Skip to main content

EU Cyber Resilience Act

How the Product CERT portal supports Flowserve vulnerability handling, transparency, and evidence workflows for products with digital elements.

Draft compliance content for DEV review
This page is a workflow overview, not legal advice or a declaration of conformity. Legal and product owners must approve production claims.

Portal role

The Product CERT portal is designed to provide a consistent public contact point, support structured vulnerability intake, maintain an auditable handling record, and publish customer actions in human-readable and machine-readable formats.

Product classification, conformity assessment, technical documentation, support periods, and regulatory notifications remain governed by the responsible Flowserve business and legal processes.

Workflow capability map

Draft mapping of capability areas to portal support and approval owners
Capability areaPortal supportApproval owner
Vulnerability contactPublic reporting workflowProduct Security and Legal
Coordinated handlingTriage, assignment, status, and audit historyProduct Security
Customer guidanceVersioned advisories with affected products and remediationProduct Security and Product Engineering
Machine-readable publicationsStructured advisory API and exportProduct Security
Support-period communicationSecurity notices and product-specific publication metadataProduct Management and Legal
Regulatory reporting supportTracked exploitation and incident escalation dataProduct Security and Legal

Evidence produced by the portal

  • Publication revisionsApproved changes, timestamps, and structured export data.
  • Handling historyAssignment, validation, escalation, and decision records.
  • Notification historySubscriber audience and publication delivery outcomes.

The portal supports compliance operations; it does not replace product-specific legal or technical documentation.