cra

Annex I, Part II, (8)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (15)

Techniques referencing this article

  • EX-0004Compromise Boot MemoryST0004
    addresses
    moderate
    direct

    Flight-software exploitation handled through the secure-update channel (primary mapping: Part II, (7)) cascades to (8)'s timely-dissemination obligation — secure update distribution and dissemination-without-delay are paired.

  • EX-0005.01Design FlawsST0004
    addresses
    moderate
    direct

    Hardware supply-chain backdoor exploitation (primary mapping: Part II, (2)) cascades to (8) — once a remediating update exists, the manufacturer must disseminate it without delay.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    direct

    Vulnerability exploitation parent (primary mapping: Part II, (2) remediate) cascades to (8) — the timing element of remediation is dissemination without delay.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    direct

    Known-vulnerability exploitation (primary mapping: Part II, (2) remediate) cascades to (8) — the patch must reach affected products without delay once available.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate
    direct

    Zero-day exploitation (primary mapping: Part II, (2) remediate) cascades to (8) — once a fix is developed for an undisclosed vulnerability, dissemination without delay is the operational obligation.

  • Manufacturer obligation to disseminate security updates without delay closes the exploit window once remediation is available.

  • EX-0010.04BootkitST0004
    addresses
    moderate
    direct

    Stack/heap-memory exploitation handled via secure update distribution (primary mapping: Part II, (7)) cascades to (8) — the secure-distribution and timely-dissemination obligations work in tandem.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    direct

    SDR-modification exfiltration (primary mapping: Part I, (2)(c) security updates) cascades to (8) — when the attack rides 'legitimate updates', the manufacturer's update channel must include the timely-dissemination discipline that legitimate fixes require.

  • Software-dependency compromise (primary mapping: Part II, (2)) cascades to (8) — once a remediating update is available, dissemination without delay is the timing element.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    direct

    Software supply-chain compromise (primary mapping: Part II, (7)) cascades to (8) — secure update distribution is paired with the timely-dissemination obligation.

  • IA-0002Compromise Software Defined RadioST0003
    addresses
    moderate
    direct

    Compromised-software-update initial-access (primary mapping: Part I, (2)(c) security updates) cascades to (8) — the (2)(c) obligation includes dissemination without delay as the timing element.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    moderate
    direct

    Malicious commands during firmware update (primary mappings: Part I, (2)(c) + Part II, (7)) cascade to (8) — once corrective updates exist, timely dissemination is the operational obligation.

  • PER-0001Memory CompromiseST0005
    addresses
    moderate
    direct

    Malicious-update persistence (primary mapping: Part II, (7)) cascades to (8) — the legitimate update channel that countervails malicious-update persistence must maintain timely dissemination of remediating fixes.

  • REC-0001.02FirmwareST0001
    addresses
    moderate
    direct

    Eavesdropping on update channels (primary mapping: Part I, (2)(c)) cascades to (8) — the security-update obligation in (2)(c) includes the dissemination-without-delay timing element under (8).

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    derived

    Manufacturer obligation to disseminate security updates without delay once available is the temporal discipline that bounds the exploit window for known vulnerabilities.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.