cra

Art. 13(6)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (3)

Techniques referencing this article

  • Manufacturer-on-component vulnerability handling (including for open-source components) is the precise obligation engaged when known-CVE-class exploitation targets COTS/FOSS components.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    derived

    Manufacturer obligation to act on identified vulnerabilities in contained components (including open-source) is the procedural lever that converts compromised-component discovery into product-level remediation.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    derived

    Manufacturer-on-component vulnerability handling (including for open-source components) is the precise obligation an adversary's known-vulnerability reconnaissance attempts to exploit before remediation; Art. 13(6) establishes the manufacturer's duty when a vulnerability is identified in a contained component.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.