Independent information resource Product security · EU CRA
CRA standards, guidance and rulemaking / 12

CRA and ISO/IEC 29147 Vulnerability Disclosure

Learn how ISO/IEC 29147:2018 vulnerability-disclosure practices can support CRA coordinated vulnerability disclosure, reporting contacts and fixed-vulnerability communication without replacing CRA-specific legal duties.

IN BRIEF

The useful relationship is process alignment, not legal equivalence. A manufacturer can reuse ISO/IEC 29147 intake, communication and disclosure procedures, then map them to CRA CVD, contact and public-disclosure requirements. Regulatory reporting under Article 14 should remain a separate branch because a researcher disclosure process and a mandatory CRA notification serve different purposes and audiences.

01 / 06

ISO/IEC 29147 Focuses on Vulnerability Disclosure

ISO/IEC 29147:2018 provides requirements and recommendations to vendors on vulnerability disclosure for products and services. ISO describes the standard as supporting vendor processes for receiving information about potential vulnerabilities and disseminating resolution information. That makes it closely relevant to the communication side of CRA vulnerability handling.

  • Receiving vulnerability information.
  • Reporter communication.
  • Coordinated disclosure.
  • Resolution information.
02 / 06

The CRA Requires a Coordinated Vulnerability Disclosure Policy

Annex I Part II point 5 requires manufacturers to put in place and enforce a coordinated vulnerability disclosure policy. Point 6 requires measures to facilitate sharing information about potential vulnerabilities, including a contact address. ISO/IEC 29147 can help structure the operational process supporting those duties, but the manufacturer remains responsible for ensuring that the CRA-required policy and contact mechanism actually exist and work for the product.

  • Public CVD policy.
  • Vulnerability contact.
  • Report intake process.
  • Coordinated communications.
03 / 06

Use ISO 29147 to Strengthen Reporter Communication

A CRA process benefits from predictable acknowledgement, case identification, requests for missing evidence, progress communication and coordination of disclosure timing. ISO/IEC 29147 provides a useful framework for organising those interactions. The company should connect communications to the vulnerability case so that researcher evidence, engineering decisions and public disclosure remain traceable.

  • Acknowledgement.
  • Case identifier.
  • Technical follow-up.
  • Disclosure coordination.
  • Communication record.
04 / 06

Fixed-Vulnerability Disclosure Has CRA-Specific Content

Annex I Part II point 4 requires manufacturers, after a security update is made available, to share and publicly disclose information about fixed vulnerabilities including affected-product identification, impact and severity and clear information helping users remediate. ISO/IEC 29147 can support the disclosure process, but the CRA content and timing requirements should be checked directly against Annex I rather than inferred from the standard alone.

  • Affected product.
  • Impact and severity.
  • Remediation information.
  • Security update availability.
05 / 06

Keep Article 14 Reporting Separate From Coordinated Disclosure

A security researcher report or coordinated disclosure process is not the Article 14 regulatory notification. Where the manufacturer becomes aware of an actively exploited vulnerability or qualifying severe incident, the CRA reporting process has its own conditions and deadlines. The CVD workflow should therefore contain an escalation decision that can trigger regulatory assessment without making the researcher responsible for legal classification.

  • CVD intake remains operational.
  • Article 14 assessment is separate.
  • Preserve awareness timing.
  • Continue remediation and disclosure coordination in parallel.
06 / 06

Map ISO Evidence to the CRA Requirement It Supports

Existing ISO/IEC 29147 procedures should be mapped at requirement level. A reporting webpage can support the Annex II contact duty, the disclosure policy can support Part II point 5 and resolution communications can support Part II point 4. Where a CRA requirement is not covered by the standard, the gap should be recorded rather than hidden by a general statement that the company follows ISO 29147.

  • CRA requirement.
  • ISO process or evidence.
  • Product-specific implementation.
  • Residual gap.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.