GLOSSARY
Vulnerability disclosure policy
The CRA requires manufacturers to establish a coordinated vulnerability disclosure policy and to provide a clear reporting channel, such as a security contact address or reporting form, that is easy for researchers and users to find. The policy sets expectations on both sides: what a reporter can expect from the manufacturer, and what the manufacturer expects from a reporter in terms of responsible handling.
What a working policy specifies
- A clearly published reporting channel, ideally supporting encrypted communication for sensitive reports.
- An acknowledgement timeframe, so a reporter knows their submission was received.
- An expected timeline for triage, remediation and coordinated public disclosure.
- Whether and how the manufacturer credits reporters, and any safe-harbour commitment for good-faith research.
A published policy is only useful if the internal process behind it actually functions: someone monitors the channel, a triage step distinguishes credible reports from noise, and a decision-maker exists to authorise remediation and disclosure timing. Organisations sometimes publish a policy as a compliance step without building the internal capability it implies, which is exposed the first time a genuine report arrives.
Coordinated disclosure timing also interacts with the CRA's reporting obligations: an actively exploited vulnerability may need to be reported to authorities on a much shorter timeline than the coordinated disclosure process would normally allow.