The useful relationship is process alignment, not legal equivalence. A manufacturer can reuse ISO/IEC 29147 intake, communication and disclosure procedures, then map them to CRA CVD, contact and public-disclosure requirements. Regulatory reporting under Article 14 should remain a separate branch because a researcher disclosure process and a mandatory CRA notification serve different purposes and audiences.
ISO/IEC 29147 Focuses on Vulnerability Disclosure
ISO/IEC 29147:2018 provides requirements and recommendations to vendors on vulnerability disclosure for products and services. ISO describes the standard as supporting vendor processes for receiving information about potential vulnerabilities and disseminating resolution information. That makes it closely relevant to the communication side of CRA vulnerability handling.
- Receiving vulnerability information.
- Reporter communication.
- Coordinated disclosure.
- Resolution information.
The CRA Requires a Coordinated Vulnerability Disclosure Policy
Annex I Part II point 5 requires manufacturers to put in place and enforce a coordinated vulnerability disclosure policy. Point 6 requires measures to facilitate sharing information about potential vulnerabilities, including a contact address. ISO/IEC 29147 can help structure the operational process supporting those duties, but the manufacturer remains responsible for ensuring that the CRA-required policy and contact mechanism actually exist and work for the product.
- Public CVD policy.
- Vulnerability contact.
- Report intake process.
- Coordinated communications.
Use ISO 29147 to Strengthen Reporter Communication
A CRA process benefits from predictable acknowledgement, case identification, requests for missing evidence, progress communication and coordination of disclosure timing. ISO/IEC 29147 provides a useful framework for organising those interactions. The company should connect communications to the vulnerability case so that researcher evidence, engineering decisions and public disclosure remain traceable.
- Acknowledgement.
- Case identifier.
- Technical follow-up.
- Disclosure coordination.
- Communication record.
Fixed-Vulnerability Disclosure Has CRA-Specific Content
Annex I Part II point 4 requires manufacturers, after a security update is made available, to share and publicly disclose information about fixed vulnerabilities including affected-product identification, impact and severity and clear information helping users remediate. ISO/IEC 29147 can support the disclosure process, but the CRA content and timing requirements should be checked directly against Annex I rather than inferred from the standard alone.
- Affected product.
- Impact and severity.
- Remediation information.
- Security update availability.
Keep Article 14 Reporting Separate From Coordinated Disclosure
A security researcher report or coordinated disclosure process is not the Article 14 regulatory notification. Where the manufacturer becomes aware of an actively exploited vulnerability or qualifying severe incident, the CRA reporting process has its own conditions and deadlines. The CVD workflow should therefore contain an escalation decision that can trigger regulatory assessment without making the researcher responsible for legal classification.
- CVD intake remains operational.
- Article 14 assessment is separate.
- Preserve awareness timing.
- Continue remediation and disclosure coordination in parallel.
Map ISO Evidence to the CRA Requirement It Supports
Existing ISO/IEC 29147 procedures should be mapped at requirement level. A reporting webpage can support the Annex II contact duty, the disclosure policy can support Part II point 5 and resolution communications can support Part II point 4. Where a CRA requirement is not covered by the standard, the gap should be recorded rather than hidden by a general statement that the company follows ISO 29147.
- CRA requirement.
- ISO process or evidence.
- Product-specific implementation.
- Residual gap.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.