Skip to content
Distr
Book DemoStart free trialLogin
← Back to Glossary

Coordinated Vulnerability Disclosure (CVD): Now Mandatory Under the CRA

What coordinated vulnerability disclosure is, and why the Cyber Resilience Act makes a CVD policy and a reporting contact mandatory for manufacturers.

Coordinated vulnerability disclosure is a process in which security researchers and other finders report vulnerabilities to the responsible manufacturer, who remediates them before details are published. The Cyber Resilience Act makes CVD mandatory for manufacturers of products with digital elements: Annex I, Part II, points (5) and (6) require manufacturers to put in place and enforce a policy on coordinated vulnerability disclosure and to provide a contact address for reporting vulnerabilities in their products.

A workable CVD setup includes a published policy stating what finders can expect, a reachable reporting channel such as a security contact address or a security.txt file, internal triage with defined response times, and a path from report to fix to advisory.

CVD complements, but is distinct from, the CRA’s reporting obligations toward authorities: reports from researchers arrive through the CVD channel, while actively exploited vulnerabilities must additionally be notified to the manufacturer’s CSIRT and ENISA under Article 14. The reporting clocks are covered in what vendors must monitor under the CRA.

Frequently Asked Questions

Is a CVD policy mandatory under the CRA?

Yes. Annex I, Part II, points (5) and (6) require manufacturers to put in place and enforce a coordinated vulnerability disclosure policy and to provide a contact address for reporting vulnerabilities.

Is CVD the same as CRA vulnerability reporting?

No. CVD is the inbound channel for researchers. Actively exploited vulnerabilities must additionally be reported outbound to the manufacturer's CSIRT and ENISA within 24 hours under Article 14.

Turn self-hosted into a repeatable sales motion

From your first on-prem POC to dozens of enterprise customers, the Distr platform gives you the tooling to deploy, update and manage self-hosted customers, backed by a team that supports you hands-on with the deployment knowledge and implementation help.

Proof from teams shipping self-hosted software

GovCloud deployments without extra overhead

"Distr gives us a clean way to deploy and update our software in GovCloud without breaking security or adding operational overhead."

Corbin Klett

Corbin Klett

Co-Founder, Artifact

Manual operations become one-click workflows

"Our main goal is to simplify the daily operations. No more manual installations, updates, or rollbacks — everything can now be handled with a single click with Distr."

Jefferson Rodrigues

Jefferson Rodrigues

Co-Founder & CTO, Lerian

Read case study

Updates that took days now take minutes

"Distr eliminated nearly all deployment headaches. Updates that used to take days now take minutes."

Ansh Gupta

Ansh Gupta

CTO, Sophris.ai

Read case study

One place for every self-hosted customer

"Having a dedicated space for all our self-hosted customers that can manage authenticated registry access is great."

Derek Reynolds

Derek Reynolds

Product Engineer, Basedash

Read case study

From guided setup to scalable delivery

"We went from hands-on Docker setup calls to an install flow that can be running in minutes."

Daniel Kasen

Daniel Kasen

Chief Engineer for Customer Success, Ozgar AI

Read case study

Self-hosted without the engineering tax

"Weave has a fully self-hosted offering. It's a huge unlock for us, but we almost didn't build it. Distr made such a huge difference in getting us there."

Andrew Churchill

Andrew Churchill

Co-Founder & CTO, Weave

Read case study