cra

Annex I, Part II, (2)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (7)

Techniques referencing this article

  • EX-0005.01Design FlawsST0004
    addresses
    high
    derived

    Address-and-remediate-without-delay obligations apply to design-flaw findings; manufacturers must close design-flaw exploitation paths under documented vulnerability handling.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    derived

    Address-and-remediate-without-delay applies directly to identified code flaws; the obligation bounds the time-to-fix metric an exploitation adversary tries to outrun.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Address-and-remediate-without-delay applies to identified FSW vulnerabilities; the obligation bounds operational dwell time before remediation.

  • EX-0009.02Operating SystemST0004
    addresses
    high
    derived

    Address-and-remediate obligations cover OS-level defects, including misconfigurations around maintenance interfaces.

  • Address-and-remediate-without-delay is the temporal discipline that bounds the time-to-fix metric known-vulnerability exploitation tries to outrun.

  • Once a poisoned dependency is identified the manufacturer must address and remediate without delay under Annex I, Part II, (2), bounding the exploit window of dependency-confusion or typosquatting attacks.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    direct

    Manufacturers must address and remediate vulnerabilities without delay; this is the operational discipline that bounds the time between disclosure and exploitation, which is the metric known-vulnerability reconnaissance is trying to outrun.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.