1) initial acknowledgement of receipt; and 2) status updates until the resolution of the reported issues. 5.3: Keep software updated website and user guidance documents; Use of a web form; Use of a vulnerability coordination and bug bounty platform (e.g. HackerOne). 5.2-2: Disclosed vulnerabilities should be acted on in a timely manner. 5.2-3: Manufacturers should continually monitor for, identify and rectify security vulnerabilities within products and services they sell, produce, have produced and services they operate during the defined support period. R R R R R R R R 5.3-1: All software components in consumer IoT devices should be securely updateable. 5.3-2: When the device is not a R R R R MC (5) MC (5) MC (5) MC (5) 2. Procedures around the initial acknowledgement of receipt. 3. Procedures around the status updates of the vulnerability until it is resolved. 4. [For 5.2-2] The internal guidelines/policies describing the expected time required for resolving vulnerabilities. 5. [For 5.2-3] Supporting evidence that describe internal processes for continuous monitoring, identification, and rectification of security vulnerabilities. Supporting evidence shall list all the software components in the device and describe how each of them can be securely updateable. Supporting evidence shall describe the various update mechanisms supported CLS Publication #2 | Page 26 of 49

Select target paragraph3