Independent information resource Product security · EU CRA
User information and security communications / 07

Providing Vulnerability Reporting Contact Information

Learn how CRA manufacturers should provide vulnerability reporting contact information, including the single point of contact, CVD policy location, two-way communication, discoverability, durability and separation from regulatory reporting channels.

IN BRIEF

Vulnerability reporting contact information should remove friction between a person who discovers a security issue and the team responsible for handling it. The external route can stay simple even when the manufacturer uses complex internal routing behind it.

01 / 08

Article 13(17) Requires a Single Point of Contact

Article 13(17) requires manufacturers to designate a single point of contact enabling users to communicate directly and rapidly with them, including to facilitate reporting of product vulnerabilities. The single point of contact must be easily identifiable by users and must also appear in the Annex II information and instructions.

  • Designate a single point of contact.
  • Make it easily identifiable.
  • Support direct and rapid communication.
  • Include it in user information.
02 / 08

Annex II Connects the Contact to Vulnerability Reporting

Annex II point 2 requires the single point of contact where vulnerability information can be reported and received and where the manufacturer's coordinated vulnerability disclosure policy can be found. This means the user-facing information should not merely publish a corporate contact page. It should clearly identify the route intended for product-security reports.

  • Identify the vulnerability-reporting route.
  • Enable information to be reported and received.
  • Identify the CVD policy location.
  • Keep the information product-security specific.
03 / 08

Allow More Than Automated Tools Alone

Article 13(17) says the single point of contact must allow users to choose their preferred means of communication and must not limit those means to automated tools. A web form can be useful, but manufacturers should avoid making an automated workflow the only practical route where users cannot communicate directly when needed.

  • Do not rely only on automated tools.
  • Offer a practical human-reachable route.
  • Keep reporting accessible.
  • Avoid unnecessary account barriers.
04 / 08

Use a Durable Contact Rather Than a Personal Address

The CRA does not prescribe one mailbox format, but a role-based or otherwise durable contact is usually more reliable than publishing one employee's address. The route should survive staff changes, holidays, reorganisations and changes to internal product ownership.

  • Use a durable external route.
  • Assign primary and backup ownership.
  • Review routing after organisational changes.
  • Test the contact periodically.
05 / 08

Keep External Contact Simple and Internal Routing Flexible

A manufacturer can have many product teams while still presenting one clear external vulnerability-reporting route. The contact process can collect product, version and component information and then route the case internally. Researchers and users should not need to understand the manufacturer's organisational chart before they can report a security issue.

  • Collect product-identification information.
  • Route internally by product or component.
  • Keep external contact stable.
  • Maintain internal case ownership.
06 / 08

Support Two-Way Follow-Up

Annex II describes a contact where information can be reported and received. The process should support follow-up where appropriate because the manufacturer may need reproduction details, affected-version information or clarification. The reporter may also need acknowledgement or coordination information.

  • Acknowledge receipt where practical.
  • Allow clarification requests.
  • Protect sensitive vulnerability details.
  • Keep communication linked to the case.
07 / 08

Keep CVD Contact Separate From Article 14 Regulatory Reporting

The product vulnerability contact is not the CRA Single Reporting Platform. Users and researchers report product vulnerabilities to the manufacturer, while Article 14 regulatory notifications are the manufacturer's separate responsibility when the statutory conditions are met. Public instructions should not send ordinary vulnerability reporters into the regulatory reporting workflow.

  • Keep researcher intake separate from regulatory notification.
  • Assess Article 14 internally.
  • Do not burden users with the manufacturer's reporting duties.
  • Escalate qualifying cases internally.
08 / 08

Keep the Contact and CVD Policy Discoverable

The contact should be easy to find from product documentation, support pages and security information. The CVD policy location should remain stable and should not disappear during website redesigns. Manufacturers can also use standard discovery mechanisms where appropriate, but the Annex II user information itself should remain clear.

  • Publish the contact in user information.
  • Link the CVD policy clearly.
  • Use durable URLs.
  • Review discoverability after website changes.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.