Skip to content

GLOSSARY

Vulnerability disclosure policy

The CRA requires manufacturers to establish a coordinated vulnerability disclosure policy and to provide a clear reporting channel, such as a security contact address or reporting form, that is easy for researchers and users to find. The policy sets expectations on both sides: what a reporter can expect from the manufacturer, and what the manufacturer expects from a reporter in terms of responsible handling.

What a working policy specifies

  • A clearly published reporting channel, ideally supporting encrypted communication for sensitive reports.
  • An acknowledgement timeframe, so a reporter knows their submission was received.
  • An expected timeline for triage, remediation and coordinated public disclosure.
  • Whether and how the manufacturer credits reporters, and any safe-harbour commitment for good-faith research.

A published policy is only useful if the internal process behind it actually functions: someone monitors the channel, a triage step distinguishes credible reports from noise, and a decision-maker exists to authorise remediation and disclosure timing. Organisations sometimes publish a policy as a compliance step without building the internal capability it implies, which is exposed the first time a genuine report arrives.

Coordinated disclosure timing also interacts with the CRA's reporting obligations: an actively exploited vulnerability may need to be reported to authorities on a much shorter timeline than the coordinated disclosure process would normally allow.