Skip to main content

Clause 7.8 — Product cybersecurity monitoring and issue management

Subclause 7.8 specifies requirements for monitoring the threat landscape, handling discovered vulnerabilities, and managing security incidents under FprEN 40000-1-2:2026.

Portal UI Path: CVD Portal → Submissions / Compliance → Article 14 Reporting

Related Procedures:

What Clause 7.8 requires

Requirements

  • [CLA-08-RQ-01]: Manufacturers shall monitor and react to changes in product risk assessments (6.4), incidents, and vulnerabilities at justifiable periodic intervals.
  • [CLA-08-RQ-02]: Discovered vulnerabilities shall be addressed in line with risk assessment (6.4) and risk communication (6.6) (aligned with prEN 40000-1-3).
  • [CLA-08-RQ-03]: Verified cybersecurity incidents shall be addressed without undue delay.
  • [CLA-08-RQ-04]: Residual risks resulting from incidents shall be communicated in alignment with 6.6.

How CVD Portal supports compliance

CVD Portal provides a comprehensive vulnerability intake, monitoring, and reporting platform:

Article 14 Notification Deadlines

Early Warning Drawer

  • Coordinated Vulnerability Disclosure (CVD) Portal: Provides a dedicated, whitelabel intake form (acme.cvdportal.com) with PGP encryption and automated acknowledgment SLAs.
  • Automated threat monitoring: Continuously cross-references uploaded SBOMs against EUVD, GCVE, and CISA KEV feeds, flagging new component vulnerabilities instantly.
  • Article 14 early warning & incident engine: Automated deadline banners guide you through mandatory 24-hour early warnings, 72-hour notifications, and final reports to ENISA and CSIRTs.
  • CSAF 2.0 advisory publisher: Generates machine-readable CSAF 2.0 advisories and user notification notices upon remediation release.