Coordinated Vulnerability Disclosure (CVD): Now Mandatory Under the CRA
What coordinated vulnerability disclosure is, and why the Cyber Resilience Act makes a CVD policy and a reporting contact mandatory for manufacturers.
Coordinated vulnerability disclosure is a process in which security researchers and other finders report vulnerabilities to the responsible manufacturer, who remediates them before details are published. The Cyber Resilience Act makes CVD mandatory for manufacturers of products with digital elements: Annex I, Part II, points (5) and (6) require manufacturers to put in place and enforce a policy on coordinated vulnerability disclosure and to provide a contact address for reporting vulnerabilities in their products.
A workable CVD setup includes a published policy stating what finders can expect, a reachable reporting channel such as a security contact address or a security.txt file, internal triage with defined response times, and a path from report to fix to advisory.
CVD complements, but is distinct from, the CRA’s reporting obligations toward authorities: reports from researchers arrive through the CVD channel, while actively exploited vulnerabilities must additionally be notified to the manufacturer’s CSIRT and ENISA under Article 14. The reporting clocks are covered in what vendors must monitor under the CRA.





