@@ -1198,8 +1198,9 @@ Depending on the chosen delivery method, the maintenance of the operating system
* For each identified exploitable vulnerability, the product shall have the risk mitigated.
* The used vulnerability scanner shall be fit for the purpose in detail, method and depth.
Recognising that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use, and that the product should be free from known exploitable vulnerabilities both when first made available and when first used by the product user.
The period of the product lifecycle, which is after the release, is addressed in [5.5 Security updates](#55-security-updates) section.
It needs to be considered that there may be vulnerabilities discovered between the time that a product is placed on the market and the time of that product's first use.
Any of these products should be free from known exploitable vulnerabilities at both points in time, when it is first made available on the market, and when the user starts the product the very first time.
The post-release period of the product lifecycle is addressed in [5.5 Security updates](#55-security-updates) section.