Annex I, a rulebook in two parts
Annex I Part I sets the product security properties for the design. A product ships with no known exploitable vulnerabilities, a secure-by-default configuration, protection of data at rest and in transit, a minimised attack surface, and a secure update mechanism that can verify what it installs. Part II sets vulnerability handling for the post-market phase, which means a public coordinated disclosure policy, remediation without undue delay, disclosure of fixed vulnerabilities with their CVE identifiers, and security updates provided free of charge. Both parts are mandatory.
The clocks Article 13 adds
Article 13 adds statutory timelines on top of the ISO disclosure and handling standards. Each security update issued during the support period stays available for at least 10 years after it was issued, or for the rest of the support period when that runs longer. Article 13(9) runs that clock from issuance, not from placing on the market. The support period must reflect how long the product is expected to be in use, and it must be at least five years unless the product is expected to be in use for less, stated as a month and year that users can find easily. Five years is a floor, not a default. Watch the one clock partners most often get wrong. The 48-hour acknowledgment to a reporter is a CVD Portal default tracked as an SLA, and the regulation itself sets no acknowledgment deadline. Do not attribute the number to ISO/IEC 29147. The standard that does set one is BSI TR-03183-3 section 4.4.8, which requires a simple response written by a person, never an automated reply, within five working days, with detailed feedback inside ten. Present 48 hours to a client as a self-imposed target with tooling behind it, and the five working days as the bar a German market-surveillance authority will look for.
Two statutory numbers from Article 13. Keep each issued update available for at least 10 years from issuance, and treat five years as the support-period floor rather than a default. The 48-hour acknowledgment is a self-imposed SLA, while BSI TR-03183-3 requires a personal reply within five working days.
The evidence a manufacturer produces
A software bill of materials lists the product's components and versions and sits inside the technical documentation, so it supports due diligence without having to be public. Fixed vulnerabilities are published as machine-readable CSAF 2.0 advisories, and the disclosure contact is commonly advertised through a security.txt file at the well-known path defined by RFC 9116. Together these give market surveillance authorities and researchers a clear, consistent way to see how a product is maintained.