Skip to content
All insights

CRA readiness · · 5 min read

Vulnerability handling processes that survive an audit

Most organisations can produce a vulnerability handling policy on request. Fewer can produce evidence that it was followed on the last three findings.

A policy document describing intake, triage, remediation and disclosure timelines is easy to write and easy to present. An auditor who asks for the record of the last three vulnerabilities handled under that policy is asking a different, harder question: did this actually happen, in this order, in this timeframe.

What the evidence gap usually looks like

  • A policy states a triage SLA, but no record shows when a report was received versus when it was triaged.
  • Severity is assigned inconsistently between reports, with no documented rationale for the assignment.
  • Remediation is tracked in an issue tracker with no link back to the originating report or its severity.
  • Coordinated disclosure timelines are described in the policy but never tested against a real report.
  • The person who receives external reports is not the person named in the policy, and the policy was not updated.

What auditable evidence actually looks like

A timestamped intake record, independent of the reporter's own account, showing when the organisation first knew. A triage decision with a stated severity and the reasoning behind it, made by a named person. A remediation record that references the original report and shows the fix that closed it, including in versions still supported. A disclosure record showing what was communicated, to whom, and when, matched against the policy's own timelines.

The policy tells an auditor what should happen. The record is the only thing that tells them what did.

Building the habit, not the document

The most reliable way to make a vulnerability handling process auditable is to make the record a by-product of doing the work, rather than a separate write-up done afterwards for compliance purposes. If triage happens in a tracked system with timestamps and named owners as a matter of course, the audit trail exists without extra effort. If it happens over an ad hoc channel and gets written up later from memory, the record will not withstand scrutiny, however accurate the policy document is.

CRA SCOPE CHECKER

Does the CRA apply to your product?

Enter your website. We read what you make and sell, then ask only the few questions the regulation turns on.

About 60 seconds. No account. PDF report on request.

More insights