Cyber path
This section translates Annex I into technical capabilities to build, tools to deploy and evidence to produce. The text itself is explained in Essential requirements.
The eight capabilities to build
Annex I, Part II sets out eight vulnerability handling obligations. Each maps to a technical capability, a tool and a verifiable artefact:
| Requirement (Annex I, Part II) | Capability | Evidence produced |
|---|---|---|
| 1. Identify components and vulnerabilities, machine-readable SBOM | Automated generation in CI | Signed CycloneDX SBOM, per build |
| 2. Address and remediate without delay, security fixes separate from features | Vulnerability management, patch branches | Handling log, measured intervals |
| 3. Regular security testing and review | SAST, DAST, SCA, fuzzing, penetration testing | Dated test reports |
| 4. Publish information on fixed vulnerabilities | Security advisories in CSAF format | Published advisories |
| 5. Coordinated disclosure policy | CVD channel, security.txt |
Published policy, acknowledgements |
| 6. Facilitate information sharing, contact address | PSIRT mailbox, public key | Live, tested address |
| 7. Secure distribution of updates | Signing, authenticated channel, anti-rollback | Description of the mechanism |
| 8. Distribution without delay and free of charge, with advisory messages | Publication process | Publication history |
What Cyber must obtain from Legal
The regulatory classification of each product (it drives the level of evidence expected), the licence policy, the committed support period, the decision on SBOM disclosure, and the decision to report during an incident.
What Cyber must supply to Legal
The signed SBOM, the risk assessment, the vulnerability handling log, the VEX statements, the test reports, the description of the update mechanism, and — within two hours of detection — the qualification of active exploitation.
The nearest obligation
It is not the SBOM, it is reporting. Since 11 September 2026, an actively exploited vulnerability triggers an early warning within 24 hours, including for products placed on the market before that date. That requires an on-call rota, a tested channel and a documented escalation rule: see 24 h / 72 h / 14 d procedure.
The link to automate. Moving from technical triage (“this vulnerability is exploited in the wild”) to the legal obligation (“you must report within 24 hours”) must not depend on the judgement of whoever is on call. It must be a tooled trigger, with escalation by default.
In this section
Cyber
Generating SBOMs
The five generation methods by context, the tool families, the choice matrix by language, and why the toolchain must be pinned per product family.
Cyber
CI/CD integration
The eight steps of the target pipeline, the blocking rules, waiver handling, monorepos, and the cost in build time.
Cyber
Securing the build chain
The chain that produces and signs the SBOM is itself an attack surface: the six ways code executes in a pipeline, the pull-request attack, and the countermeasures.
Cyber
Locking and updating dependencies
The central tension: freeze so you can rebuild identically for ten years, and update so there is no known exploitable vulnerability. Lock files, hash pinning, automated updates and quarantine.
Cyber
Assessing an open source component
Making the diligence required by Article 13(5) computable: the eighteen OpenSSF Scorecard checks, what they cover of the grid, what they do not tell you, and the S2C2F ingestion framework.
Cyber
Secure by design
Turning Annex I Part I into verifiable requirements: threat modelling, risk assessment, test plan, and the frameworks to use while harmonised standards are pending.
Cyber
Vulnerability management
The full cycle from detection to closure, the sources to aggregate, composite-score prioritisation, remediation SLAs and the automated reporting trigger.
Cyber
Coordinated disclosure policy
What a CVD policy contains, security.txt and RFC 9116, the safe harbour commitment, ISO/IEC 29147 and 30111, the French legal route, and whether to become a CNA.
Cyber
24 h / 72 h / 14 d procedure
The full reporting runbook: detection, qualification, crisis cell, submissions, informing users, on-call cover, exercises and a printable response card.
Cyber
Continuous monitoring
Replaying the SBOM daily against sources that move: architecture, EUVD and the ENISA reporting platform, upstream monitoring, metrics.
Cyber
Supply chain risk
Attack typology, what an SBOM does and does not enable, countermeasures for hardening the build chain, and mapping your exposure.
Cross-cutting
Reference incidents
Fourteen documented, dated compromises, from a vendor update channel to a hijacked CI action: what happened, what would have limited the damage, and the requirement each one illuminates.
Cyber
Managing false positives
The compliance risk of excess noise: root causes, remedies, a dated and reasoned suppression policy, and the metric to track.
Cyber
Secure updates
Authenticated channel, signing, rollback protection, automatic updates with opt-out, separating fixes, free of charge, and the embedded case.
Cyber
Technical checklist
Fifteen points to verify per product before the conformity review, printable, to be attached to the pre-market review file.