Directive (EU) 2024/2853 on liability for defective products introduces continuous monitoring obligations that directly affect those who develop or distribute software and related services. For manufacturers, demonstrating that a product is monitored and updated over time is no longer just a best practice: it is a requirement with legal consequences. Vulnerability assessment is one of the most effective tools for building and documenting this evidence.
This article is part of the mini-guide on Directive (EU) 2024/2853. For the general framework, consult the hub dedicated to the product liability directive and the in-depth analysis of digital products and connected software.
Post-sales control: what the directive asks of the manufacturer
Directive 2024/2853 establishes that the manufacturer is required to monitor the product for the entire period during which it is capable of providing updates. If a defect depends on the lack of updates or software improvements necessary for security, liability remains with the manufacturer even after the sale. The omission of updates to correct cybersecurity vulnerabilities does not exempt the manufacturer from civil liability.
In this context, vulnerability assessment performs a concrete function: it allows for the identification of vulnerabilities present in the product, their classification by priority, and the initiation of a structured remediation process. The frequency of scans and the management of the remediation backlog become documentable elements, useful for demonstrating that continuous monitoring has actually been exercised.
Remediation backlog and update management
One of the most relevant aspects for software manufacturers is the management of the backlog of identified vulnerabilities. It is not enough to detect problems: it is necessary to track the decisions made regarding each vulnerability, the intervention times, and the reasons for any postponements. A well-documented vulnerability assessment process produces periodic reports that can be used as evidence in the event of a dispute or disclosure.
The directive does not prescribe specific tools, but the connection with the Cyber Resilience Act — also referenced by the European Delegation Law 2025 (Law 36/2026) — introduces precise technical requirements for products with digital elements. Failure to comply with these rules results in an automatic presumption of product defectiveness in civil proceedings. Having a traceable vulnerability assessment process is therefore also relevant for legal defense.
Compensable damages and impact on data
Directive 2024/2853 expands compensable damages to include, for the first time, the destruction or corruption of data not used for professional purposes. An effective vulnerability assessment reduces the risk of incidents that compromise end-user data or databases. Preventing such events lowers the probability of having to bear both the material costs of restoration and the legal consequences deriving from the defectiveness of the product.
To learn more about the specific implications for software, consult the article on software liability in the EU directive. To understand how penetration testing integrates with vulnerability assessment in evidence management, read the in-depth analysis on penetration testing and manufacturer liability.
FAQ: Directive (EU) 2024/2853 and vulnerability assessment
- Is vulnerability assessment mandatory by law under Directive 2024/2853?
- The directive does not explicitly name vulnerability assessment, but it requires the manufacturer to monitor the product and release security updates. Vulnerability assessment is one of the most suitable tools for fulfilling this obligation in a documentable and verifiable manner.
- When does the continuous monitoring obligation come into force?
- Directive 2024/2853 will be fully applicable from December 9, 2026. Manufacturers operating in the EU market have an interest in starting compliance processes with sufficient lead time.
- What happens if a vulnerability is identified but not corrected in a reasonable time?
- If the damage is attributable to a known and uncorrected vulnerability, the manufacturer may be held liable. Documentation of the remediation backlog — with the decisions made and the reasons for postponements — is a relevant element for defense in the event of a dispute.
- Does the Cyber Resilience Act apply to the same companies?
- The Cyber Resilience Act applies to products with digital elements placed on the EU market and introduces specific technical requirements, including those related to vulnerability management. Law 36/2026 connects the two regulatory instruments within the Italian legal system.
Protect your organisation with Vulnerability Assessment.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
