include
  3. What we commit toAnnex I Part II⁠(5)⁠
  4. Scope
  5. DisclosureAnnex I Part II⁠(4)⁠
Software bill of materials policyWhat you generate, when, how long you keep it, and who may see it.4 sections · show outline
  1. Why we keep oneAnnex I Part II⁠(1)⁠, Annex VII⁠(2)⁠⁠(b)⁠
  2. What we produce
  3. Coverage
  4. Who may see itArt. 13⁠(25)⁠, Annex VII⁠(8)⁠
Technical documentation (Annex VII)The Annex VII structure with what we hold filled in. The engineering content is yours.8 sections · show outline
  1. 1. General description of the productAnnex VII⁠(1)⁠
  2. 2. Design, development and vulnerability handlingAnnex VII⁠(2)⁠
  3. 3. Cybersecurity risk assessmentAnnex VII⁠(3)⁠, Art. 13⁠(2)⁠-⁠(3)⁠
  4. 4. Determination of the support periodAnnex VII⁠(4)⁠, Art. 13⁠(8)⁠
  5. 5. Harmonised standards appliedAnnex VII⁠(5)⁠
  6. 6. Test reportsAnnex VII⁠(6)⁠
  7. 7. EU declaration of conformityAnnex VII⁠(7)⁠
  8. 8. Software bill of materialsAnnex VII⁠(8)⁠
EU declaration of conformity (Annex V)The Annex V structure. A draft only: signing one is a legal act taken under your sole responsibility.8 sections · show outline
  1. 1. ProductAnnex V⁠(1)⁠
  2. 2. ManufacturerAnnex V⁠(2)⁠
  3. 3. ResponsibilityAnnex V⁠(3)⁠
  4. 4. Object of the declarationAnnex V⁠(4)⁠
  5. 5. Conformity statementAnnex V⁠(5)⁠
  6. 6. StandardsAnnex V⁠(6)⁠
  7. 7. Notified bodyAnnex V⁠(7)⁠
  8. 8. SignatureAnnex V⁠(8)⁠

Readiness Pack

The questionnaire and the five documents, generated from your answers and regenerated as they change, as a one-time purchase of 1,490 excluding VAT. Bought from inside a workspace, on any plan; included in Partner. The questionnaire is readable there before you pay.

The declaration of conformity is a legal act taken under your sole responsibility, and for a Class II product the route runs through a notified body. Neither is something a document generator does for you; see what the duty is and bring counsel for the rest.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.