The problem it solves
Security no longer stops at the boundary of the organisation. Those who make software or devices have their own reporting duties; those who buy must require them by contract.
Who it is for
- Manufacturers and distributors of products with digital elements;
- Covered entities that depend on critical suppliers;
- Procurement and legal departments.
Deliverables
- Map of products and applicable duties;
- Vulnerability handling and reporting procedure;
- Contractual security and alerting clauses;
- Supplier assessment criteria.
Method
- 01
Inventory
Products and suppliers.
- 02
Frame
Applicable duties.
- 03
Contract
Clauses and alerts.
- 04
Verify
Periodic assessment.
Regulatory basis
- Regulation (EU) 2024/2847, whose Article 14 requires reporting of actively exploited vulnerabilities and severe incidents, applicable since 11 September 2026;
- Article 27 of Decree-Law 125/2025, on supply chain security.
Expected results
- Product duties identified and met;
- Suppliers assessed and contractually bound;
- Fewer surprises coming from the supply chain.