Vulnerability handling and security contact questions
Supplier evidence is also about what happens after a vulnerability or security concern is reported. If the security contact is unreachable or the vulnerability handling route is unclear, a valid concern can stall before assessment, leaving importers and product teams without a reliable path for fixes, patches, mitigations or customer communication.
ENISA describes coordinated vulnerability disclosure as a multi-party approach that supports reporting and coordinated disclosure after responsible parties have developed a fix, patch or mitigation. The exact process can differ between suppliers, but the contact and follow-up route should be understood before a supplier meeting, distributor review or product-security event makes it urgent.
Source: https://www.enisa.europa.eu/topics/vulnerability-disclosure
ENISA’s supply-chain cybersecurity work also provides context for treating supplier relationships and supply-chain risk as structured cybersecurity concerns.
Source: https://www.enisa.europa.eu/publications/good-practices-for-supply-chain-cybersecurity
The CRA separately establishes manufacturer reporting for actively exploited vulnerabilities and severe incidents. This section focuses on supplier communication and reviewable follow-up, not legal reporting instructions.
Security contact and reporting route
A reachable security contact gives product teams a defined entry point for vulnerability disclosure. The route should be clear enough that a concern reaches the responsible function without depending on an informal personal contact.
- Where should a product-security concern or vulnerability report be submitted?
- Who monitors that security contact, and is there a fallback route?
- Does the supplier maintain a vulnerability disclosure or coordinated vulnerability disclosure process?
Assessment, fixes and mitigations
Once a report is received, importers need enough supplier evidence to understand whether it has been acknowledged, assessed and connected to the affected product versions. They do not need the supplier’s internal incident-response playbook, but they do need a usable status and remediation path.
- How does the supplier acknowledge, assess and track a vulnerability report?
- How are affected products and versions identified?
- How will available fixes, patches or mitigations be communicated?
Communication records and supplier follow-up
Confirmed issues can affect importers, distributors, customers or users in different ways. A reviewable communication record helps the organisation see what was known, what was sent, who owns supplier follow-up and whether an open action has been closed.
- How are relevant parties notified when a security issue is confirmed?
- Are security advisories, update notices and mitigation records retained?
- Who provides status updates and closure evidence for unresolved actions?
In a PAXECT Readiness workflow, vulnerability-handling evidence can turn an unclear supplier contact route into reviewable product-security follow-up.