Independent information resource Product security · EU CRA
Vulnerability handling and security updates / 03

Coordinated Vulnerability Disclosure Under the CRA

Understand the Cyber Resilience Act coordinated vulnerability disclosure requirement, including CVD policy, researcher communication, remediation coordination, fixed-vulnerability disclosure and the distinction from Article 14 reporting.

IN BRIEF

CRA coordinated vulnerability disclosure is an operational bridge between external vulnerability reporting and the manufacturer's internal remediation process. It should give researchers a predictable route to report findings, preserve communication while the issue is investigated and coordinate public disclosure with the availability of remediation.

01 / 10

Annex I Explicitly Requires Coordinated Vulnerability Disclosure

Annex I Part II point 5 requires manufacturers to put in place and enforce a policy on coordinated vulnerability disclosure. The requirement is stronger than merely publishing a page called security. The policy needs to connect to a real process that receives reports, validates potential vulnerabilities, assigns remediation and coordinates communication. Point 6 separately requires measures that facilitate the sharing of information about potential vulnerabilities, including a contact address for reports.

  • Put the CVD policy in place.
  • Enforce the policy operationally.
  • Connect external reports to the internal vulnerability process.
  • Maintain a working reporting route.
02 / 10

CVD Starts With Receiving a Potential Vulnerability Report

A coordinated disclosure process begins before the manufacturer knows whether the report describes a confirmed vulnerability. Researchers may provide incomplete information, unusual test conditions or evidence that requires reproduction. The reporting route should therefore accept potential vulnerabilities and preserve the original submission while the product security team validates it. Rejecting a report simply because severity is not yet known can cause useful security information to be lost.

  • Accept potential vulnerabilities.
  • Preserve the original report.
  • Record affected product information.
  • Route the report for validation.
03 / 10

Acknowledge the Reporter and Establish a Communication Channel

The CRA does not prescribe one fixed acknowledgement deadline for every manufacturer, but coordinated disclosure works better when reporters know their submission reached the responsible team. An acknowledgement can provide the case reference, request missing technical details and explain the next stage of assessment. The manufacturer should avoid promising remediation dates before scope and risk are understood, but silence can make coordination more difficult and can encourage uncoordinated public disclosure.

  • Confirm receipt.
  • Provide a case reference where practical.
  • Request missing information.
  • Maintain a communication channel.
04 / 10

Validate the Finding Before Setting the Disclosure Plan

The manufacturer should determine whether the reported behaviour is reproducible and which product versions or components are affected. Validation can change the disclosure plan substantially. A report may be invalid, may affect only an unsupported configuration, may reveal a broader issue than first reported or may involve a third-party component. Coordinated disclosure should therefore be based on technical investigation rather than an automatic publication timeline triggered by the first email.

  • Reproduce or substantiate the finding.
  • Identify affected versions.
  • Identify third-party components where relevant.
  • Record the technical assessment.
05 / 10

Coordinate Remediation Before Public Disclosure Where Appropriate

A central purpose of coordinated vulnerability disclosure is to reduce the period in which users face an avoidable known risk without remediation. Once a vulnerability is confirmed, the manufacturer should coordinate engineering, testing, update preparation and communication. The reporter can be informed about progress at an appropriate level without receiving information that would create unnecessary additional security risk. The process should aim to make remediation available before or alongside detailed public disclosure where circumstances permit.

  • Assign remediation ownership.
  • Develop and verify the fix.
  • Coordinate with the reporter.
  • Prepare disclosure around remediation availability.
06 / 10

Fixed-Vulnerability Disclosure Is Addressed Separately in Point 4

Annex I Part II point 4 requires manufacturers, once a security update has been made available, to share and publicly disclose information about fixed vulnerabilities. That information includes a description, information allowing users to identify the affected product, impact and severity, and clear information helping users remediate the vulnerability. In duly justified cases, public disclosure may be delayed where the manufacturer considers publication risk to outweigh the security benefit until users have had the possibility to apply the relevant patch.

  • Describe the fixed vulnerability.
  • Identify affected products.
  • Explain impact and severity.
  • Provide remediation information.
  • Document any justified disclosure delay.
07 / 10

CVD Does Not Mean Every Technical Detail Must Be Published Immediately

Coordinated disclosure should balance useful transparency with the security of affected users. The CRA itself recognises this through the point 4 possibility of delaying public information about a fixed vulnerability in duly justified cases. The manufacturer should document the reason for significant disclosure timing decisions and revisit the decision once users have had an appropriate opportunity to apply remediation.

  • Consider user security impact.
  • Coordinate disclosure timing with remediation.
  • Document significant delay decisions.
  • Reassess once remediation is available.
08 / 10

Third-Party Components Can Require Multi-Party Coordination

Point 6 expressly refers to potential vulnerabilities in third-party components contained in the product. A report can therefore involve the manufacturer, an upstream component maintainer and possibly other affected vendors. The manufacturer should define how upstream information is shared without losing ownership of the vulnerability risk in its own product. A dependency vulnerability may require coordination with the upstream project while the manufacturer separately assesses affected versions and prepares product-specific remediation.

  • Identify the upstream component.
  • Coordinate responsibly with maintainers.
  • Assess product-specific exposure.
  • Keep responsibility for the manufacturer's own product clear.
09 / 10

CVD Is Separate From Article 14 Regulatory Reporting

A researcher report through the manufacturer's CVD process is not the same as a notification through the CRA Single Reporting Platform. Article 14 applies when the manufacturer becomes aware of an actively exploited vulnerability or a qualifying severe incident. If those statutory conditions are met, the Article 14 reporting process must run according to its own timeline even while CVD coordination, investigation and remediation continue.

  • Keep CVD case management separate from SRP notification.
  • Assess active exploitation independently.
  • Capture manufacturer awareness time.
  • Run regulatory reporting and remediation in parallel where necessary.
10 / 10

Retain Evidence That the CVD Policy Is Enforced

Annex VII requires technical documentation to include the coordinated vulnerability disclosure policy and evidence of the provision of the vulnerability-reporting contact address. Operational case records can provide further evidence that the policy is actually enforced. Useful records include report receipt, acknowledgement, validation, affected-version analysis, remediation activity, reporter communication, disclosure decisions and closure.

  • Published CVD policy.
  • Evidence of the reporting contact.
  • Case records.
  • Reporter communication.
  • Disclosure decisions.
  • Remediation evidence.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.