Clause 7.8 — Product cybersecurity monitoring and issue management
Subclause 7.8 specifies requirements for monitoring the threat landscape, handling discovered vulnerabilities, and managing security incidents under FprEN 40000-1-2:2026.
Portal UI Path: CVD Portal → Submissions / Compliance → Article 14 Reporting
Related Procedures:
What Clause 7.8 requires
Requirements
[CLA-08-RQ-01]: Manufacturers shall monitor and react to changes in product risk assessments (6.4), incidents, and vulnerabilities at justifiable periodic intervals.[CLA-08-RQ-02]: Discovered vulnerabilities shall be addressed in line with risk assessment (6.4) and risk communication (6.6) (aligned with prEN 40000-1-3).[CLA-08-RQ-03]: Verified cybersecurity incidents shall be addressed without undue delay.[CLA-08-RQ-04]: Residual risks resulting from incidents shall be communicated in alignment with 6.6.
How CVD Portal supports compliance
CVD Portal provides a comprehensive vulnerability intake, monitoring, and reporting platform:


- Coordinated Vulnerability Disclosure (CVD) Portal: Provides a dedicated, whitelabel intake form (
acme.cvdportal.com) with PGP encryption and automated acknowledgment SLAs. - Automated threat monitoring: Continuously cross-references uploaded SBOMs against EUVD, GCVE, and CISA KEV feeds, flagging new component vulnerabilities instantly.
- Article 14 early warning & incident engine: Automated deadline banners guide you through mandatory 24-hour early warnings, 72-hour notifications, and final reports to ENISA and CSIRTs.
- CSAF 2.0 advisory publisher: Generates machine-readable CSAF 2.0 advisories and user notification notices upon remediation release.