Glossary · Term

Vulnerability management explained

Vulnerability management is the governed process of finding security gaps, prioritising them, closing them and evidencing how it was done.

At a glance
Meaning
A governed way of handling security gaps
Perspective
Process, responsibility, governance
Duty
NIS2 Article 21 (risk management measures)
Evidence
Policy, roles, audit trail
Related
Vulnerability, cyber hygiene
Updated
June 2026
Editorial team
Compliance Compass

What does vulnerability management mean?

Vulnerability management is how an organisation handles vulnerabilities, the exploitable gaps in systems, applications or workflows. This page takes the organisational view : vulnerability management as a governed process with clear responsibilities and audit-proof evidence. The technical detail – CVE identifiers, CVSS and EPSS scoring, scanner tooling and patch SLAs – is covered by the entry on Vulnerability. What matters here is not the single gap but the question of who is responsible, by which rules work is prioritised, and how all of it can be evidenced in an audit.

Why a governed process is needed

Gaps appear continuously – through new software faults, changed configurations, bought-in components or freshly discovered attack techniques. An application that was safe yesterday can carry a critical gap tomorrow. Without a fixed process, treatment is left to chance: sometimes someone takes care of it, sometimes nobody does. A defined sequence with named roles turns that uncertainty into a reliable, repeatable routine – and it is precisely that reliability a supervisory authority looks for.

Governance: process, responsibility, prioritisation

Effective vulnerability management stands or falls with clear responsibilities. A policy sets out who assesses gaps, who decides on exceptions and within which deadlines a response is due. Prioritisation follows risk, not gut feeling: business criticality of the system, exposure from outside and severity of the gap set the order. Every decision – including a residual risk that is deliberately accepted – is recorded so that it stays traceable later. That is how an audit trail comes about, one that evidences the effectiveness of the measures to the authority.

Vulnerability management and NIS2

A governed approach to vulnerabilities is expressly part of Cyber hygiene and of the risk management measures that NIS2 requires under Article 21. The directive entered into force on 16 January 2023 and has applied since 18 October 2024; entities in scope must not only take effective measures but also be able to evidence them. If known gaps are left untreated and this leads to a significant incident, the reporting chain applies: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts. In practice: A mid-sized machinery manufacturer learns from an advisory issued by its national CSIRT that its VPN gateway carries a critical gap. Because responsibility is clearly assigned, everyone knows at once who checks, who decides and who documents – a potential way in becomes a demonstrably closed risk.

Next steps

Further reading: BSI IT-Grundschutz – the German baseline information security standard

Frequently asked questions

What does vulnerability management cover?

Vulnerability management is the governed way an organisation finds, prioritises, closes and monitors the exploitable gaps in its systems, applications, configurations and processes. Attackers use such a gap to gain access, steal data or disrupt services; typical examples are outdated software, missing security updates or misconfigurations. A process is needed because gaps keep appearing: an application that was safe yesterday can be exposed tomorrow by a new software fault or a new attack technique. What a single gap is in technical terms is covered on the vulnerability page.

How does vulnerability management work in practice?

Systems are scanned regularly, the gaps that turn up are prioritised by risk, closed through patching and hardening, and then monitored. Prioritisation follows the business criticality of the system, its exposure from outside and the severity of the gap, not gut feeling. A policy sets out responsibilities and deadlines, and every decision is recorded in an audit trail. Fast, documented patching is one of the most effective measures against cyberattacks there is.

Why is vulnerability management relevant for NIS2?

A governed approach to vulnerabilities is expressly part of the cyber hygiene and of the risk management measures that Article 21 of NIS2 requires. The directive has applied since 18 October 2024, and entities in scope must not only take effective measures but also be able to evidence them. If known gaps are left untreated and a significant incident follows, the reporting chain applies: 24 hours, 72 hours and one month. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Risk management

Vulnerability management that survives an audit intact

Compliance Compass anchors responsibilities, response deadlines and risk-based prioritisation in an auditable process – and produces the evidence for Article 21 of NIS2 at the touch of a button.