The five documents, as outlines
A manufacturer needs a vulnerability handling process, a coordinated disclosure policy, a bill-of-materials policy, the technical documentation of Annex VII and the declaration of conformity of Annex V. Here is the structure of each, with the article every section answers to and the fields each one needs.Art. 13
Nothing on this page is filled in. Write them yourself from these, or have them drafted from your answers; either way, the headings are the Regulation’s.
Vulnerability handling process
The process Annex I Part II requires you to have, written from what you told us you do.
- 1
Purpose and scopeAnnex I Part II
Needs: Support periods
- 2
Knowing what we shipAnnex I Part II(1)
- 3
Detection and triageAnnex I Part II(2)
- Triage owner: [to be completed]
- Target time from advisory to triage decision: [to be completed]
- Escalation if the owner is unavailable: [to be completed]
- 4
RemediationAnnex I Part II(2), (3)
- 5
Distributing updatesAnnex I Part II(7), (8)
- 6
Reporting to authoritiesArt. 14
Needs: Reporting owner · Deputy · CSIRT designated as coordinator
- 7
RecordsArt. 13(15), Art. 31(4)
Coordinated vulnerability disclosure policy
A public policy and reporting address, ready to publish.
- 1
How to report a vulnerabilityAnnex I Part II(6)
Needs: Reporting address · Policy published at
- 2
What to include
- The product and version affected.
- What you did, and what happened.
- Enough detail for us to reproduce it.
- How you would like to be credited, if at all.
- 3
What we commit toAnnex I Part II(5)
- We acknowledge your report within three working days.
- We tell you whether we have reproduced it within ten working days.
- We keep you informed while we work on a fix.
- We publish an advisory when the fix is available, and credit you unless you ask us not to.
- and 1 more
- 4
Scope
- 5
DisclosureAnnex I Part II(4)
Software bill of materials policy
What you generate, when, how long you keep it, and who may see it.
- 1
Why we keep oneAnnex I Part II(1), Annex VII(2)(b)
- 2
What we produce
- A CycloneDX or SPDX document per released version, not per build branch.
- Generated by the release pipeline, so it describes what shipped.
- Retained for the support period of the version it describes, and for as long as the technical documentation must be kept.
- 3
Coverage
Needs: Format · Depth (top level, or transitive) · Where it is stored
- 4
Who may see itArt. 13(25), Annex VII(8)
Technical documentation (Annex VII)
The Annex VII structure with what we hold filled in. The engineering content is yours.
- 1
1. General description of the productAnnex VII(1)
Needs: Products covered · Versions affecting compliance · Intended purpose · User information and instructions (Annex II)
- 2
2. Design, development and vulnerability handlingAnnex VII(2)
Needs: Architecture description · Vulnerability handling process · Disclosure policy and contact address · Secure distribution of updates
- 3
3. Cybersecurity risk assessmentAnnex VII(3), Art. 13(2)-(3)
- 4
4. Determination of the support periodAnnex VII(4), Art. 13(8)
Needs: Support periods and reasoning
- 5
5. Harmonised standards appliedAnnex VII(5)
Needs: Standards or common specifications
- 6
6. Test reportsAnnex VII(6)
Needs: Reports verifying conformity
- 7
7. EU declaration of conformityAnnex VII(7)
- 8
8. Software bill of materialsAnnex VII(8)
EU declaration of conformity (Annex V)
The Annex V structure. A draft only: signing one is a legal act taken under your sole responsibility.
- 1
1. ProductAnnex V(1)
Needs: Name, type and identification
- 2
2. ManufacturerAnnex V(2)
Needs: Name · Address · Authorised representative in the Union
- 3
3. ResponsibilityAnnex V(3)
- 4
4. Object of the declarationAnnex V(4)
Needs: Versions covered
- 5
5. Conformity statementAnnex V(5)
Needs: Other Union legislation applied
- 6
6. StandardsAnnex V(6)
Needs: Harmonised standards or common specifications · European cybersecurity certification scheme, if any
- 7
7. Notified bodyAnnex V(7)
Needs: Conformity assessment route · Notified body name and number · Certificate identification
- 8
8. SignatureAnnex V(8)
Needs: Place of issue · Date of issue · Name and function of signatory
Drafted, not just outlined
The Readiness Pack fills these from the readiness questionnaire and from the products, versions and disclosure address a workspace already holds, and leaves every fact it does not have as a counted placeholder. One-time purchase, €1,490 excluding VAT.
The declaration of conformity is a legal act taken under your sole responsibility, and none of these outlines is legal advice. Your product class decides whether a notified body signs before you do.
Hear how the exploited list moves each month
The monthly digest is not configured on this deployment yet.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.