Cyber path

This section translates Annex I into technical capabilities to build, tools to deploy and evidence to produce. The text itself is explained in Essential requirements.

The eight capabilities to build

Annex I, Part II sets out eight vulnerability handling obligations. Each maps to a technical capability, a tool and a verifiable artefact:

Requirement (Annex I, Part II) Capability Evidence produced
1. Identify components and vulnerabilities, machine-readable SBOM Automated generation in CI Signed CycloneDX SBOM, per build
2. Address and remediate without delay, security fixes separate from features Vulnerability management, patch branches Handling log, measured intervals
3. Regular security testing and review SAST, DAST, SCA, fuzzing, penetration testing Dated test reports
4. Publish information on fixed vulnerabilities Security advisories in CSAF format Published advisories
5. Coordinated disclosure policy CVD channel, security.txt Published policy, acknowledgements
6. Facilitate information sharing, contact address PSIRT mailbox, public key Live, tested address
7. Secure distribution of updates Signing, authenticated channel, anti-rollback Description of the mechanism
8. Distribution without delay and free of charge, with advisory messages Publication process Publication history

The regulatory classification of each product (it drives the level of evidence expected), the licence policy, the committed support period, the decision on SBOM disclosure, and the decision to report during an incident.

The signed SBOM, the risk assessment, the vulnerability handling log, the VEX statements, the test reports, the description of the update mechanism, and — within two hours of detection — the qualification of active exploitation.

The nearest obligation

It is not the SBOM, it is reporting. Since 11 September 2026, an actively exploited vulnerability triggers an early warning within 24 hours, including for products placed on the market before that date. That requires an on-call rota, a tested channel and a documented escalation rule: see 24 h / 72 h / 14 d procedure.

The link to automate. Moving from technical triage (“this vulnerability is exploited in the wild”) to the legal obligation (“you must report within 24 hours”) must not depend on the judgement of whoever is on call. It must be a tooled trigger, with escalation by default.

In this section

  • Cyber

    Generating SBOMs

    The five generation methods by context, the tool families, the choice matrix by language, and why the toolchain must be pinned per product family.

  • Cyber

    CI/CD integration

    The eight steps of the target pipeline, the blocking rules, waiver handling, monorepos, and the cost in build time.

  • Cyber

    Securing the build chain

    The chain that produces and signs the SBOM is itself an attack surface: the six ways code executes in a pipeline, the pull-request attack, and the countermeasures.

  • Cyber

    Locking and updating dependencies

    The central tension: freeze so you can rebuild identically for ten years, and update so there is no known exploitable vulnerability. Lock files, hash pinning, automated updates and quarantine.

  • Cyber

    Assessing an open source component

    Making the diligence required by Article 13(5) computable: the eighteen OpenSSF Scorecard checks, what they cover of the grid, what they do not tell you, and the S2C2F ingestion framework.

  • Cyber

    Secure by design

    Turning Annex I Part I into verifiable requirements: threat modelling, risk assessment, test plan, and the frameworks to use while harmonised standards are pending.

  • Cyber

    Vulnerability management

    The full cycle from detection to closure, the sources to aggregate, composite-score prioritisation, remediation SLAs and the automated reporting trigger.

  • Cyber

    Coordinated disclosure policy

    What a CVD policy contains, security.txt and RFC 9116, the safe harbour commitment, ISO/IEC 29147 and 30111, the French legal route, and whether to become a CNA.

  • Cyber

    24 h / 72 h / 14 d procedure

    The full reporting runbook: detection, qualification, crisis cell, submissions, informing users, on-call cover, exercises and a printable response card.

  • Cyber

    Continuous monitoring

    Replaying the SBOM daily against sources that move: architecture, EUVD and the ENISA reporting platform, upstream monitoring, metrics.

  • Cyber

    Supply chain risk

    Attack typology, what an SBOM does and does not enable, countermeasures for hardening the build chain, and mapping your exposure.

  • Cross-cutting

    Reference incidents

    Fourteen documented, dated compromises, from a vendor update channel to a hijacked CI action: what happened, what would have limited the damage, and the requirement each one illuminates.

  • Cyber

    Managing false positives

    The compliance risk of excess noise: root causes, remedies, a dated and reasoned suppression policy, and the metric to track.

  • Cyber

    Secure updates

    Authenticated channel, signing, rollback protection, automatic updates with opt-out, separating fixes, free of charge, and the embedded case.

  • Cyber

    Technical checklist

    Fifteen points to verify per product before the conformity review, printable, to be attached to the pre-market review file.